Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-71986 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to exec… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71985 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attacke… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71984 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers t… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71983 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71958 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71957 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi in… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71956 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi … No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71955 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71954 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71953 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71952 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71951 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71950 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71949 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71948 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71947 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71946 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71945 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71944 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-68082 In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cl… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-14526 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.6 CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-48170 `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value`… Patch available Fix from $2,3002026-08-07 CRITICAL 9.2 CVE-2026-47243 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-50540 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P… Patch available Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-61808 LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with… Patch available Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-48039 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispat… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.0 CVE-2026-71851 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() us… Patch available Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-64637 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th… No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-19264 Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload di… Patch available Fix from $2,3002026-08-07