87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,401–1,450 of 8,161 in High · page 29 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-34795 | CVE-2026-34795 CVSS 8.8endian | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE p… |
| CVE-2026-34794 | CVE-2026-34794 CVSS 8.8endian | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE p… |
| CVE-2026-34793 | CVE-2026-34793 CVSS 8.8endian | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The D… |
| CVE-2026-34792 | CVE-2026-34792 CVSS 8.8endian | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DAT… |
| CVE-2026-34791 | CVE-2026-34791 CVSS 8.8 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE… |
| CVE-2026-34790 | CVE-2026-34790 CVSS 8.1 | Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bi… |
| CVE-2026-34783 | CVE-2026-34783 CVSS 8.1 | Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library fun… |
| CVE-2026-34774 | CVE-2026-34774 CVSS 8.1electronjs | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that… |
| CVE-2026-34772 | CVE-2026-34772 CVSS 5.8electronjs | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-be… |
| CVE-2026-34771 | CVE-2026-34771 CVSS 7.5electronjs | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-be… |
| CVE-2026-34770 | CVE-2026-34770 CVSS 7.0electronjs | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-be… |
| CVE-2026-34765 | CVE-2026-34765 CVSS 6.0electronjs | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, wh… |
| CVE-2026-34759 | CVE-2026-34759 CVSS 8.1hackerbay | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authent… |
| CVE-2026-34748 | CVE-2026-34748 CVSS 8.7 | Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerab… |
| CVE-2026-34747 | CVE-2026-34747 CVSS 8.2 | Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker … |
| CVE-2026-34742 | CVE-2026-34742 CVSS 8.1lfprojects | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by de… |
| CVE-2026-34728 | CVE-2026-34728 CVSS 8.1 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser.… |
| CVE-2026-34725 | CVE-2026-34725 CVSS 8.2 | DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled … |
| CVE-2026-34717 | CVE-2026-34717 CVSS 9.9openproject | OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 … |
| CVE-2026-34714 | CVE-2026-34714 CVSS 9.2vim | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs w… |
| CVE-2026-34686 | CVE-2026-34686 CVSS 8.7adobe | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulner… |
| CVE-2026-34653 | CVE-2026-34653 CVSS 8.7adobe | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a … |
| CVE-2026-3464 | CVE-2026-3464 CVSS 8.8 | The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' … |
| CVE-2026-34632 | CVE-2026-34632 CVSS 8.6adobe | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context… |
| CVE-2026-34622 | CVE-2026-34622 CVSS 8.6adobe | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attribut… |
| CVE-2026-34621 | Adobe Acrobat and Reader Prototype Pollution Vulnerability KEVCVSS 8.6Adobe | Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. |
| CVE-2026-34617 | CVE-2026-34617 CVSS 8.7adobe | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-pr… |
| CVE-2026-34608 | CVE-2026-34608 CVSS 4.9emqx | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function proce… |
| CVE-2026-34604 | CVE-2026-34604 CVSS 8.8 | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That bloc… |
| CVE-2026-34603 | CVE-2026-34603 CVSS 8.3 | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but th… |
| CVE-2026-3459 | CVE-2026-3459 CVSS 8.1 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i… |
| CVE-2026-34587 | CVE-2026-34587 CVSS 8.1 | Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform sp… |
| CVE-2026-34585 | CVE-2026-34585 CVSS 8.2 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute… |
| CVE-2026-34581 | CVE-2026-34581 CVSS 8.1goshs | goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited s… |
| CVE-2026-34578 | CVE-2026-34578 CVSS 8.2 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an… |
| CVE-2026-34577 | CVE-2026-34577 CVSS 8.6gitroom | Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query pa… |
| CVE-2026-34572 | CVE-2026-34572 CVSS 8.8 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version … |
| CVE-2026-34570 | CVE-2026-34570 CVSS 8.8 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version … |
| CVE-2026-34561 | CVE-2026-34561 CVSS 8.4 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version … |
| CVE-2026-34531 | CVE-2026-34531 CVSS 8.2 | Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request t… |
| CVE-2026-3453 | CVE-2026-3453 CVSS 8.1 | The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing o… |
| CVE-2026-34524 | CVE-2026-34524 CVSS 8.3sillytavern | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-… |
| CVE-2026-34522 | CVE-2026-34522 CVSS 8.1sillytavern | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-… |
| CVE-2026-34512 | CVE-2026-34512 CVSS 8.1 | OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated u… |
| CVE-2026-34504 | CVE-2026-34504 CVSS 8.3openclaw | OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers… |
| CVE-2026-34503 | CVE-2026-34503 CVSS 8.1openclaw | OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can … |
| CVE-2026-34464 | CVE-2026-34464 CVSS 8.8sandboxie-plus | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server f… |
| CVE-2026-34459 | CVE-2026-34459 CVSS 8.8sandboxie-plus | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInf… |
| CVE-2026-34458 | CVE-2026-34458 CVSS 8.8sandboxie-plus | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standa… |
| CVE-2026-34455 | CVE-2026-34455 CVSS 8.8 | Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository classes p… |