89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,701–1,750 of 8,161 in High · page 35 of 164

IDTitleSummary
CVE-2026-3243CVE-2026-3243
CVSS 8.8
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function…
CVE-2026-32422CVE-2026-32422
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind…
CVE-2026-32399CVE-2026-32399
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assis…
CVE-2026-32368CVE-2026-32368
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injec…
CVE-2026-32366CVE-2026-32366
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categories allo…
CVE-2026-32365CVE-2026-32365
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows B…
CVE-2026-32355CVE-2026-32355
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8…
CVE-2026-32321CVE-2026-32321
CVSS 8.8
ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 w…
CVE-2026-32313CVE-2026-32313
CVSS 8.2
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm…
CVE-2026-32302CVE-2026-32302
CVSS 8.1
OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set…
CVE-2026-32300CVE-2026-32300
CVSS 8.1
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0,…
CVE-2026-32296CVE-2026-32296
CVSS 8.2
Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to …
CVE-2026-32277CVE-2026-32277
CVSS 8.7
Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in…
CVE-2026-32276CVE-2026-32276
CVSS 8.8
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0,…
CVE-2026-32255CVE-2026-32255
CVSS 8.6
Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation.…
CVE-2026-32247CVE-2026-32247
CVSS 8.1
Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerabi…
CVE-2026-32241CVE-2026-32241
CVSS 8.8
Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily…
CVE-2026-32231CVE-2026-32231
CVSS 8.2
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request bod…
CVE-2026-32225CVE-2026-32225
CVSS 8.8microsoft
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-32221CVE-2026-32221
CVSS 8.4microsoft
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVE-2026-3220CVE-2026-3220
CVSS 8.8
The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to …
CVE-2026-32190CVE-2026-32190
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-32172CVE-2026-32172
CVSS 8.0
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
CVE-2026-32171CVE-2026-32171
CVSS 8.8
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-32162CVE-2026-32162
CVSS 8.4
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.
CVE-2026-32157CVE-2026-32157
CVSS 8.8microsoft
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-32140CVE-2026-32140
CVSS 8.8
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to l…
CVE-2026-32138CVE-2026-32138
CVSS 8.2
NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability…
CVE-2026-32137CVE-2026-32137
CVSS 8.8
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated …
CVE-2026-32127CVE-2026-32127
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vul…
CVE-2026-32126CVE-2026-32126
CVSS 8.1
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in Con…
CVE-2026-32116CVE-2026-32116
CVSS 8.1
Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wor…
CVE-2026-32110CVE-2026-32110
CVSS 8.3
SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary HTTP requ…
CVE-2026-32107CVE-2026-32107
CVSS 8.8
xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop proce…
CVE-2026-32097CVE-2026-32097
CVSS 8.8
PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrieve or dele…
CVE-2026-32096CVE-2026-32096
CVSS 8.6
Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook h…
CVE-2026-32067CVE-2026-32067
CVSS 8.1
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control for direct message pairing policy that a…
CVE-2026-32060CVE-2026-32060
CVSS 8.8
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configure…
CVE-2026-32059CVE-2026-32059
CVSS 8.8
OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allow…
CVE-2026-32055CVE-2026-32055
CVSS 8.2
OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the w…
CVE-2026-32051CVE-2026-32051
CVSS 8.8
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner…
CVE-2026-32042CVE-2026-32042
CVSS 8.8
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requ…
CVE-2026-32036CVE-2026-32036
CVSS 8.2
OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authentication checks b…
CVE-2026-32034CVE-2026-32034
CVSS 8.1
OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled and the gate…
CVE-2026-32026CVE-2026-32026
CVSS 8.6
OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the host temp…
CVE-2026-32014CVE-2026-32014
CVSS 8.0
OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client wi…
CVE-2026-32013CVE-2026-32013
CVSS 8.8
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows reading and wri…
CVE-2026-32010CVE-2026-32010
CVSS 8.8
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exec.safeBins…
CVE-2026-32007CVE-2026-32007
CVSS 8.1
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox access to m…
CVE-2026-32005CVE-2026-32005
CVSS 8.1
OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including block_action, view_submission, and view_cl…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.