87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,501–1,550 of 8,161 in High · page 31 of 164

IDTitleSummary
CVE-2026-33953CVE-2026-33953
CVSS 8.5
LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side…
CVE-2026-33949CVE-2026-33949
CVSS 8.1
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write …
CVE-2026-33941CVE-2026-33941
CVSS 8.2handlebarsjs
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars…
CVE-2026-33940CVE-2026-33940
CVSS 8.1handlebarsjs
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context…
CVE-2026-33938CVE-2026-33938
CVSS 8.1handlebarsjs
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored…
CVE-2026-33918CVE-2026-33918
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download en…
CVE-2026-33917CVE-2026-33917
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vuln…
CVE-2026-33910CVE-2026-33910
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL inj…
CVE-2026-33898CVE-2026-33898
CVSS 8.8
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authenticat…
CVE-2026-33858CVE-2026-33858
CVSS 8.8
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code.…
CVE-2026-33849CVE-2026-33849
CVSS 8.8
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.
CVE-2026-33848CVE-2026-33848
CVSS 8.8
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.
CVE-2026-33833CVE-2026-33833
CVSS 8.2microsoft
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to…
CVE-2026-33827CVE-2026-33827
CVSS 8.1microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o…
CVE-2026-33826CVE-2026-33826
CVSS 8.0microsoft
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
CVE-2026-33825Microsoft Defender Insufficient Granularity of Access Control Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2026-33810CVE-2026-33810
CVSS 8.2golang
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different …
CVE-2026-3380CVE-2026-3380
CVSS 8.8
A vulnerability was found in Tenda F453 1.0.0.3. This issue affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page re…
CVE-2026-3379CVE-2026-3379
CVSS 8.8
A vulnerability has been found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of …
CVE-2026-33785CVE-2026-33785
CVSS 8.8
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute sp…
CVE-2026-3378CVE-2026-3378
CVSS 8.8
A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromqossetting of the file /goform/qossetting. Executing a manipulation of the argument …
CVE-2026-3377CVE-2026-3377
CVSS 8.8
A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Performing a ma…
CVE-2026-33767CVE-2026-33767
CVSS 8.8
WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using …
CVE-2026-3376CVE-2026-3376
CVSS 8.8
A security vulnerability has been detected in Tenda F453 1.0.0.3. Affected by this vulnerability is the function fromSafeMacFilter of the file /goform/SafeMacF…
CVE-2026-33757CVE-2026-33757
CVSS 9.6openbao
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via J…
CVE-2026-33755CVE-2026-33755
CVSS 8.8
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Inject…
CVE-2026-33752CVE-2026-33752
CVSS 8.6
curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically vi…
CVE-2026-33735CVE-2026-33735
CVSS 8.8
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database…
CVE-2026-33719CVE-2026-33719
CVSS 8.6
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disab…
CVE-2026-33717CVE-2026-33717
CVSS 8.8
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.jso…
CVE-2026-33713CVE-2026-33713
CVSS 8.8
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify w…
CVE-2026-33704CVE-2026-33704
CVSS 8.8
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server v…
CVE-2026-33696CVE-2026-33696
CVSS 8.8
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify w…
CVE-2026-33687CVE-2026-33687
CVSS 8.8
Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allow…
CVE-2026-33686CVE-2026-33686
CVSS 8.8
Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. Th…
CVE-2026-33678CVE-2026-33678
CVSS 8.1
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = …
CVE-2026-33668CVE-2026-33668
CVSS 8.1
Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locke…
CVE-2026-33660CVE-2026-33660
CVSS 8.8
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify w…
CVE-2026-33651CVE-2026-33651
CVSS 8.8
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule_id']` thr…
CVE-2026-33649CVE-2026-33649
CVSS 8.8
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parame…
CVE-2026-33648CVE-2026-33648
CVSS 8.8
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-contro…
CVE-2026-33647CVE-2026-33647
CVSS 8.8
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using…
CVE-2026-33645CVE-2026-33645
CVSS 8.1
Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoin…
CVE-2026-33634Aquasecurity Trivy Embedded Malicious Code Vulnerability
KEVCVSS 8.8Aquasecurity
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, includ…
CVE-2026-33633CVE-2026-33633
CVSS 7.5kovidgoyal
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can w…
CVE-2026-33631CVE-2026-33631
CVSS 8.7
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter En…
CVE-2026-33622CVE-2026-33622
CVSS 8.8
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary JavaScript e…
CVE-2026-33618CVE-2026-33618
CVSS 8.8
Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse pl…
CVE-2026-33613CVE-2026-33613
CVSS 8.8
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray functi…
CVE-2026-33602CVE-2026-33602
CVSS 8.2
A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading t…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.