87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,401–1,450 of 8,161 in High · page 29 of 164

IDTitleSummary
CVE-2026-34795CVE-2026-34795
CVSS 8.8endian
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE p…
CVE-2026-34794CVE-2026-34794
CVSS 8.8endian
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE p…
CVE-2026-34793CVE-2026-34793
CVSS 8.8endian
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The D…
CVE-2026-34792CVE-2026-34792
CVSS 8.8endian
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DAT…
CVE-2026-34791CVE-2026-34791
CVSS 8.8
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE…
CVE-2026-34790CVE-2026-34790
CVSS 8.1
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bi…
CVE-2026-34783CVE-2026-34783
CVSS 8.1
Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library fun…
CVE-2026-34774CVE-2026-34774
CVSS 8.1electronjs
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that…
CVE-2026-34772CVE-2026-34772
CVSS 5.8electronjs
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-be…
CVE-2026-34771CVE-2026-34771
CVSS 7.5electronjs
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-be…
CVE-2026-34770CVE-2026-34770
CVSS 7.0electronjs
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-be…
CVE-2026-34765CVE-2026-34765
CVSS 6.0electronjs
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, wh…
CVE-2026-34759CVE-2026-34759
CVSS 8.1hackerbay
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authent…
CVE-2026-34748CVE-2026-34748
CVSS 8.7
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a stored Cross-Site Scripting (XSS) vulnerab…
CVE-2026-34747CVE-2026-34747
CVSS 8.2
Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs were not properly validated. An attacker …
CVE-2026-34742CVE-2026-34742
CVSS 8.1lfprojects
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by de…
CVE-2026-34728CVE-2026-34728
CVSS 8.1
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser.…
CVE-2026-34725CVE-2026-34725
CVSS 8.2
DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled …
CVE-2026-34717CVE-2026-34717
CVSS 9.9openproject
OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 …
CVE-2026-34714CVE-2026-34714
CVSS 9.2vim
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs w…
CVE-2026-34686CVE-2026-34686
CVSS 8.7adobe
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulner…
CVE-2026-34653CVE-2026-34653
CVSS 8.7adobe
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a …
CVE-2026-3464CVE-2026-3464
CVSS 8.8
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' …
CVE-2026-34632CVE-2026-34632
CVSS 8.6adobe
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context…
CVE-2026-34622CVE-2026-34622
CVSS 8.6adobe
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attribut…
CVE-2026-34621Adobe Acrobat and Reader Prototype Pollution Vulnerability
KEVCVSS 8.6Adobe
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-34617CVE-2026-34617
CVSS 8.7adobe
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-pr…
CVE-2026-34608CVE-2026-34608
CVSS 4.9emqx
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function proce…
CVE-2026-34604CVE-2026-34604
CVSS 8.8
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That bloc…
CVE-2026-34603CVE-2026-34603
CVSS 8.3
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media routes, but th…
CVE-2026-3459CVE-2026-3459
CVSS 8.1
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i…
CVE-2026-34587CVE-2026-34587
CVSS 8.1
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform sp…
CVE-2026-34585CVE-2026-34585
CVSS 8.2
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute…
CVE-2026-34581CVE-2026-34581
CVSS 8.1goshs
goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited s…
CVE-2026-34578CVE-2026-34578
CVSS 8.2
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an…
CVE-2026-34577CVE-2026-34577
CVSS 8.6gitroom
Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query pa…
CVE-2026-34572CVE-2026-34572
CVSS 8.8
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version …
CVE-2026-34570CVE-2026-34570
CVSS 8.8
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version …
CVE-2026-34561CVE-2026-34561
CVSS 8.4
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version …
CVE-2026-34531CVE-2026-34531
CVSS 8.2
Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request t…
CVE-2026-3453CVE-2026-3453
CVSS 8.1
The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing o…
CVE-2026-34524CVE-2026-34524
CVSS 8.3sillytavern
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-…
CVE-2026-34522CVE-2026-34522
CVSS 8.1sillytavern
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-…
CVE-2026-34512CVE-2026-34512
CVSS 8.1
OpenClaw before 2026.3.25 contains an improper access control vulnerability in the HTTP /sessions/:sessionKey/kill route that allows any bearer-authenticated u…
CVE-2026-34504CVE-2026-34504
CVSS 8.3openclaw
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers…
CVE-2026-34503CVE-2026-34503
CVSS 8.1openclaw
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can …
CVE-2026-34464CVE-2026-34464
CVSS 8.8sandboxie-plus
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server f…
CVE-2026-34459CVE-2026-34459
CVSS 8.8sandboxie-plus
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInf…
CVE-2026-34458CVE-2026-34458
CVSS 8.8sandboxie-plus
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standa…
CVE-2026-34455CVE-2026-34455
CVSS 8.8
Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository classes p…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.