89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,601–1,650 of 8,161 in High · page 33 of 164

IDTitleSummary
CVE-2026-33175CVE-2026-33175
CVSS 8.8jupyter
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass v…
CVE-2026-33172CVE-2026-33172
CVSS 8.7
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads a…
CVE-2026-33154CVE-2026-33154
CVSS 8.1
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe …
CVE-2026-33149CVE-2026-33149
CVSS 8.1
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*'…
CVE-2026-33142CVE-2026-33142
CVSS 8.1hackerbay
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggrega…
CVE-2026-33134CVE-2026-33134
CVSS 8.8
WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_…
CVE-2026-33125CVE-2026-33125
CVSS 8.1
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can del…
CVE-2026-33124CVE-2026-33124
CVSS 8.8
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to c…
CVE-2026-33121CVE-2026-33121
CVSS 8.8
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource sa…
CVE-2026-33120CVE-2026-33120
CVSS 8.8microsoft
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-33115CVE-2026-33115
CVSS 8.4microsoft
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-33114CVE-2026-33114
CVSS 8.4microsoft
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-33112CVE-2026-33112
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-33110CVE-2026-33110
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-33084CVE-2026-33084
CVSS 8.8
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of…
CVE-2026-33083CVE-2026-33083
CVSS 8.8
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection pa…
CVE-2026-33075CVE-2026-33075
CVSS 8.8
FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and …
CVE-2026-33071CVE-2026-33071
CVSS 8.8
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml,…
CVE-2026-33068CVE-2026-33068
CVSS 8.8
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/setting…
CVE-2026-33055CVE-2026-33055
CVSS 8.1
tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips the PAX size header in cases where the ba…
CVE-2026-33053CVE-2026-33053
CVSS 8.8
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_k…
CVE-2026-33046CVE-2026-33046
CVSS 8.8
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabil…
CVE-2026-33043CVE-2026-33043
CVSS 8.1
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthentica…
CVE-2026-33039CVE-2026-33039
CVSS 8.6
WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal…
CVE-2026-33038CVE-2026-33038
CVSS 8.1
WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfigura…
CVE-2026-33037CVE-2026-33037
CVSS 8.1
WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the …
CVE-2026-33031CVE-2026-33031
CVSS 8.1
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API to…
CVE-2026-33025CVE-2026-33025
CVSS 8.8
AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'…
CVE-2026-33010CVE-2026-33010
CVSS 8.8
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true),…
CVE-2026-33001CVE-2026-33001
CVSS 8.8jenkins
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted a…
CVE-2026-32993CVE-2026-32993
CVSS 8.3
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header…
CVE-2026-32992CVE-2026-32992
CVSS 8.2cpanel
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
CVE-2026-32989CVE-2026-32989
CVSS 8.8
Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests…
CVE-2026-32971CVE-2026-32971
CVSS 7.1openclaw
OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the …
CVE-2026-32955CVE-2026-32955
CVSS 8.8
SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code…
CVE-2026-32950CVE-2026-32950
CVSS 8.8
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in t…
CVE-2026-32942CVE-2026-32942
CVSS 8.1
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE …
CVE-2026-32939CVE-2026-32939
CVSS 8.1
DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic…
CVE-2026-32931CVE-2026-32931
CVSS 8.8
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function a…
CVE-2026-32920CVE-2026-32920
CVSS 8.4openclaw
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code exe…
CVE-2026-3292CVE-2026-3292
CVSS 8.8
A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch …
CVE-2026-32918CVE-2026-32918
CVSS 8.4
OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandboxed subagents to access parent or siblin…
CVE-2026-32915CVE-2026-32915
CVSS 8.8
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagents control surface and resolve against …
CVE-2026-32914CVE-2026-32914
CVSS 8.8
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handlers that allows command-authorized non-o…
CVE-2026-32892CVE-2026-32892
CVSS 8.8
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move funct…
CVE-2026-32888CVE-2026-32888
CVSS 8.8
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items s…
CVE-2026-3288CVE-2026-3288
CVSS 8.8
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration …
CVE-2026-32877CVE-2026-32877
CVSS 8.2
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication code value (C…
CVE-2026-32857CVE-2026-32857
CVSS 8.6
Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network…
CVE-2026-32853CVE-2026-32853
CVSS 8.1libvncserver_project
LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.