87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,451–1,500 of 8,161 in High · page 30 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-34445 | CVE-2026-34445 CVSS 8.6 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was … |
| CVE-2026-34427 | CVE-2026-34427 CVSS 8.8 | Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileg… |
| CVE-2026-34413 | CVE-2026-34413 CVSS 8.6 | Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/conne… |
| CVE-2026-34406 | CVE-2026-34406 CVSS 8.8aptrs | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security orga… |
| CVE-2026-34403 | CVE-2026-34403 CVSS 8.1 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with Ch… |
| CVE-2026-34394 | CVE-2026-34394 CVSS 8.1wwbn | WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF tok… |
| CVE-2026-34393 | CVE-2026-34393 CVSS 8.8 | Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has be… |
| CVE-2026-34386 | CVE-2026-34386 CVSS 8.8 | Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authen… |
| CVE-2026-34385 | CVE-2026-34385 CVSS 8.1 | Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline cou… |
| CVE-2026-34377 | CVE-2026-34377 CVSS 8.1zfnd | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verificat… |
| CVE-2026-34375 | CVE-2026-34375 CVSS 8.2 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUE… |
| CVE-2026-34373 | CVE-2026-34373 CVSS 8.8parseplatform | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQ… |
| CVE-2026-34367 | CVE-2026-34367 CVSS 7.6invoiceshelf | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a S… |
| CVE-2026-34366 | CVE-2026-34366 CVSS 7.6invoiceshelf | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a S… |
| CVE-2026-34365 | CVE-2026-34365 CVSS 7.6invoiceshelf | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a S… |
| CVE-2026-34358 | CVE-2026-34358 CVSS 8.1 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin c… |
| CVE-2026-34332 | CVE-2026-34332 CVSS 8.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. |
| CVE-2026-34329 | CVE-2026-34329 CVSS 8.8 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. |
| CVE-2026-34327 | CVE-2026-34327 CVSS 8.2 | Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-34309 | CVE-2026-34309 CVSS 8.1 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61-8.62.… |
| CVE-2026-34291 | CVE-2026-34291 CVSS 8.7 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2… |
| CVE-2026-34259 | CVE-2026-34259 CVSS 8.2 | Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non… |
| CVE-2026-34253 | CVE-2026-34253 CVSS 8.2 | A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulne… |
| CVE-2026-3425 | CVE-2026-3425 CVSS 8.8 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter… |
| CVE-2026-34241 | CVE-2026-34241 CVSS 8.7 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the tick… |
| CVE-2026-34227 | CVE-2026-34227 CVSS 8.8bishopfox | Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenti… |
| CVE-2026-34210 | CVE-2026-34210 CVSS 8.1wevm | mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Repla… |
| CVE-2026-34197 | Apache ActiveMQ Improper Input Validation Vulnerability KEVCVSS 8.8Apache | Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. |
| CVE-2026-34186 | CVE-2026-34186 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields. This issue affects Pandora FMS: from 7… |
| CVE-2026-34185 | CVE-2026-34185 CVSS 8.8hydrosystem.poznan | AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can injec… |
| CVE-2026-34176 | CVE-2026-34176 CVSS 8.7f5 | When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit c… |
| CVE-2026-34172 | CVE-2026-34172 CVSS 8.8giskard | Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, ChatWorkflow.chat(message) passes its… |
| CVE-2026-34160 | CVE-2026-34160 CVSS 8.6chamilo | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at… |
| CVE-2026-34121 | CVE-2026-34121 CVSS 8.8tp-link | An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent… |
| CVE-2026-34072 | CVE-2026-34072 CVSS 8.3fccview | Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentica… |
| CVE-2026-34064 | CVE-2026-34064 CVSS 8.2 | nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `Acc… |
| CVE-2026-34053 | CVE-2026-34053 CVSS 8.1 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the… |
| CVE-2026-3405 | CVE-2026-3405 CVSS 8.1 | A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulat… |
| CVE-2026-34046 | CVE-2026-34046 CVSS 8.8 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/ap… |
| CVE-2026-34042 | CVE-2026-34042 CVSS 8.2 | act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all i… |
| CVE-2026-3404 | CVE-2026-3404 CVSS 8.1 | A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the com… |
| CVE-2026-34005 | CVE-2026-34005 CVSS 8.8 | In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName val… |
| CVE-2026-33997 | CVE-2026-33997 CVSS 6.8docker | Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be … |
| CVE-2026-33991 | CVE-2026-33991 CVSS 8.8 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 … |
| CVE-2026-3399 | CVE-2026-3399 CVSS 8.8 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer of the… |
| CVE-2026-33982 | CVE-2026-33982 CVSS 8.1 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflow READ vulnerability at 24 bytes before… |
| CVE-2026-33980 | CVE-2026-33980 CVSS 8.1 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/… |
| CVE-2026-3398 | CVE-2026-3398 CVSS 8.8 | A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromAdvSetWan of the file /goform/AdvSetWan of the component httpd. Executing a … |
| CVE-2026-33979 | CVE-2026-33979 CVSS 8.2 | Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross S… |
| CVE-2026-33955 | CVE-2026-33955 CVSS 8.6 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can e… |