89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,801–1,850 of 8,161 in High · page 37 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-3166 | CVE-2026-3166 CVSS 8.8 | A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component htt… |
| CVE-2026-3165 | CVE-2026-3165 CVSS 8.8 | A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component http… |
| CVE-2026-31631 | CVE-2026-31631 CVSS 8.2 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authentic… |
| CVE-2026-31629 | CVE-2026-31629 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_ll… |
| CVE-2026-31622 | CVE-2026-31622 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler The NFC-A anti-col… |
| CVE-2026-31613 | CVE-2026-31613 CVSS 8.1linux | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads parsing symlink error response When a CREATE returns STATUS_ST… |
| CVE-2026-31611 | CVE-2026-31611 CVSS 8.6linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each AC… |
| CVE-2026-31588 | CVE-2026-31588 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use scratch field in MMIO fragment to hold small write values When exiting to u… |
| CVE-2026-31570 | CVE-2026-31570 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: can: gw: fix OOB heap access in cgw_csum_crc8_rel() cgw_csum_crc8_rel() correctly compute… |
| CVE-2026-31558 | CVE-2026-31558 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a … |
| CVE-2026-31553 | CVE-2026-31553 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva +… |
| CVE-2026-31513 | CVE-2026-31513 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req Syzbot reported a … |
| CVE-2026-3150 | CVE-2026-3150 CVSS 8.8 | A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-teacher.php. … |
| CVE-2026-3149 | CVE-2026-3149 CVSS 8.8 | A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/asign-sin… |
| CVE-2026-31476 | CVE-2026-31476 CVSS 8.2linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding reque… |
| CVE-2026-31464 | CVE-2026-31464 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() A malicious or compromised… |
| CVE-2026-31450 | CVE-2026-31450 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_inode_attach_jinode() publishes ei->jinode… |
| CVE-2026-31435 | CVE-2026-31435 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under certain circumstances, all the remaining s… |
| CVE-2026-31433 | CVE-2026-31433 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for compound requests When a compound req… |
| CVE-2026-31432 | CVE-2026-31432 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as … |
| CVE-2026-31431 | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability KEVCVSS 7.8Linux | Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. |
| CVE-2026-31409 | CVE-2026-31409 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding request When a multichannel SMB2_SESSION_SET… |
| CVE-2026-31408 | CVE-2026-31408 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold sco_recv_… |
| CVE-2026-31393 | CVE-2026-31393 CVSS 8.1linux | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_… |
| CVE-2026-31392 | CVE-2026-31392 CVSS 8.1linux | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option Customer reported that some of their krb… |
| CVE-2026-3132 | CVE-2026-3132 CVSS 8.8 | The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_… |
| CVE-2026-31281 | CVE-2026-31281 CVSS 8.0 | Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the appl… |
| CVE-2026-31232 | CVE-2026-31232 CVSS 8.8 | The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its mod… |
| CVE-2026-31225 | CVE-2026-31225 CVSS 8.8 | The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in qu… |
| CVE-2026-31224 | CVE-2026-31224 CVSS 8.8 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifi… |
| CVE-2026-31223 | CVE-2026-31223 CVSS 8.8 | The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class… |
| CVE-2026-31222 | CVE-2026-31222 CVSS 8.8 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loa… |
| CVE-2026-31219 | CVE-2026-31219 CVSS 8.8 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vu… |
| CVE-2026-31218 | CVE-2026-31218 CVSS 8.8 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vu… |
| CVE-2026-31196 | CVE-2026-31196 CVSS 8.8 | OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firmware… |
| CVE-2026-31195 | CVE-2026-31195 CVSS 8.8 | OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France GR140DG Fibre Router with firmware 3GN80… |
| CVE-2026-3108 | CVE-2026-3108 CVSS 8.8 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl comman… |
| CVE-2026-31069 | CVE-2026-31069 CVSS 8.8 | BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and ag… |
| CVE-2026-3105 | CVE-2026-3105 CVSS 8.8 | SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query co… |
| CVE-2026-3102 | CVE-2026-3102 CVSS 8.8 | A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the co… |
| CVE-2026-31019 | CVE-2026-31019 CVSS 8.8dolibarr | In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to sys… |
| CVE-2026-31018 | CVE-2026-31018 CVSS 8.8dolibarr | In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameter… |
| CVE-2026-3101 | CVE-2026-3101 CVSS 8.8 | A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation results in os… |
| CVE-2026-30995 | CVE-2026-30995 CVSS 8.6 | Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint. |
| CVE-2026-30967 | CVE-2026-30967 CVSS 8.8 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authenti… |
| CVE-2026-30958 | CVE-2026-30958 CVSS 7.2hackerbay | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName e… |
| CVE-2026-30949 | CVE-2026-30949 CVSS 8.8 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authent… |
| CVE-2026-30944 | CVE-2026-30944 CVSS 8.8 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows … |
| CVE-2026-30932 | CVE-2026-30932 CVSS 8.8 | Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does… |
| CVE-2026-30920 | CVE-2026-30920 CVSS 8.6 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and ins… |