89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,751–1,800 of 8,161 in High · page 36 of 164

IDTitleSummary
CVE-2026-32004CVE-2026-32004
CVSS 8.2
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization depth mism…
CVE-2026-31998CVE-2026-31998
CVSS 8.6
OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist wit…
CVE-2026-31992CVE-2026-31992
CVSS 8.8
OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows authenticated operators to execute unintend…
CVE-2026-31971CVE-2026-31971
CVSS 8.1
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety o…
CVE-2026-31970CVE-2026-31970
CVSS 8.1
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading fu…
CVE-2026-31969CVE-2026-31969
CVSS 8.1
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety o…
CVE-2026-31968CVE-2026-31968
CVSS 8.1
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety o…
CVE-2026-31965CVE-2026-31965
CVSS 8.2
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_dec…
CVE-2026-31963CVE-2026-31963
CVSS 8.1
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of…
CVE-2026-31962CVE-2026-31962
CVSS 8.8
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most align…
CVE-2026-31952CVE-2026-31952
CVSS 8.1
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQ…
CVE-2026-31943CVE-2026-31943
CVSS 8.5
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped…
CVE-2026-31940CVE-2026-31940
CVSS 8.8
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to…
CVE-2026-31939CVE-2026-31939
CVSS 8.3
Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. Us…
CVE-2026-31922CVE-2026-31922
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Injection.This i…
CVE-2026-31921CVE-2026-31921
CVSS 8.2
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Confi…
CVE-2026-3192CVE-2026-3192
CVSS 8.1
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the compon…
CVE-2026-31917CVE-2026-31917
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects…
CVE-2026-31913CVE-2026-31913
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue af…
CVE-2026-31895CVE-2026-31895
CVSS 8.8
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vu…
CVE-2026-31892CVE-2026-31892
CVSS 8.1argoproj
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user …
CVE-2026-31889CVE-2026-31889
CVSS 8.9
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditi…
CVE-2026-31862CVE-2026-31862
CVSS 8.8
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoin…
CVE-2026-31861CVE-2026-31861
CVSS 8.8
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoin…
CVE-2026-31858CVE-2026-31858
CVSS 8.8
Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementInd…
CVE-2026-31857CVE-2026-31857
CVSS 8.8
Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The B…
CVE-2026-31854CVE-2026-31854
CVSS 8.8
Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to f…
CVE-2026-31847CVE-2026-31847
CVSS 8.8nexxtsolutions
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Teln…
CVE-2026-31844CVE-2026-31844
CVSS 8.8koha
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper…
CVE-2026-31836CVE-2026-31836
CVSS 8.1
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful …
CVE-2026-31829CVE-2026-31829
CVSS 8.8
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflo…
CVE-2026-31828CVE-2026-31828
CVSS 8.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentica…
CVE-2026-31817CVE-2026-31817
CVSS 8.5
OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution …
CVE-2026-31805CVE-2026-31805
CVSS 8.2
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plugin allowe…
CVE-2026-3179CVE-2026-3179
CVSS 8.1
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacke…
CVE-2026-31788CVE-2026-31788
CVSS 8.2
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue a…
CVE-2026-31779CVE-2026-31779
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() T…
CVE-2026-31773CVE-2026-31773
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy res…
CVE-2026-31771CVE-2026-31771
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: move wake reason storage into validated event handlers hci_store_wa…
CVE-2026-31739CVE-2026-31739
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The tegra crypto driver failed to set the CR…
CVE-2026-31735CVE-2026-31735
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a large mapping unmap has the odd behavi…
CVE-2026-3172CVE-2026-3172
CVSS 8.1
Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the da…
CVE-2026-31717CVE-2026-31717
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate owner of durable handle on reconnect Currently, ksmbd does not verify if …
CVE-2026-31712CVE-2026-31712
CVSS 8.3linux
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require minimum ACE size in smb_check_perm_dacl() Both ACE-walk loops in smb_check…
CVE-2026-31709CVE-2026-31709
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and …
CVE-2026-31708CVE-2026-31708
CVSS 8.1linux
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info(…
CVE-2026-31706CVE-2026-31706
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() smb_inherit_dacl() tru…
CVE-2026-3169CVE-2026-3169
CVSS 8.8
A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the comp…
CVE-2026-3168CVE-2026-3168
CVSS 8.8
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component http…
CVE-2026-3167CVE-2026-3167
CVSS 8.8
A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the co…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.