89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,651–1,700 of 8,161 in High · page 34 of 164

IDTitleSummary
CVE-2026-32845CVE-2026-32845
CVSS 8.4
cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers …
CVE-2026-32841CVE-2026-32841
CVSS 8.1
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the managem…
CVE-2026-32813CVE-2026-32813
CVSS 8.0
Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature…
CVE-2026-32808CVE-2026-32808
CVSS 8.1
pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verificatio…
CVE-2026-32763CVE-2026-32763
CVSS 8.2
Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL a…
CVE-2026-32759CVE-2026-32759
CVSS 8.1filebrowser
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x…
CVE-2026-32756CVE-2026-32756
CVSS 8.8
Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files…
CVE-2026-32752CVE-2026-32752
CVSS 8.1
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a br…
CVE-2026-3275CVE-2026-3275
CVSS 8.8
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing…
CVE-2026-32740CVE-2026-32740
CVSS 8.8struktur
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile com…
CVE-2026-3274CVE-2026-3274
CVSS 8.8
A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component htt…
CVE-2026-32730CVE-2026-32730
CVSS 8.1
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/in…
CVE-2026-3273CVE-2026-3273
CVSS 8.8
A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the…
CVE-2026-32729CVE-2026-32729
CVSS 8.8
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting,…
CVE-2026-32726CVE-2026-32726
CVSS 8.1scitokens
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypa…
CVE-2026-32725CVE-2026-32725
CVSS 8.3scitokens
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypa…
CVE-2026-3272CVE-2026-3272
CVSS 8.8
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. Th…
CVE-2026-32708CVE-2026-32708
CVSS 8.0
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload …
CVE-2026-32706CVE-2026-32706
CVSS 8.1
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it …
CVE-2026-3270CVE-2026-3270
CVSS 8.8
A vulnerability has been found in psi-probe PSI Probe up to 5.3.0. This affects the function lookup of the file psi-probe-core/src/main/java/psiprobe/tools/Who…
CVE-2026-32693CVE-2026-32693
CVSS 8.8
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret c…
CVE-2026-32673CVE-2026-32673
CVSS 8.7f5
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute ar…
CVE-2026-32658CVE-2026-32658
CVSS 8.8
Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentia…
CVE-2026-3265CVE-2026-3265
CVSS 8.8
A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of…
CVE-2026-32643CVE-2026-32643
CVSS 8.7f5
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify con…
CVE-2026-3264CVE-2026-3264
CVSS 8.8
A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of th…
CVE-2026-32634CVE-2026-32634
CVSS 8.1
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised s…
CVE-2026-3263CVE-2026-3263
CVSS 8.8
A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functional…
CVE-2026-32628CVE-2026-32628
CVSS 8.8
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL inject…
CVE-2026-32627CVE-2026-32627
CVSS 8.1
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set…
CVE-2026-32623CVE-2026-32623
CVSS 8.1
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sess…
CVE-2026-32622CVE-2026-32622
CVSS 8.8
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability th…
CVE-2026-3262CVE-2026-3262
CVSS 8.8
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component A…
CVE-2026-32616CVE-2026-32616
CVSS 8.2
Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verifi…
CVE-2026-32610CVE-2026-32610
CVSS 8.1
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuratio…
CVE-2026-32600CVE-2026-32600
CVSS 8.2
xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-1…
CVE-2026-32590CVE-2026-32590
CVSS 7.1redhat
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a for…
CVE-2026-32534CVE-2026-32534
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL I…
CVE-2026-32531CVE-2026-32531
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local Fi…
CVE-2026-32530CVE-2026-32530
CVSS 8.8
Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <…
CVE-2026-32522CVE-2026-32522
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-…
CVE-2026-32516CVE-2026-32516
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows…
CVE-2026-32513CVE-2026-32513
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archi…
CVE-2026-32505CVE-2026-32505
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Kiddy kiddy allows PHP Loca…
CVE-2026-32504CVE-2026-32504
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS VintWood vintwood allows PH…
CVE-2026-32503CVE-2026-32503
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Trendustry trendustry allow…
CVE-2026-32500CVE-2026-32500
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS MetaMax metamax allows PHP …
CVE-2026-32488CVE-2026-32488
CVSS 8.1
Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration:…
CVE-2026-32484CVE-2026-32484
CVSS 8.8
Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.
CVE-2026-32433CVE-2026-32433
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-wi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.