89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,801–1,850 of 8,161 in High · page 37 of 164

IDTitleSummary
CVE-2026-3166CVE-2026-3166
CVSS 8.8
A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component htt…
CVE-2026-3165CVE-2026-3165
CVSS 8.8
A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component http…
CVE-2026-31631CVE-2026-31631
CVSS 8.2
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authentic…
CVE-2026-31629CVE-2026-31629
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_ll…
CVE-2026-31622CVE-2026-31622
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler The NFC-A anti-col…
CVE-2026-31613CVE-2026-31613
CVSS 8.1linux
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads parsing symlink error response When a CREATE returns STATUS_ST…
CVE-2026-31611CVE-2026-31611
CVSS 8.6linux
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each AC…
CVE-2026-31588CVE-2026-31588
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use scratch field in MMIO fragment to hold small write values When exiting to u…
CVE-2026-31570CVE-2026-31570
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: can: gw: fix OOB heap access in cgw_csum_crc8_rel() cgw_csum_crc8_rel() correctly compute…
CVE-2026-31558CVE-2026-31558
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a …
CVE-2026-31553CVE-2026-31553
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva +…
CVE-2026-31513CVE-2026-31513
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req Syzbot reported a …
CVE-2026-3150CVE-2026-3150
CVSS 8.8
A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-teacher.php. …
CVE-2026-3149CVE-2026-3149
CVSS 8.8
A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/asign-sin…
CVE-2026-31476CVE-2026-31476
CVSS 8.2linux
In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding reque…
CVE-2026-31464CVE-2026-31464
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() A malicious or compromised…
CVE-2026-31450CVE-2026-31450
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_inode_attach_jinode() publishes ei->jinode…
CVE-2026-31435CVE-2026-31435
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under certain circumstances, all the remaining s…
CVE-2026-31433CVE-2026-31433
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for compound requests When a compound req…
CVE-2026-31432CVE-2026-31432
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as …
CVE-2026-31431Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
KEVCVSS 7.8Linux
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CVE-2026-31409CVE-2026-31409
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SET…
CVE-2026-31408CVE-2026-31408
CVSS 8.8linux
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold sco_recv_…
CVE-2026-31393CVE-2026-31393
CVSS 8.1linux
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_…
CVE-2026-31392CVE-2026-31392
CVSS 8.1linux
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Customer reported that some of their krb…
CVE-2026-3132CVE-2026-3132
CVSS 8.8
The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_…
CVE-2026-31281CVE-2026-31281
CVSS 8.0
Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the appl…
CVE-2026-31232CVE-2026-31232
CVSS 8.8
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its mod…
CVE-2026-31225CVE-2026-31225
CVSS 8.8
The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in qu…
CVE-2026-31224CVE-2026-31224
CVSS 8.8
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifi…
CVE-2026-31223CVE-2026-31223
CVSS 8.8
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class…
CVE-2026-31222CVE-2026-31222
CVSS 8.8
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loa…
CVE-2026-31219CVE-2026-31219
CVSS 8.8
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vu…
CVE-2026-31218CVE-2026-31218
CVSS 8.8
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vu…
CVE-2026-31196CVE-2026-31196
CVSS 8.8
OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firmware…
CVE-2026-31195CVE-2026-31195
CVSS 8.8
OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firmware 3GN80…
CVE-2026-3108CVE-2026-3108
CVSS 8.8
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl comman…
CVE-2026-31069CVE-2026-31069
CVSS 8.8
BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and ag…
CVE-2026-3105CVE-2026-3105
CVSS 8.8
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query co…
CVE-2026-3102CVE-2026-3102
CVSS 8.8
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the co…
CVE-2026-31019CVE-2026-31019
CVSS 8.8dolibarr
In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to sys…
CVE-2026-31018CVE-2026-31018
CVSS 8.8dolibarr
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameter…
CVE-2026-3101CVE-2026-3101
CVSS 8.8
A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation results in os…
CVE-2026-30995CVE-2026-30995
CVSS 8.6
Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.
CVE-2026-30967CVE-2026-30967
CVSS 8.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authenti…
CVE-2026-30958CVE-2026-30958
CVSS 7.2hackerbay
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName e…
CVE-2026-30949CVE-2026-30949
CVSS 8.8
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authent…
CVE-2026-30944CVE-2026-30944
CVSS 8.8
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows …
CVE-2026-30932CVE-2026-30932
CVSS 8.8
Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does…
CVE-2026-30920CVE-2026-30920
CVSS 8.6
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and ins…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.