Total CVEs

138,170

Critical Severity

3,538

High Severity

12,685

Last 7 Days

1,964
Quick preset (or use dates below)
Clear Filters
Showing 781 - 800 of 3,538 CVEs
CVE-2026-9388 CRITICAL - 9.8

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument mode can lead to os command injection. It is possible to la...

Published: May 24, 2026
Source: NVD
CVE-2026-9387 CRITICAL - 9.8

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possi...

Published: May 24, 2026
Source: NVD
CVE-2026-9386 CRITICAL - 9.8

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument lang leads to os command injection. The attack may be performed from remote. T...

Published: May 24, 2026
Source: NVD
CVE-2026-9385 CRITICAL - 9.8

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument command causes os command injection. The attack is possible to be car...

Published: May 24, 2026
Source: NVD
CVE-2026-9384 CRITICAL - 9.8

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument ip results in os command injection. The attack can be executed remot...

Published: May 24, 2026
Source: NVD
CVE-2018-25357 CRITICAL - 9.8

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then exe...

Vendor: dolibarr
Product: dolibarr_erp\/crm
Published: May 23, 2026
Source: NVD
CVE-2018-25350 CRITICAL - 9.8

userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify e...

Published: May 23, 2026
Source: NVD
CVE-2026-46716 CRITICAL - 9.9

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboa...

Vendor: go
Product: github.com/nezhahq/nezha
Published: May 23, 2026
Source: GitHub
CVE-2026-47280 CRITICAL - 10.0

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_resource_manager
Published: May 22, 2026
Source: NVD
CVE-2026-42901 CRITICAL - 10.0

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: entra_id
Published: May 22, 2026
Source: NVD
CVE-2026-41104 CRITICAL - 10.0

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: planetary_computer
Published: May 22, 2026
Source: NVD
CVE-2026-41090 CRITICAL - 9.3

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: 365_copilot
Published: May 22, 2026
Source: NVD
CVE-2026-40412 CRITICAL - 10.0

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: azure_orbital_spatio
Published: May 22, 2026
Source: NVD
CVE-2026-40411 CRITICAL - 9.9

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: azure_virtual_network_gateway
Published: May 22, 2026
Source: NVD
CVE-2026-33843 CRITICAL - 9.1

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: entra_id
Published: May 22, 2026
Source: NVD
CVE-2026-23652 CRITICAL - 10.0

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: power_pages
Published: May 22, 2026
Source: NVD
CVE-2026-33712 CRITICAL - 10.0

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side code blocks. The fetch...

Published: May 22, 2026
Source: NVD
CVE-2026-32253 CRITICAL - 9.8

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom verify callback treats X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOC...

Vendor: lizardbyte
Product: sunshine
Published: May 22, 2026
Source: NVD
CVE-2026-39821 CRITICAL - 10.0

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program...

Vendor: golang
Product: net
Published: May 22, 2026
Source: NVD
CVE-2026-46670 CRITICAL - 9.8

YesWiki: Unauthenticated SQL Injection

Vendor: composer
Product: yeswiki/yeswiki
Published: May 22, 2026
Source: GitHub