89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,751–1,800 of 8,161 in High · page 36 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-32004 | CVE-2026-32004 CVSS 8.2 | OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization depth mism… |
| CVE-2026-31998 | CVE-2026-31998 CVSS 8.6 | OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist wit… |
| CVE-2026-31992 | CVE-2026-31992 CVSS 8.8 | OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows authenticated operators to execute unintend… |
| CVE-2026-31971 | CVE-2026-31971 CVSS 8.1 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety o… |
| CVE-2026-31970 | CVE-2026-31970 CVSS 8.1 | HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading fu… |
| CVE-2026-31969 | CVE-2026-31969 CVSS 8.1 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety o… |
| CVE-2026-31968 | CVE-2026-31968 CVSS 8.1 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety o… |
| CVE-2026-31965 | CVE-2026-31965 CVSS 8.2 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_dec… |
| CVE-2026-31963 | CVE-2026-31963 CVSS 8.1 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of… |
| CVE-2026-31962 | CVE-2026-31962 CVSS 8.8 | HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most align… |
| CVE-2026-31952 | CVE-2026-31952 CVSS 8.1 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQ… |
| CVE-2026-31943 | CVE-2026-31943 CVSS 8.5 | LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped… |
| CVE-2026-31940 | CVE-2026-31940 CVSS 8.8 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to… |
| CVE-2026-31939 | CVE-2026-31939 CVSS 8.3 | Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. Us… |
| CVE-2026-31922 | CVE-2026-31922 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Injection.This i… |
| CVE-2026-31921 | CVE-2026-31921 CVSS 8.2 | Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Confi… |
| CVE-2026-3192 | CVE-2026-3192 CVSS 8.1 | A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the compon… |
| CVE-2026-31917 | CVE-2026-31917 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects… |
| CVE-2026-31913 | CVE-2026-31913 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue af… |
| CVE-2026-31895 | CVE-2026-31895 CVSS 8.8 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vu… |
| CVE-2026-31892 | CVE-2026-31892 CVSS 8.1argoproj | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user … |
| CVE-2026-31889 | CVE-2026-31889 CVSS 8.9 | Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditi… |
| CVE-2026-31862 | CVE-2026-31862 CVSS 8.8 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoin… |
| CVE-2026-31861 | CVE-2026-31861 CVSS 8.8 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoin… |
| CVE-2026-31858 | CVE-2026-31858 CVSS 8.8 | Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementInd… |
| CVE-2026-31857 | CVE-2026-31857 CVSS 8.8 | Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The B… |
| CVE-2026-31854 | CVE-2026-31854 CVSS 8.8 | Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to f… |
| CVE-2026-31847 | CVE-2026-31847 CVSS 8.8nexxtsolutions | Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Teln… |
| CVE-2026-31844 | CVE-2026-31844 CVSS 8.8koha | An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper… |
| CVE-2026-31836 | CVE-2026-31836 CVSS 8.1 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful … |
| CVE-2026-31829 | CVE-2026-31829 CVSS 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflo… |
| CVE-2026-31828 | CVE-2026-31828 CVSS 8.8 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentica… |
| CVE-2026-31817 | CVE-2026-31817 CVSS 8.5 | OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution … |
| CVE-2026-31805 | CVE-2026-31805 CVSS 8.2 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plugin allowe… |
| CVE-2026-3179 | CVE-2026-3179 CVSS 8.1 | The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacke… |
| CVE-2026-31788 | CVE-2026-31788 CVSS 8.2 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue a… |
| CVE-2026-31779 | CVE-2026-31779 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() T… |
| CVE-2026-31773 | CVE-2026-31773 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy res… |
| CVE-2026-31771 | CVE-2026-31771 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: move wake reason storage into validated event handlers hci_store_wa… |
| CVE-2026-31739 | CVE-2026-31739 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The tegra crypto driver failed to set the CR… |
| CVE-2026-31735 | CVE-2026-31735 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a large mapping unmap has the odd behavi… |
| CVE-2026-3172 | CVE-2026-3172 CVSS 8.1 | Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the da… |
| CVE-2026-31717 | CVE-2026-31717 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate owner of durable handle on reconnect Currently, ksmbd does not verify if … |
| CVE-2026-31712 | CVE-2026-31712 CVSS 8.3linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: require minimum ACE size in smb_check_perm_dacl() Both ACE-walk loops in smb_check… |
| CVE-2026-31709 | CVE-2026-31709 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and … |
| CVE-2026-31708 | CVE-2026-31708 CVSS 8.1linux | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info(… |
| CVE-2026-31706 | CVE-2026-31706 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() smb_inherit_dacl() tru… |
| CVE-2026-3169 | CVE-2026-3169 CVSS 8.8 | A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the comp… |
| CVE-2026-3168 | CVE-2026-3168 CVSS 8.8 | A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component http… |
| CVE-2026-3167 | CVE-2026-3167 CVSS 8.8 | A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the co… |