89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,951–2,000 of 8,161 in High · page 40 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-29205 | CVE-2026-29205 CVSS 8.6cpanel | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. |
| CVE-2026-29203 | CVE-2026-29203 CVSS 8.8 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. … |
| CVE-2026-29202 | CVE-2026-29202 CVSS 8.8 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated… |
| CVE-2026-29201 | CVE-2026-29201 CVSS 8.6 | Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is p… |
| CVE-2026-29199 | CVE-2026-29199 CVSS 8.1 | phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostn… |
| CVE-2026-29194 | CVE-2026-29194 CVSS 8.1 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a route permit… |
| CVE-2026-29193 | CVE-2026-29193 CVSS 8.2 | ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login be… |
| CVE-2026-29189 | CVE-2026-29189 CVSS 8.1 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST… |
| CVE-2026-29188 | CVE-2026-29188 CVSS 8.1 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to ver… |
| CVE-2026-29187 | CVE-2026-29187 CVSS 8.8 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulner… |
| CVE-2026-29180 | CVE-2026-29180 CVSS 8.8 | Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer t… |
| CVE-2026-29174 | CVE-2026-29174 CVSS 8.8 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoin… |
| CVE-2026-29172 | CVE-2026-29172 CVSS 8.8 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpo… |
| CVE-2026-2911 | CVE-2026-2911 CVSS 8.8 | A vulnerability has been found in Tenda FH451 up to 1.0.0.9. This issue affects some unknown processing of the file /goform/GstDhcpSetSer. The manipulation lea… |
| CVE-2026-29102 | CVE-2026-29102 CVSS 8.8 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated … |
| CVE-2026-2910 | CVE-2026-2910 CVSS 8.8 | A flaw has been found in Tenda HG9 300001138. This vulnerability affects unknown code of the file /boaform/formPing6. Executing a manipulation of the argument … |
| CVE-2026-29099 | CVE-2026-29099 CVSS 8.8 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `retrieve()` … |
| CVE-2026-29091 | CVE-2026-29091 CVSS 8.1locutus | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was di… |
| CVE-2026-29090 | CVE-2026-29090 CVSS 8.8 | ### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgre… |
| CVE-2026-2909 | CVE-2026-2909 CVSS 8.8 | A vulnerability was detected in Tenda HG9 300001138. This affects an unknown part of the file /boaform/formPing of the component Diagnostic Ping Endpoint. Perf… |
| CVE-2026-29089 | CVE-2026-29089 CVSS 8.8 | TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses… |
| CVE-2026-29081 | CVE-2026-29081 CVSS 8.8 | Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafte… |
| CVE-2026-29080 | CVE-2026-29080 CVSS 8.8 | A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database t… |
| CVE-2026-2908 | CVE-2026-2908 CVSS 8.8 | A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of th… |
| CVE-2026-29073 | CVE-2026-29073 CVSS 8.8 | SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not a… |
| CVE-2026-29070 | CVE-2026-29070 CVSS 8.1 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is missing w… |
| CVE-2026-2907 | CVE-2026-2907 CVSS 8.8 | A weakness has been identified in Tenda HG9 300001138. Affected by this vulnerability is an unknown functionality of the file /boaform/formgponConf of the comp… |
| CVE-2026-29064 | CVE-2026-29064 CVSS 8.2 | Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction al… |
| CVE-2026-2906 | CVE-2026-2906 CVSS 8.8 | A security flaw has been discovered in Tenda HG9 300001138. Affected is an unknown function of the file /boaform/formSamba of the component Samba Configuration… |
| CVE-2026-29056 | CVE-2026-29056 CVSS 8.8 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::re… |
| CVE-2026-2905 | CVE-2026-2905 CVSS 8.8 | A vulnerability was identified in Tenda HG9 300001138. This impacts an unknown function of the file /boaform/formWlanSetup of the component Wireless Configurat… |
| CVE-2026-29047 | CVE-2026-29047 CVSS 8.8 | GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the lo… |
| CVE-2026-29046 | CVE-2026-29046 CVSS 8.2 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI en… |
| CVE-2026-29041 | CVE-2026-29041 CVSS 8.8 | Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by im… |
| CVE-2026-2904 | CVE-2026-2904 CVSS 8.8 | A vulnerability was determined in UTT HiPER 810G 1.7.7-171114. This affects the function strcpy of the file /goform/ConfigExceptAli. Executing a manipulation c… |
| CVE-2026-29004 | CVE-2026-29004 CVSS 8.1 | BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dh… |
| CVE-2026-28995 | CVE-2026-28995 CVSS 8.8apple | A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, ma… |
| CVE-2026-28978 | CVE-2026-28978 CVSS 8.8 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious… |
| CVE-2026-28955 | CVE-2026-28955 CVSS 8.8apple | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe … |
| CVE-2026-2895 | CVE-2026-2895 CVSS 8.1 | A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. … |
| CVE-2026-28947 | CVE-2026-28947 CVSS 8.8apple | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 2… |
| CVE-2026-28940 | CVE-2026-28940 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, mac… |
| CVE-2026-28923 | CVE-2026-28923 CVSS 8.8 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app… |
| CVE-2026-28907 | CVE-2026-28907 CVSS 8.1 | The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe… |
| CVE-2026-28891 | CVE-2026-28891 CVSS 8.1 | A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be ab… |
| CVE-2026-2886 | CVE-2026-2886 CVSS 8.8 | A weakness has been identified in Tenda A21 1.0.0.0. This affects the function set_device_name of the file /goform/SetOnlineDevName. This manipulation of the a… |
| CVE-2026-2885 | CVE-2026-2885 CVSS 8.8 | A security flaw has been discovered in D-Link DWR-M960 1.01.07. The impacted element is the function sub_469104 of the file /boafrm/formIpv6Setup. The manipula… |
| CVE-2026-28847 | CVE-2026-28847 CVSS 8.8apple | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe … |
| CVE-2026-2884 | CVE-2026-2884 CVSS 8.8 | A vulnerability was identified in D-Link DWR-M960 1.01.07. The affected element is the function sub_41914C of the file /boafrm/formWanConfigSetup of the compon… |
| CVE-2026-28832 | CVE-2026-28832 CVSS 8.4 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app m… |