23295 Total CVEs
23200 AI Analyzed
327 CISA KEV
5281 Critical
All Vendors
Showing 2401-2450 of 23295 CVEs Page 49 of 466
CVE-2026-68502
Analyzed
9.8
Unknown LazyOwn

A missing authentication flaw in the LazyOwn Socket.IO event handler allows unauthenticated remote attackers to execute arbitrary commands within the...

2026-07-31
CVE-2026-68494
Analyzed
8.7
FasterXML jackson-core

The fix released in jackson-core 2

2026-08-05
CVE-2026-6849
Analyzed
8.8
TUBITAK BILGEM Institute Pardus

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Resea...

2026-04-30
CVE-2026-6847
Analyzed
9.3
HP ThemisNETPanel

ThemisNETPanel contains a critical remote code execution vulnerability due to the lack of authentication on its file upload functionality.

2026-07-14
CVE-2026-6846
Analyzed
7.8
Unknown Multiple Products

A flaw was found in binutils

2026-04-23
CVE-2026-68454
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to re...

2026-08-14
CVE-2026-68385
Analyzed
9.8
Linux Kernel

A memory corruption vulnerability exists in the Linux kernel s390 checksum implementation, where the csum_partial function incorrectly reads from addr...

2026-08-27
CVE-2026-6832
Analyzed
8.1
Unknown Multiple Products

Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files...

2026-04-22
CVE-2026-68302
Analyzed
9.8
Linux Kernel

A use-after-free vulnerability in the Linux kernel AMT implementation allows remote attackers to trigger memory corruption and potential code executio...

2026-08-27
CVE-2026-68300
Analyzed
9.8
Linux Kernel

A flaw in the Linux kernel SCTP implementation allows unauthenticated attackers to bypass authentication requirements, potentially leading to unauthor...

2026-08-27
CVE-2026-6823
Analyzed
8.2
HKUDS Multiple Products

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*...

2026-04-22
CVE-2026-6819
Analyzed
8.8
HKUDS Multiple Products

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /relo...

2026-04-22
CVE-2026-68160
Analyzed
9.8
Linux Kernel

A memory safety flaw in the Linux kernel Ceph filesystem driver allows an unauthenticated attacker to trigger an out-of-bounds read during snaptrace p...

2026-08-27
CVE-2026-68158
Analyzed
9.8
Linux Kernel

A multiplication overflow in the Linux kernel libceph component allows unauthenticated attackers to trigger out-of-bounds memory access via a maliciou...

2026-08-27
CVE-2026-68154
Analyzed
9.8
Linux Kernel

A flaw in the Linux kernel libceph component allows a malformed CRUSH map to trigger an out-of-bounds memory access, potentially leading to system ins...

2026-08-27
CVE-2026-68140
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path af_iucv queues not-yet-recei...

2026-08-27
CVE-2026-68134
Analyzed
7.3
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only register the physical clock when...

2026-08-20
CVE-2026-68131
Analyzed
7.5
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object map update path In a reply me...

2026-08-20
CVE-2026-68128
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profile_init set_bit(rslt->ptype, p...

2026-08-20
CVE-2026-68125
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_dec...

2026-08-20
CVE-2026-68124
Analyzed
9.6
Linux Kernel

A buffer overflow vulnerability in the Linux kernel MCTP serial driver allows local attackers to trigger arbitrary memory corruption via crafted zero-...

2026-08-20
CVE-2026-68123
Analyzed
9.8
Linux Kernel

A memory safety vulnerability exists in the Open vSwitch module of the Linux kernel due to improper handling of GSO packet truncation, which can lead...

2026-08-27
CVE-2026-68121
Analyzed
7.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a poi...

2026-08-20
CVE-2026-68120
Analyzed
7.5
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang caused by hardware packet parsing The hardware per...

2026-08-20
CVE-2026-68118
Analyzed
8.2
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVED The SYN-RECEIVED request-so...

2026-08-20
CVE-2026-68116
Analyzed
7.9
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list corruption on a failed replace When replacing the so...

2026-08-20
CVE-2026-68107
Analyzed
8.8
AMD Kernel

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length Reuse the parameter length retu...

2026-08-27
CVE-2026-68104
Analyzed
7.8
AMD Kernel

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove()...

2026-08-20
CVE-2026-68100
Analyzed
8.1
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl set_ntacl_dacl()...

2026-08-19
CVE-2026-68098
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_ntacl_dacl() can stop copying AC...

2026-08-19
CVE-2026-68097
Analyzed
8.8
Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authorities set_ntacl_dacl() validates...

2026-08-19
CVE-2026-68083
Analyzed
9.1
Linux Kernel

A path traversal vulnerability in the Linux kernel ksmbd implementation allows an authenticated attacker to escape the intended share root directory d...

2026-08-27
CVE-2026-68079
Analyzed
9.8
Apache Apache CXF

Apache CXF contains a flaw in the removeCodeGrant functionality, allowing an authorization code to be redeemed multiple times in violation of RFC spec...

2026-08-06
CVE-2026-68074
Analyzed
7.5
Apache Apache Qpid Broker-J

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue aff...

2026-08-27
CVE-2026-68067
Analyzed
9.8
Quanovate Tech Inc. Mira Firmware and Mira App

The Mira cloud API login endpoint contains a critical authentication bypass vulnerability, allowing unauthenticated attackers to hijack user accounts...

2026-08-12
CVE-2026-68060
Analyzed
7.5
Apache Apache Qpid Broker-J

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issu...

2026-08-27
CVE-2026-68005
Analyzed
7.5
GitHub mini_httpd

An issue in ACME mini_httpd 1

2026-08-18
CVE-2026-67975
Analyzed
7.5
GitHub cFS (Core Flight System)

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/...

2026-08-12
CVE-2026-67974
Analyzed
7.5
GitHub cFS (Core Flight System)

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause...

2026-08-27
CVE-2026-67973
Analyzed
7.5
GitHub cFS

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

2026-08-27
CVE-2026-67961
Analyzed
7.8
O2OA O2OA

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

2026-08-26
CVE-2026-67960
Analyzed
9.8
HP PbootCMS

PbootCMS v.3.2.15 contains an arbitrary code execution vulnerability in multiple controller files, allowing unauthenticated attackers to compromise th...

2026-08-26
CVE-2026-6795
Analyzed
9.6
Infor Multiple Products

URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection....

2026-05-08
CVE-2026-67919
Analyzed
9.8
GitHub Halo

A remote code execution vulnerability in Halo 2.25.4 exists due to insecure handling of plugin artifacts and insufficient validation of external plugi...

2026-08-26
CVE-2026-67917
Analyzed
9.8
GitHub ZuraCast

A SQL injection vulnerability in ZuraCast allows unauthenticated, remote attackers to execute arbitrary SQL statements during the backup restoration p...

2026-08-27
CVE-2026-67873
Analyzed
9.8
Unknown lib60870-C

A heap-based buffer overflow in lib60870-C 2.4.0 allows unauthenticated attackers to potentially achieve arbitrary code execution.

2026-08-06
CVE-2026-67870
Analyzed
9.8
Unknown open62541

A null pointer dereference vulnerability exists in the open62541 AddReferences service, allowing unauthenticated remote attackers to trigger a crash o...

2026-08-27
CVE-2026-67868
Analyzed
9.8
GitHub S2OPC

A heap-based out-of-bounds write in S2OPC 1.7.3 during EventFilter handling allows remote, unauthenticated attackers to execute arbitrary code.

2026-08-26
CVE-2026-6786
Analyzed
8.1
Mozilla Firefox ESR

Memory safety bugs present in Firefox ESR 140

2026-04-27
CVE-2026-6785
Analyzed
8.1
Mozilla Firefox ESR

Memory safety bugs present in Firefox ESR 115

2026-04-27