89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,901–1,950 of 8,161 in High · page 39 of 164

IDTitleSummary
CVE-2026-3037CVE-2026-3037
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the…
CVE-2026-30363CVE-2026-30363
CVSS 8.4
flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function.
CVE-2026-30292CVE-2026-30292
CVSS 8.4
An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file im…
CVE-2026-30291CVE-2026-30291
CVSS 8.4
An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the fil…
CVE-2026-30290CVE-2026-30290
CVSS 8.4intouchapp
An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import…
CVE-2026-30289CVE-2026-30289
CVSS 8.4
An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file …
CVE-2026-30287CVE-2026-30287
CVSS 8.4
An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to overwrite critical internal files via t…
CVE-2026-30284CVE-2026-30284
CVSS 8.6uxgroupllc
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process…
CVE-2026-30279CVE-2026-30279
CVSS 8.4squareapps
An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the fi…
CVE-2026-30277CVE-2026-30277
CVSS 8.4triumph-adler
An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the …
CVE-2026-30242CVE-2026-30242
CVSS 8.5
Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_lo…
CVE-2026-30241CVE-2026-30241
CVSS 8.2
Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries…
CVE-2026-30240CVE-2026-30240
CVSS 8.1
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Pro…
CVE-2026-3023CVE-2026-3023
CVSS 8.8
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. This vulnera…
CVE-2026-30223CVE-2026-30223
CVSS 8.8
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJw…
CVE-2026-3016CVE-2026-3016
CVSS 8.8
A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. The affected element is the function strcpy of the file /goform/formP2PLimitConfig. The ma…
CVE-2026-3015CVE-2026-3015
CVSS 8.8
A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manip…
CVE-2026-3009CVE-2026-3009
CVSS 8.1redhat
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it …
CVE-2026-29972CVE-2026-29972
CVSS 8.2
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or…
CVE-2026-29955CVE-2026-29955
CVSS 8.8
The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` w…
CVE-2026-2992CVE-2026-2992
CVSS 8.2
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-jso…
CVE-2026-29872CVE-2026-29872
CVSS 8.2
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). Th…
CVE-2026-29839CVE-2026-29839
CVSS 8.8
DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.
CVE-2026-2981CVE-2026-2981
CVSS 8.8
A vulnerability was found in UTT HiPER 810G up to 1.7.7-1711. The affected element is the function strcpy of the file /goform/formTaskEdit_ap. The manipulation…
CVE-2026-2979CVE-2026-2979
CVSS 8.8
A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/…
CVE-2026-29789CVE-2026-29789
CVSS 8.8
Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authori…
CVE-2026-29784CVE-2026-29784
CVSS 8.8
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs i…
CVE-2026-2978CVE-2026-2978
CVSS 8.8
A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module…
CVE-2026-29775CVE-2026-29775
CVSS 8.2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/write occurs in FreeRDP's bitmap cache …
CVE-2026-29774CVE-2026-29774
CVSS 8.2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occurs in the FreeRDP client's AVC420/AVC4…
CVE-2026-2977CVE-2026-2977
CVSS 8.8
A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_comm…
CVE-2026-29648CVE-2026-29648
CVSS 8.8
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privil…
CVE-2026-2962CVE-2026-2962
CVSS 8.8
A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /boafrm/formDateReboot of the component Sc…
CVE-2026-29610CVE-2026-29610
CVSS 8.8
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH enviro…
CVE-2026-2961CVE-2026-2961
CVSS 8.8
A vulnerability has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4196C4 of the file /boafrm/formVpnConfigSetup of the component VPN Con…
CVE-2026-2960CVE-2026-2960
CVSS 8.8
A flaw has been found in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_468D64 of the file /boafrm/formDhcpv6s. Executing a manipulation o…
CVE-2026-2959CVE-2026-2959
CVSS 8.8
A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_44E0F8 of the file /boafrm/formNewSchedule. Perform…
CVE-2026-2958CVE-2026-2958
CVSS 8.8
A security vulnerability has been detected in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of th…
CVE-2026-2957CVE-2026-2957
CVSS 8.1
A weakness has been identified in qinming99 dst-admin up to 1.5.0. This impacts the function deleteBackup of the file src/main/java/com/tugos/dst/admin/control…
CVE-2026-2956CVE-2026-2956
CVSS 8.8
A security flaw has been discovered in qinming99 dst-admin up to 1.5.0. This affects the function revertBackup of the file /home/restore. The manipulation of t…
CVE-2026-29514CVE-2026-29514
CVSS 8.8
NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authen…
CVE-2026-2941CVE-2026-2941
CVSS 8.8
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_a…
CVE-2026-2931CVE-2026-2931
CVSS 8.8
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin p…
CVE-2026-2930CVE-2026-2930
CVSS 8.8
A vulnerability was identified in Tenda A18 15.13.07.13. The affected element is the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the compone…
CVE-2026-2929CVE-2026-2929
CVSS 8.8
A vulnerability was determined in D-Link DWR-M960 1.01.07. Impacted is the function sub_453140 of the file /boafrm/formWlAc of the component Wireless Access Co…
CVE-2026-2928CVE-2026-2928
CVSS 8.8
A vulnerability was found in D-Link DWR-M960 1.01.07. This issue affects the function sub_452CCC of the file /boafrm/formWlEncrypt of the component WLAN Encryp…
CVE-2026-2927CVE-2026-2927
CVSS 8.8
A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_462590 of the file /boafrm/formOpMode of the component O…
CVE-2026-2926CVE-2026-2926
CVSS 8.8
A flaw has been found in D-Link DWR-M960 1.01.07. This affects the function sub_4237AC of the file /boafrm/formLteSetup of the component LTE Configuration Endp…
CVE-2026-2925CVE-2026-2925
CVSS 8.8
A vulnerability was detected in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_42B5A0 of the file /boafrm/formBridgeVlan of the component …
CVE-2026-29206CVE-2026-29206
CVSS 8.1
Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.