87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,551–1,600 of 8,161 in High · page 32 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-33599 | CVE-2026-33599 CVSS 8.1 | A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newS… |
| CVE-2026-33588 | CVE-2026-33588 CVSS 8.1 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker cont… |
| CVE-2026-33583 | CVE-2026-33583 CVSS 8.7 | Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP … |
| CVE-2026-33581 | CVE-2026-33581 CVSS 6.5openclaw | OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and… |
| CVE-2026-33577 | CVE-2026-33577 CVSS 8.1openclaw | OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to appr… |
| CVE-2026-33573 | CVE-2026-33573 CVSS 8.8 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permi… |
| CVE-2026-3357 | CVE-2026-3357 CVSS 8.8langflow | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default sett… |
| CVE-2026-33549 | CVE-2026-33549 CVSS 8.8 | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the editing of an author data structure be… |
| CVE-2026-33529 | CVE-2026-33529 CVSS 8.8 | Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the configuration … |
| CVE-2026-33510 | CVE-2026-33510 CVSS 8.8 | Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The… |
| CVE-2026-33509 | CVE-2026-33509 CVSS 8.8 | pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint al… |
| CVE-2026-33507 | CVE-2026-33507 CVSS 8.8 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload a… |
| CVE-2026-33506 | CVE-2026-33506 CVSS 8.8 | Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based … |
| CVE-2026-33502 | CVE-2026-33502 CVSS 8.2 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Liv… |
| CVE-2026-33496 | CVE-2026-33496 CVSS 8.1 | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior … |
| CVE-2026-33493 | CVE-2026-33493 CVSS 8.1 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` … |
| CVE-2026-33488 | CVE-2026-33488 CVSS 8.1 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system gen… |
| CVE-2026-33482 | CVE-2026-33482 CVSS 8.1 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.… |
| CVE-2026-33480 | CVE-2026-33480 CVSS 8.6 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped … |
| CVE-2026-33479 | CVE-2026-33479 CVSS 8.8 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user i… |
| CVE-2026-33468 | CVE-2026-33468 CVSS 8.1 | Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quote… |
| CVE-2026-33442 | CVE-2026-33442 CVSS 8.1 | Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method in Kysely's query compiler escapes sing… |
| CVE-2026-33435 | CVE-2026-33435 CVSS 8.0 | Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to… |
| CVE-2026-33433 | CVE-2026-33433 CVSS 8.8traefik | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HT… |
| CVE-2026-33413 | CVE-2026-33413 CVSS 8.8 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authenti… |
| CVE-2026-33373 | CVE-2026-33373 CVSS 8.8 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the i… |
| CVE-2026-33362 | CVE-2026-33362 CVSS 8.6 | In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple se… |
| CVE-2026-33346 | CVE-2026-33346 CVSS 8.7 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) … |
| CVE-2026-33344 | CVE-2026-33344 CVSS 8.1 | Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDAGName to C… |
| CVE-2026-3334 | CVE-2026-3334 CVSS 8.8 | The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versi… |
| CVE-2026-33336 | CVE-2026-33336 CVSS 8.8 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper ena… |
| CVE-2026-33335 | CVE-2026-33335 CVSS 8.0 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper pas… |
| CVE-2026-33329 | CVE-2026-33329 CVSS 8.1 | FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js … |
| CVE-2026-33324 | CVE-2026-33324 CVSS 8.8fit2cloud | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to… |
| CVE-2026-33318 | CVE-2026-33318 CVSS 8.8 | Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migr… |
| CVE-2026-33317 | CVE-2026-33317 CVSS 8.7trustedfirmware | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technolog… |
| CVE-2026-33316 | CVE-2026-33316 CVSS 8.1 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password reset logic allows disabled users to regai… |
| CVE-2026-33310 | CVE-2026-33310 CVSS 8.8 | Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default values appe… |
| CVE-2026-33302 | CVE-2026-33302 CVSS 8.1 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zh… |
| CVE-2026-33301 | CVE-2026-33301 CVSS 8.1 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounte… |
| CVE-2026-33293 | CVE-2026-33293 CVSS 8.1 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly t… |
| CVE-2026-33288 | CVE-2026-33288 CVSS 8.8 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection v… |
| CVE-2026-33277 | CVE-2026-33277 CVSS 8.8 | An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. |
| CVE-2026-33243 | CVE-2026-33243 CVSS 8.2pengutronix | barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit… |
| CVE-2026-3324 | CVE-2026-3324 CVSS 8.2zohocorp | Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration. |
| CVE-2026-33236 | CVE-2026-33236 CVSS 8.1nltk | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Proc… |
| CVE-2026-33226 | CVE-2026-33226 CVSS 8.7 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview … |
| CVE-2026-33208 | CVE-2026-33208 CVSS 8.8 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpo… |
| CVE-2026-33207 | CVE-2026-33207 CVSS 8.8 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTa… |
| CVE-2026-33191 | CVE-2026-33191 CVSS 8.6 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to null byte injection … |