87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,451–1,500 of 8,161 in High · page 30 of 164

IDTitleSummary
CVE-2026-34445CVE-2026-34445
CVSS 8.6
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was …
CVE-2026-34427CVE-2026-34427
CVSS 8.8
Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileg…
CVE-2026-34413CVE-2026-34413
CVSS 8.6
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/conne…
CVE-2026-34406CVE-2026-34406
CVSS 8.8aptrs
APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security orga…
CVE-2026-34403CVE-2026-34403
CVSS 8.1
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with Ch…
CVE-2026-34394CVE-2026-34394
CVSS 8.1wwbn
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF tok…
CVE-2026-34393CVE-2026-34393
CVSS 8.8
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has be…
CVE-2026-34386CVE-2026-34386
CVSS 8.8
Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authen…
CVE-2026-34385CVE-2026-34385
CVSS 8.1
Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline cou…
CVE-2026-34377CVE-2026-34377
CVSS 8.1zfnd
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verificat…
CVE-2026-34375CVE-2026-34375
CVSS 8.2
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUE…
CVE-2026-34373CVE-2026-34373
CVSS 8.8parseplatform
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQ…
CVE-2026-34367CVE-2026-34367
CVSS 7.6invoiceshelf
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a S…
CVE-2026-34366CVE-2026-34366
CVSS 7.6invoiceshelf
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a S…
CVE-2026-34365CVE-2026-34365
CVSS 7.6invoiceshelf
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a S…
CVE-2026-34358CVE-2026-34358
CVSS 8.1
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin c…
CVE-2026-34332CVE-2026-34332
CVSS 8.0
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
CVE-2026-34329CVE-2026-34329
CVSS 8.8
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-34327CVE-2026-34327
CVSS 8.2
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-34309CVE-2026-34309
CVSS 8.1
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62.…
CVE-2026-34291CVE-2026-34291
CVSS 8.7
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2…
CVE-2026-34259CVE-2026-34259
CVSS 8.2
Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non…
CVE-2026-34253CVE-2026-34253
CVSS 8.2
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulne…
CVE-2026-3425CVE-2026-3425
CVSS 8.8
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter…
CVE-2026-34241CVE-2026-34241
CVSS 8.7
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the tick…
CVE-2026-34227CVE-2026-34227
CVSS 8.8bishopfox
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenti…
CVE-2026-34210CVE-2026-34210
CVSS 8.1wevm
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Repla…
CVE-2026-34197Apache ActiveMQ Improper Input Validation Vulnerability
KEVCVSS 8.8Apache
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-34186CVE-2026-34186
CVSS 8.8
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 7…
CVE-2026-34185CVE-2026-34185
CVSS 8.8hydrosystem.poznan
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can injec…
CVE-2026-34176CVE-2026-34176
CVSS 8.7f5
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit c…
CVE-2026-34172CVE-2026-34172
CVSS 8.8giskard
Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, ChatWorkflow.chat(message) passes its…
CVE-2026-34160CVE-2026-34160
CVSS 8.6chamilo
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at…
CVE-2026-34121CVE-2026-34121
CVSS 8.8tp-link
An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent…
CVE-2026-34072CVE-2026-34072
CVSS 8.3fccview
Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentica…
CVE-2026-34064CVE-2026-34064
CVSS 8.2
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `Acc…
CVE-2026-34053CVE-2026-34053
CVSS 8.1
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the…
CVE-2026-3405CVE-2026-3405
CVSS 8.1
A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulat…
CVE-2026-34046CVE-2026-34046
CVSS 8.8
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/ap…
CVE-2026-34042CVE-2026-34042
CVSS 8.2
act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all i…
CVE-2026-3404CVE-2026-3404
CVSS 8.1
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the com…
CVE-2026-34005CVE-2026-34005
CVSS 8.8
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName val…
CVE-2026-33997CVE-2026-33997
CVSS 6.8docker
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be …
CVE-2026-33991CVE-2026-33991
CVSS 8.8
WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 …
CVE-2026-3399CVE-2026-3399
CVSS 8.8
A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the…
CVE-2026-33982CVE-2026-33982
CVSS 8.1
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before…
CVE-2026-33980CVE-2026-33980
CVSS 8.1
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/…
CVE-2026-3398CVE-2026-3398
CVSS 8.8
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a …
CVE-2026-33979CVE-2026-33979
CVSS 8.2
Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross S…
CVE-2026-33955CVE-2026-33955
CVSS 8.6
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can e…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.