500 records · 61 critical · 254 with a public exploit · source: NVD · no signup, no key, no rate limit
Search the index
Vendor apache nvidia linux eclipse qualcomm ibm redhat soumu tp-link zephyrproject
500 / 500 records · showing 50
CVE-2026-16940 The flaw allows unauthenticated users to delete arbitrary files, leading to potential full site takeover. 10 CRITICAL · pub. 2026-08-05 · —CVE-2026-71268 The flaw allows attackers to execute arbitrary code by manipulating file paths in uploaded Structured Text files, due to lack of proper validation. 9.9 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-10090 The flaw allows a user with namespace-scoped 'edit' privileges to create Subscription resources that can escalate their privileges to full cluster-admin access, bypassing intended security controls. 9.9 CRITICAL · pub. 2026-08-05 · —CVE-2026-71289 The flaw allows direct access to the amp-manager REST API without going through the CAM gateway, enabling unauthorized access and potential full system compromise. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71278 The flaw allows creating a 'calc rule' without authentication, enabling unauthorized access and potential manipulation of critical data. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71267 The flaw allows an attacker to overwrite critical data on the stack by supplying a long entry name, potentially leading to remote code execution. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71262 The IoTSharp BlobStorageController.cs lacks proper authorization, allowing unauthenticated attackers to access sensitive storage operations such as upload, download, list, modify, and delete. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71256 The flaw involves an out-of-bounds stack read in nanoMODBUS v1.23.0, allowing a wild-pointer write that can lead to severe system vulnerabilities. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71254 The flaw allows an attacker to perform out-of-bounds writes by manipulating Modbus requests, leading to potential code execution or data corruption. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71248 The flaw is an SQL injection vulnerability due to direct string concatenation in login.php, allowing attackers to bypass authentication by manipulating input parameters. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71237 The flaw allows unauthenticated attackers to bypass authentication and potentially extract database data through SQL injection. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71231 The flaw allows an attacker to execute arbitrary SQL commands by exploiting improper input sanitization in the authentication query construction. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-66747 The Zbtlink router firmware includes an embedded implant called ENDLESSDOORS that provides unauthenticated remote code execution as root over cleartext TCP to a hardcoded C2 server. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71214 The flaw allows an attacker to bypass authentication by manipulating the session_variables object in the request body instead of using the Authorization header's JWT claims. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71207 The flaw allows direct SQL injection due to unparameterized query construction and hardcoded credentials, enabling unauthorized access. 9.8 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-64566 The vulnerability in iptfs_skb_add_frags() allows for kernel memory corruption when handling shared frags, leading to potential panic conditions. 9.8 CRITICAL · pub. 2026-08-05 · —CVE-2026-61486 A stack-based buffer overflow vulnerability exists in Apache Lucy, allowing attackers to potentially execute arbitrary code through crafted input. 9.8 CRITICAL · pub. 2026-08-05 · apacheCVE-2026-61484 The flaw is a deserialization vulnerability in Apache Lucy, allowing untrusted data to be deserialized, which can lead to remote code execution or other severe impacts. This matters because it can enable attackers to exploit the software even though it is no longer supported. 9.8 CRITICAL · pub. 2026-08-05 · apacheCVE-2026-70554 The flaw is a PHP object injection vulnerability in MaxSite CMS that allows unauthenticated attackers to execute arbitrary code by passing malicious serialized data through the maxsite_comuser cookie. This matters because it can lead to full system compromise without authentication. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-66902 This vulnerability allows an attacker to execute arbitrary commands with the privileges of the application process by manipulating external_account credentials JSON. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-45538 The flaw is a stack buffer overflow in OpenSIPS due to unbounded copying of SIP header names into a fixed-size buffer, allowing remote code execution via crafted SIP messages. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-70553 The flaw allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file via crafted POST requests, leading to persistent remote code execution. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-70552 The flaw allows unauthenticated attackers to access admin endpoints by exploiting an authentication bypass in the AJAX dispatcher, enabling unauthorized actions such as manipulating poll states and vote counts. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-69703 The flaw allows unauthenticated attackers to bypass session-based authentication and invoke admin actions, leading to potential unauthorized record deletion. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-49435 The flaw is a stack-based buffer overflow in Keysight IxChariot Endpoint products, allowing unauthenticated remote attackers to execute arbitrary code with administrative privileges by sending specially crafted packets. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-0163 The flaw involves a use after free vulnerability in vpu_ioctl.c, allowing remote escalation of privilege without user interaction. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2017-20242 The flaw is a stack-based buffer overflow in Keysight IxChariot Endpoint versions before 9.5.102, allowing unauthenticated remote attackers to crash the endpoint or execute arbitrary code by sending specially crafted packets. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2017-20241 The flaw is a heap-based buffer overflow in Keysight IxChariot Endpoint versions before 9.5.102, allowing unauthenticated remote attackers to crash the endpoint or execute arbitrary code. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-24254 The vulnerability in NVIDIA Dynamo for Linux allows an attacker to perform out-of-bounds writes, potentially leading to code execution and data tampering. 9.8 CRITICAL · pub. 2026-08-04 · nvidia, linux · public exploit CVE-2026-63456 The flaw allows unauthenticated attackers to bypass web authentication and access sensitive system functions via the REST API, posing a significant security risk. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-63455 The flaw allows unauthenticated attackers to bypass web authentication and access sensitive system functions via the REST API, posing a significant security risk. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2025-29296 The flaw allows command injection via the /api/esps request handler, enabling remote attackers to execute arbitrary commands as root. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-69098 The flaw allows unauthenticated attackers to execute arbitrary code by deserializing crafted YAML/JSON input, posing a significant security risk. 9.8 CRITICAL · pub. 2026-08-04 · — · public exploit CVE-2026-61515 The flaw allows unauthenticated command injection, enabling attackers to execute arbitrary OS commands and gain root-level access. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-61514 The flaw allows unauthenticated attackers to access device functions by exploiting an authentication bypass vulnerability in Puwell IP Camera firmware versions 2.x through 4.x. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-15721 The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources versions before 26.1, allowing attackers to access sensitive data through unencrypted storage and execute malicious SQL commands. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-14175 Allows attackers to upload a web shell by exploiting an unrestricted file upload vulnerability, leading to remote code execution. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-64564 This vulnerability allows an attacker to free a transport structure and then reuse it, leading to potential denial of service or other critical issues in SCTP associations. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-16618 The flaw allows unauthenticated users to upload executable PHP files due to improper file validation in the Improve SEO WordPress plugin, leading to remote code execution. 9.8 CRITICAL · pub. 2026-08-04 · —CVE-2026-70376 The flaw allows attackers to perform CSRF attacks by manipulating the Referer header, bypassing admin panel protections. 9.6 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-25289 The flaw involves memory corruption when processing Device Capability Extended attributes in specific NAN Service Discovery Frames with invalid length values, potentially leading to remote code execution. 9.6 CRITICAL · pub. 2026-08-04 · qualcommCVE-2026-9273 The flaw allows password reset link poisoning, enabling account takeover due to unvalidated POST parameters and a broadcasted nonce. 9.3 CRITICAL · pub. 2026-08-05 · —CVE-2026-15958 The flaw allows unauthenticated attackers to perform file management actions on connected Dropbox accounts, leading to unauthorized access and data exposure. 9.3 CRITICAL · pub. 2026-08-04 · —CVE-2026-71277 The flaw allows an attacker to bypass authentication by sending any non-empty Authorization header, granting unauthorized access to protected endpoints. 9.1 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71263 The flaw involves an off-by-one error in the bounds check for LINUXTCP port of FreeModbus, leading to potential buffer overflow. This matters because it can allow attackers to exploit the vulnerability to execute malicious code or cause system crashes. 9.1 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-71238 The flaw involves a hardcoded Django SECRET_KEY in the codebase, allowing attackers to forge session cookies and tokens, leading to full account takeover. 9.1 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-44945 A privilege escalation vulnerability allows authenticated users to gain full administrative access, bypassing role restrictions. 9.1 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-10059 The flaw allows a tenant administrator with namespace-scoped privileges to exploit a vulnerability in the Multicluster Engine for Kubernetes ClusterCurator controller, leading to privilege escalation and full control over the cluster. 9.1 CRITICAL · pub. 2026-08-05 · —CVE-2026-71213 The flaw allows unauthenticated attackers to perform unlimited password-guessing attacks due to lack of rate-limiting or account lockout mechanisms when captcha is disabled by default. 9.1 CRITICAL · pub. 2026-08-05 · — · public exploit CVE-2026-5581 The flaw allows unauthenticated attackers to delete any media attachment by exploiting missing capability checks and exposed nonce values, potentially leading to complete media library destruction. 9.1 CRITICAL · pub. 2026-08-05 · —load 100 more → §
Data Records are real CVEs mirrored from the NVD . Nothing here is generated or synthesised. Severity and CVSS come straight from the upstream record; where a field is missing it renders as — rather than a guess.
§
Free here, paid there exploits-db.com — $0
· full index, search and facets · CVSS, vendors, public-exploit flag · links to the upstream NVD record · no account, no key exploit-db.ai — the analysis layer
· AI-written exploitability & blast-radius reads · prioritized remediation notes · JSON API and RSS feed · watchlists and alerts (planned) Go to exploit-db.ai ↗