89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,851–1,900 of 8,161 in High · page 38 of 164

IDTitleSummary
CVE-2026-30914CVE-2026-30914
CVSS 8.1
SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handler…
CVE-2026-30911CVE-2026-30911
CVSS 8.1
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authe…
CVE-2026-30898CVE-2026-30898
CVSS 8.8
An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to es…
CVE-2026-30881CVE-2026-30881
CVSS 8.8
Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters d…
CVE-2026-30875CVE-2026-30875
CVSS 8.8
Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated us…
CVE-2026-30868CVE-2026-30868
CVSS 8.1
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are acces…
CVE-2026-30861CVE-2026-30861
CVSS 8.8
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenti…
CVE-2026-30855CVE-2026-30855
CVSS 8.8
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant …
CVE-2026-30853CVE-2026-30853
CVSS 8.2
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the Rock…
CVE-2026-30851CVE-2026-30851
CVSS 8.8
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-…
CVE-2026-3085CVE-2026-3085
CVSS 8.8gstreamer
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …
CVE-2026-30845CVE-2026-30845
CVSS 8.2
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data…
CVE-2026-30844CVE-2026-30844
CVSS 8.1
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. …
CVE-2026-30840CVE-2026-30840
CVSS 8.8
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notifica…
CVE-2026-3083CVE-2026-3083
CVSS 8.8gstreamer
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte…
CVE-2026-30823CVE-2026-30823
CVSS 8.8
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to ac…
CVE-2026-30820CVE-2026-30820
CVSS 8.8
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the …
CVE-2026-30818CVE-2026-30818
CVSS 8.0tp-link
An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code whe…
CVE-2026-30815CVE-2026-30815
CVSS 8.0tp-link
An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands wh…
CVE-2026-30814CVE-2026-30814
CVSS 8.0tp-link
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and…
CVE-2026-30813CVE-2026-30813
CVSS 8.8
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search. This issue affects Pandora FMS: from 7…
CVE-2026-30810CVE-2026-30810
CVSS 8.8
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30809CVE-2026-30809
CVSS 8.8
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandor…
CVE-2026-30808CVE-2026-30808
CVSS 8.1
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30807CVE-2026-30807
CVSS 8.8
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 thro…
CVE-2026-30806CVE-2026-30806
CVSS 8.8
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS:…
CVE-2026-30797CVE-2026-30797
CVSS 8.1
Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, conf…
CVE-2026-30794CVE-2026-30794
CVSS 8.1
Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS t…
CVE-2026-30792CVE-2026-30792
CVSS 8.1
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config op…
CVE-2026-30711CVE-2026-30711
CVSS 8.8
Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-a…
CVE-2026-3071CVE-2026-3071
CVSS 8.4
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a m…
CVE-2026-30707CVE-2026-30707
CVSS 8.1
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control via the ReviewAnswerDetails ASP.NET Page…
CVE-2026-3067CVE-2026-3067
CVSS 8.8
A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/…
CVE-2026-3066CVE-2026-3066
CVSS 8.8
A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/jav…
CVE-2026-3065CVE-2026-3065
CVSS 8.8
A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the…
CVE-2026-3064CVE-2026-3064
CVSS 8.8
A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreateService.ja…
CVE-2026-30635CVE-2026-30635
CVSS 8.1
Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTra…
CVE-2026-30624CVE-2026-30624
CVSS 8.6
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP s…
CVE-2026-30617CVE-2026-30617
CVSS 8.6
LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can acc…
CVE-2026-30615CVE-2026-30615
CVSS 8.0
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attack…
CVE-2026-30587CVE-2026-30587
CVSS 8.7
Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, v…
CVE-2026-30534CVE-2026-30534
CVSS 8.3
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.
CVE-2026-30531CVE-2026-30531
CVSS 8.8
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The ap…
CVE-2026-30529CVE-2026-30529
CVSS 8.8
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The applic…
CVE-2026-30495CVE-2026-30495
CVSS 8.8
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP port 5555 over the network without req…
CVE-2026-30478CVE-2026-30478
CVSS 8.8
A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable.
CVE-2026-3047CVE-2026-3047
CVSS 8.8redhat
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-init…
CVE-2026-30461CVE-2026-30461
CVSS 8.3thedaylightstudio
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the …
CVE-2026-30460CVE-2026-30460
CVSS 8.8thedaylightstudio
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
CVE-2026-3044CVE-2026-3044
CVSS 8.8
A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Se…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.