89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,851–1,900 of 8,161 in High · page 38 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-30914 | CVE-2026-30914 CVSS 8.1 | SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handler… |
| CVE-2026-30911 | CVE-2026-30911 CVSS 8.1 | Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authe… |
| CVE-2026-30898 | CVE-2026-30898 CVSS 8.8 | An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to es… |
| CVE-2026-30881 | CVE-2026-30881 CVSS 8.8 | Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters d… |
| CVE-2026-30875 | CVE-2026-30875 CVSS 8.8 | Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated us… |
| CVE-2026-30868 | CVE-2026-30868 CVSS 8.1 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are acces… |
| CVE-2026-30861 | CVE-2026-30861 CVSS 8.8 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenti… |
| CVE-2026-30855 | CVE-2026-30855 CVSS 8.8 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant … |
| CVE-2026-30853 | CVE-2026-30853 CVSS 8.2 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the Rock… |
| CVE-2026-30851 | CVE-2026-30851 CVSS 8.8 | Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-… |
| CVE-2026-3085 | CVE-2026-3085 CVSS 8.8gstreamer | GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on … |
| CVE-2026-30845 | CVE-2026-30845 CVSS 8.2 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data… |
| CVE-2026-30844 | CVE-2026-30844 CVSS 8.1 | Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. … |
| CVE-2026-30840 | CVE-2026-30840 CVSS 8.8 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notifica… |
| CVE-2026-3083 | CVE-2026-3083 CVSS 8.8gstreamer | GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
| CVE-2026-30823 | CVE-2026-30823 CVSS 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to ac… |
| CVE-2026-30820 | CVE-2026-30820 CVSS 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the … |
| CVE-2026-30818 | CVE-2026-30818 CVSS 8.0tp-link | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code whe… |
| CVE-2026-30815 | CVE-2026-30815 CVSS 8.0tp-link | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands wh… |
| CVE-2026-30814 | CVE-2026-30814 CVSS 8.0tp-link | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and… |
| CVE-2026-30813 | CVE-2026-30813 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 7… |
| CVE-2026-30810 | CVE-2026-30810 CVSS 8.8 | Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800 |
| CVE-2026-30809 | CVE-2026-30809 CVSS 8.8 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandor… |
| CVE-2026-30808 | CVE-2026-30808 CVSS 8.1 | Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800 |
| CVE-2026-30807 | CVE-2026-30807 CVSS 8.8 | Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 thro… |
| CVE-2026-30806 | CVE-2026-30806 CVSS 8.8 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS:… |
| CVE-2026-30797 | CVE-2026-30797 CVSS 8.1 | Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, conf… |
| CVE-2026-30794 | CVE-2026-30794 CVSS 8.1 | Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS t… |
| CVE-2026-30792 | CVE-2026-30792 CVSS 8.1 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config op… |
| CVE-2026-30711 | CVE-2026-30711 CVSS 8.8 | Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-a… |
| CVE-2026-3071 | CVE-2026-3071 CVSS 8.4 | Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a m… |
| CVE-2026-30707 | CVE-2026-30707 CVSS 8.1 | An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET Page… |
| CVE-2026-3067 | CVE-2026-3067 CVSS 8.8 | A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/… |
| CVE-2026-3066 | CVE-2026-3066 CVSS 8.8 | A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/jav… |
| CVE-2026-3065 | CVE-2026-3065 CVSS 8.8 | A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the… |
| CVE-2026-3064 | CVE-2026-3064 CVSS 8.8 | A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreateService.ja… |
| CVE-2026-30635 | CVE-2026-30635 CVSS 8.1 | Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTra… |
| CVE-2026-30624 | CVE-2026-30624 CVSS 8.6 | Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP s… |
| CVE-2026-30617 | CVE-2026-30617 CVSS 8.6 | LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can acc… |
| CVE-2026-30615 | CVE-2026-30615 CVSS 8.0 | A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attack… |
| CVE-2026-30587 | CVE-2026-30587 CVSS 8.7 | Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, v… |
| CVE-2026-30534 | CVE-2026-30534 CVSS 8.3 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter. |
| CVE-2026-30531 | CVE-2026-30531 CVSS 8.8 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The ap… |
| CVE-2026-30529 | CVE-2026-30529 CVSS 8.8 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The applic… |
| CVE-2026-30495 | CVE-2026-30495 CVSS 8.8 | The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without req… |
| CVE-2026-30478 | CVE-2026-30478 CVSS 8.8 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable. |
| CVE-2026-3047 | CVE-2026-3047 CVSS 8.8redhat | A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-init… |
| CVE-2026-30461 | CVE-2026-30461 CVSS 8.3thedaylightstudio | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the … |
| CVE-2026-30460 | CVE-2026-30460 CVSS 8.8thedaylightstudio | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. |
| CVE-2026-3044 | CVE-2026-3044 CVSS 8.8 | A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Se… |