89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,651–1,700 of 8,161 in High · page 34 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-32845 | CVE-2026-32845 CVSS 8.4 | cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers … |
| CVE-2026-32841 | CVE-2026-32841 CVSS 8.1 | Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the managem… |
| CVE-2026-32813 | CVE-2026-32813 CVSS 8.0 | Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature… |
| CVE-2026-32808 | CVE-2026-32808 CVSS 8.1 | pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verificatio… |
| CVE-2026-32763 | CVE-2026-32763 CVSS 8.2 | Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL a… |
| CVE-2026-32759 | CVE-2026-32759 CVSS 8.1filebrowser | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x… |
| CVE-2026-32756 | CVE-2026-32756 CVSS 8.8 | Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files… |
| CVE-2026-32752 | CVE-2026-32752 CVSS 8.1 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a br… |
| CVE-2026-3275 | CVE-2026-3275 CVSS 8.8 | A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing… |
| CVE-2026-32740 | CVE-2026-32740 CVSS 8.8struktur | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile com… |
| CVE-2026-3274 | CVE-2026-3274 CVSS 8.8 | A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component htt… |
| CVE-2026-32730 | CVE-2026-32730 CVSS 8.1 | ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/in… |
| CVE-2026-3273 | CVE-2026-3273 CVSS 8.8 | A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the… |
| CVE-2026-32729 | CVE-2026-32729 CVSS 8.8 | Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting,… |
| CVE-2026-32726 | CVE-2026-32726 CVSS 8.1scitokens | SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypa… |
| CVE-2026-32725 | CVE-2026-32725 CVSS 8.3scitokens | SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypa… |
| CVE-2026-3272 | CVE-2026-3272 CVSS 8.8 | A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. Th… |
| CVE-2026-32708 | CVE-2026-32708 CVSS 8.0 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload … |
| CVE-2026-32706 | CVE-2026-32706 CVSS 8.1 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it … |
| CVE-2026-3270 | CVE-2026-3270 CVSS 8.8 | A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-probe-core/src/main/java/psiprobe/tools/Who… |
| CVE-2026-32693 | CVE-2026-32693 CVSS 8.8 | In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret c… |
| CVE-2026-32673 | CVE-2026-32673 CVSS 8.7f5 | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute ar… |
| CVE-2026-32658 | CVE-2026-32658 CVSS 8.8 | Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentia… |
| CVE-2026-3265 | CVE-2026-3265 CVSS 8.8 | A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of… |
| CVE-2026-32643 | CVE-2026-32643 CVSS 8.7f5 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify con… |
| CVE-2026-3264 | CVE-2026-3264 CVSS 8.8 | A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of th… |
| CVE-2026-32634 | CVE-2026-32634 CVSS 8.1 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised s… |
| CVE-2026-3263 | CVE-2026-3263 CVSS 8.8 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functional… |
| CVE-2026-32628 | CVE-2026-32628 CVSS 8.8 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL inject… |
| CVE-2026-32627 | CVE-2026-32627 CVSS 8.1 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set… |
| CVE-2026-32623 | CVE-2026-32623 CVSS 8.1 | xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sess… |
| CVE-2026-32622 | CVE-2026-32622 CVSS 8.8 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability th… |
| CVE-2026-3262 | CVE-2026-3262 CVSS 8.8 | A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component A… |
| CVE-2026-32616 | CVE-2026-32616 CVSS 8.2 | Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verifi… |
| CVE-2026-32610 | CVE-2026-32610 CVSS 8.1 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuratio… |
| CVE-2026-32600 | CVE-2026-32600 CVSS 8.2 | xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-1… |
| CVE-2026-32590 | CVE-2026-32590 CVSS 7.1redhat | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a for… |
| CVE-2026-32534 | CVE-2026-32534 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL I… |
| CVE-2026-32531 | CVE-2026-32531 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local Fi… |
| CVE-2026-32530 | CVE-2026-32530 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <… |
| CVE-2026-32522 | CVE-2026-32522 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-… |
| CVE-2026-32516 | CVE-2026-32516 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows… |
| CVE-2026-32513 | CVE-2026-32513 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archi… |
| CVE-2026-32505 | CVE-2026-32505 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Kiddy kiddy allows PHP Loca… |
| CVE-2026-32504 | CVE-2026-32504 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS VintWood vintwood allows PH… |
| CVE-2026-32503 | CVE-2026-32503 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Trendustry trendustry allow… |
| CVE-2026-32500 | CVE-2026-32500 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS MetaMax metamax allows PHP … |
| CVE-2026-32488 | CVE-2026-32488 CVSS 8.1 | Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration:… |
| CVE-2026-32484 | CVE-2026-32484 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26. |
| CVE-2026-32433 | CVE-2026-32433 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-wi… |