89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,601–1,650 of 8,161 in High · page 33 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-33175 | CVE-2026-33175 CVSS 8.8jupyter | OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass v… |
| CVE-2026-33172 | CVE-2026-33172 CVSS 8.7 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads a… |
| CVE-2026-33154 | CVE-2026-33154 CVSS 8.1 | dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe … |
| CVE-2026-33149 | CVE-2026-33149 CVSS 8.1 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*'… |
| CVE-2026-33142 | CVE-2026-33142 CVSS 8.1hackerbay | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggrega… |
| CVE-2026-33134 | CVE-2026-33134 CVSS 8.8 | WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_… |
| CVE-2026-33125 | CVE-2026-33125 CVSS 8.1 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can del… |
| CVE-2026-33124 | CVE-2026-33124 CVSS 8.8 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to c… |
| CVE-2026-33121 | CVE-2026-33121 CVSS 8.8 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource sa… |
| CVE-2026-33120 | CVE-2026-33120 CVSS 8.8microsoft | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-33115 | CVE-2026-33115 CVSS 8.4microsoft | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-33114 | CVE-2026-33114 CVSS 8.4microsoft | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-33112 | CVE-2026-33112 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-33110 | CVE-2026-33110 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-33084 | CVE-2026-33084 CVSS 8.8 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of… |
| CVE-2026-33083 | CVE-2026-33083 CVSS 8.8 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection pa… |
| CVE-2026-33075 | CVE-2026-33075 CVSS 8.8 | FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and … |
| CVE-2026-33071 | CVE-2026-33071 CVSS 8.8 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml,… |
| CVE-2026-33068 | CVE-2026-33068 CVSS 8.8 | Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/setting… |
| CVE-2026-33055 | CVE-2026-33055 CVSS 8.1 | tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips the PAX size header in cases where the ba… |
| CVE-2026-33053 | CVE-2026-33053 CVSS 8.8 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_k… |
| CVE-2026-33046 | CVE-2026-33046 CVSS 8.8 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabil… |
| CVE-2026-33043 | CVE-2026-33043 CVSS 8.1 | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthentica… |
| CVE-2026-33039 | CVE-2026-33039 CVSS 8.6 | WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal… |
| CVE-2026-33038 | CVE-2026-33038 CVSS 8.1 | WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfigura… |
| CVE-2026-33037 | CVE-2026-33037 CVSS 8.1 | WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the … |
| CVE-2026-33031 | CVE-2026-33031 CVSS 8.1 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API to… |
| CVE-2026-33025 | CVE-2026-33025 CVSS 8.8 | AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'… |
| CVE-2026-33010 | CVE-2026-33010 CVSS 8.8 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true),… |
| CVE-2026-33001 | CVE-2026-33001 CVSS 8.8jenkins | Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted a… |
| CVE-2026-32993 | CVE-2026-32993 CVSS 8.3 | Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header… |
| CVE-2026-32992 | CVE-2026-32992 CVSS 8.2cpanel | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. |
| CVE-2026-32989 | CVE-2026-32989 CVSS 8.8 | Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests… |
| CVE-2026-32971 | CVE-2026-32971 CVSS 7.1openclaw | OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the … |
| CVE-2026-32955 | CVE-2026-32955 CVSS 8.8 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code… |
| CVE-2026-32950 | CVE-2026-32950 CVSS 8.8 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in t… |
| CVE-2026-32942 | CVE-2026-32942 CVSS 8.1 | PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE … |
| CVE-2026-32939 | CVE-2026-32939 CVSS 8.1 | DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic… |
| CVE-2026-32931 | CVE-2026-32931 CVSS 8.8 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function a… |
| CVE-2026-32920 | CVE-2026-32920 CVSS 8.4openclaw | OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code exe… |
| CVE-2026-3292 | CVE-2026-3292 CVSS 8.8 | A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch … |
| CVE-2026-32918 | CVE-2026-32918 CVSS 8.4 | OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or siblin… |
| CVE-2026-32915 | CVE-2026-32915 CVSS 8.8 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against … |
| CVE-2026-32914 | CVE-2026-32914 CVSS 8.8 | OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-authorized non-o… |
| CVE-2026-32892 | CVE-2026-32892 CVSS 8.8 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move funct… |
| CVE-2026-32888 | CVE-2026-32888 CVSS 8.8 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items s… |
| CVE-2026-3288 | CVE-2026-3288 CVSS 8.8 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration … |
| CVE-2026-32877 | CVE-2026-32877 CVSS 8.2 | Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C… |
| CVE-2026-32857 | CVE-2026-32857 CVSS 8.6 | Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network… |
| CVE-2026-32853 | CVE-2026-32853 CVSS 8.1libvncserver_project | LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a… |