89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,701–1,750 of 8,161 in High · page 35 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-3243 | CVE-2026-3243 CVSS 8.8 | The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function… |
| CVE-2026-32422 | CVE-2026-32422 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind… |
| CVE-2026-32399 | CVE-2026-32399 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assis… |
| CVE-2026-32368 | CVE-2026-32368 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injec… |
| CVE-2026-32366 | CVE-2026-32366 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categories allo… |
| CVE-2026-32365 | CVE-2026-32365 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows B… |
| CVE-2026-32355 | CVE-2026-32355 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8… |
| CVE-2026-32321 | CVE-2026-32321 CVSS 8.8 | ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 w… |
| CVE-2026-32313 | CVE-2026-32313 CVSS 8.2 | xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm… |
| CVE-2026-32302 | CVE-2026-32302 CVSS 8.1 | OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set… |
| CVE-2026-32300 | CVE-2026-32300 CVSS 8.1 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0,… |
| CVE-2026-32296 | CVE-2026-32296 CVSS 8.2 | Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to … |
| CVE-2026-32277 | CVE-2026-32277 CVSS 8.7 | Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in… |
| CVE-2026-32276 | CVE-2026-32276 CVSS 8.8 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0,… |
| CVE-2026-32255 | CVE-2026-32255 CVSS 8.6 | Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation.… |
| CVE-2026-32247 | CVE-2026-32247 CVSS 8.1 | Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerabi… |
| CVE-2026-32241 | CVE-2026-32241 CVSS 8.8 | Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily… |
| CVE-2026-32231 | CVE-2026-32231 CVSS 8.2 | ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request bod… |
| CVE-2026-32225 | CVE-2026-32225 CVSS 8.8microsoft | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-32221 | CVE-2026-32221 CVSS 8.4microsoft | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
| CVE-2026-3220 | CVE-2026-3220 CVSS 8.8 | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to … |
| CVE-2026-32190 | CVE-2026-32190 CVSS 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2026-32172 | CVE-2026-32172 CVSS 8.0 | Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. |
| CVE-2026-32171 | CVE-2026-32171 CVSS 8.8 | Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-32162 | CVE-2026-32162 CVSS 8.4 | Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-32157 | CVE-2026-32157 CVSS 8.8microsoft | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-32140 | CVE-2026-32140 CVSS 8.8 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to l… |
| CVE-2026-32138 | CVE-2026-32138 CVSS 8.2 | NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability… |
| CVE-2026-32137 | CVE-2026-32137 CVSS 8.8 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated … |
| CVE-2026-32127 | CVE-2026-32127 CVSS 8.8 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vul… |
| CVE-2026-32126 | CVE-2026-32126 CVSS 8.1 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in Con… |
| CVE-2026-32116 | CVE-2026-32116 CVSS 8.1 | Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wor… |
| CVE-2026-32110 | CVE-2026-32110 CVSS 8.3 | SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary HTTP requ… |
| CVE-2026-32107 | CVE-2026-32107 CVSS 8.8 | xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop proce… |
| CVE-2026-32097 | CVE-2026-32097 CVSS 8.8 | PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrieve or dele… |
| CVE-2026-32096 | CVE-2026-32096 CVSS 8.6 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook h… |
| CVE-2026-32067 | CVE-2026-32067 CVSS 8.1 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that a… |
| CVE-2026-32060 | CVE-2026-32060 CVSS 8.8 | OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configure… |
| CVE-2026-32059 | CVE-2026-32059 CVSS 8.8 | OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allow… |
| CVE-2026-32055 | CVE-2026-32055 CVSS 8.2 | OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the w… |
| CVE-2026-32051 | CVE-2026-32051 CVSS 8.8 | OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner… |
| CVE-2026-32042 | CVE-2026-32042 CVSS 8.8 | OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requ… |
| CVE-2026-32036 | CVE-2026-32036 CVSS 8.2 | OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authentication checks b… |
| CVE-2026-32034 | CVE-2026-32034 CVSS 8.1 | OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled and the gate… |
| CVE-2026-32026 | CVE-2026-32026 CVSS 8.6 | OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the host temp… |
| CVE-2026-32014 | CVE-2026-32014 CVSS 8.0 | OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client wi… |
| CVE-2026-32013 | CVE-2026-32013 CVSS 8.8 | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and wri… |
| CVE-2026-32010 | CVE-2026-32010 CVSS 8.8 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins… |
| CVE-2026-32007 | CVE-2026-32007 CVSS 8.1 | OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to m… |
| CVE-2026-32005 | CVE-2026-32005 CVSS 8.1 | OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, and view_cl… |