Total CVEs

138,042

Critical Severity

3,520

High Severity

12,656

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 621 - 640 of 3,394 CVEs
CVE-2025-41277 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41276 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41275 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41274 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41273 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41272 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41270 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41269 CRITICAL - 9.8

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary ope...

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2025-41268 CRITICAL - 9.1

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

Vendor: Waterfall
Product: WF-500
Published: May 29, 2026
Source: NVD
CVE-2026-9558 CRITICAL - 9.9

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the ...

Published: May 29, 2026
Source: NVD
CVE-2026-49199 CRITICAL - 9.8

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

Vendor: Acer
Product: Predator Connect W6x
Published: May 29, 2026
Source: NVD
CVE-2026-3655 CRITICAL - 9.8

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the ...

Published: May 29, 2026
Source: NVD
CVE-2026-8732 CRITICAL - 9.8

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call...

Published: May 29, 2026
Source: NVD
CVE-2026-9967 CRITICAL - 9.6

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9918 CRITICAL - 9.6

Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9891 CRITICAL - 9.0

Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9886 CRITICAL - 9.6

Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9881 CRITICAL - 9.0

Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9876 CRITICAL - 9.6

Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD
CVE-2026-9875 CRITICAL - 9.6

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 28, 2026
Source: NVD