Search
1,517 CVEs · Critical severity
CVEs (1,517, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 1,517 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-71984 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary com… | |
| CVE-2026-71985 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary… | |
| CVE-2026-71986 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands … | |
| CVE-2026-71987 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands … | |
| CVE-2026-71988 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary comman… | |
| CVE-2026-71989 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary co… | |
| CVE-2026-71990 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attacke… | |
| CVE-2026-71991 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote atta… | |
| CVE-2026-71992 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary com… | |
| CVE-2026-71993 | CRITICAL | 9.8 | 2026-08-09 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary comma… | |
| CVE-2026-15038 | CRITICAL | Patched | 9.8 | 2026-08-09 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint o… |
| CVE-2026-18473 | CRITICAL | Patched | 9.1 | 2026-08-09 | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploita… |
| CVE-2026-19348 | CRITICAL | 9.8 | 2026-08-09 | A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_c… | |
| CVE-2026-16298 | CRITICAL | Patched | 9.8 | 2026-08-10 | The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary… |
| CVE-2026-16299 | CRITICAL | Patched | 9.8 | 2026-08-10 | The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of ar… |
| CVE-2026-19053 | CRITICAL | Patched | 9.1 | 2026-08-10 | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, l… |
| CVE-2026-19089 | CRITICAL | Patched | 9.8 | 2026-08-10 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own do… |
| CVE-2026-28672 | CRITICAL | Patched | 9.8 | 2026-08-10 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8. |
| CVE-2026-32227 | CRITICAL | Patched | 9.8 | 2026-08-10 | SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue. |
| CVE-2026-40920 | CRITICAL | Patched | 9.8 | 2026-08-10 | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. |
| CVE-2026-42537 | CRITICAL | Patched | 9.8 | 2026-08-10 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. |
| CVE-2026-44416 | CRITICAL | Patched | 9.8 | 2026-08-10 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, wh… |
| CVE-2026-55799 | CRITICAL | Patched | 9.8 | 2026-08-10 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. |
| CVE-2026-72564 | CRITICAL | 9.6 | 2026-08-10 | An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reu… | |
| CVE-2026-72565 | CRITICAL | 9.8 | 2026-08-10 | A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables… |