89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,001–2,050 of 8,161 in High · page 41 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-2883 | CVE-2026-2883 CVSS 8.8 | A vulnerability was determined in D-Link DWR-M960 1.01.07. Impacted is the function sub_427D74 of the file /boafrm/formIpQoS. Executing a manipulation of the a… |
| CVE-2026-28821 | CVE-2026-28821 CVSS 8.4 | A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed i… |
| CVE-2026-2882 | CVE-2026-2882 CVSS 8.8 | A vulnerability was found in D-Link DWR-M960 1.01.07. This issue affects the function sub_46385C of the file /boafrm/formDosCfg. Performing a manipulation of t… |
| CVE-2026-28817 | CVE-2026-28817 CVSS 8.1 | A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed pr… |
| CVE-2026-2881 | CVE-2026-2881 CVSS 8.8 | A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_425FF8 of the file /boafrm/formFirewallAdv of the compon… |
| CVE-2026-28805 | CVE-2026-28805 CVSS 8.8 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAM… |
| CVE-2026-28800 | CVE-2026-28800 CVSS 8.0 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-priva… |
| CVE-2026-28797 | CVE-2026-28797 CVSS 8.8infiniflow | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exis… |
| CVE-2026-28793 | CVE-2026-28793 CVSS 8.4 | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal,… |
| CVE-2026-28774 | CVE-2026-28774 CVSS 8.8 | An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex… |
| CVE-2026-28773 | CVE-2026-28773 CVSS 8.8 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Manageme… |
| CVE-2026-28770 | CVE-2026-28770 CVSS 8.8 | Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Sate… |
| CVE-2026-2877 | CVE-2026-2877 CVSS 8.8 | A vulnerability has been found in Tenda A18 15.13.07.13. This affects the function strcpy of the file /goform/WifiExtraSet of the component Httpd Service. The … |
| CVE-2026-28761 | CVE-2026-28761 CVSS 8.1 | Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious… |
| CVE-2026-2876 | CVE-2026-2876 CVSS 8.8 | A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of … |
| CVE-2026-28741 | CVE-2026-28741 CVSS 8.1 | Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which … |
| CVE-2026-2874 | CVE-2026-2874 CVSS 8.8 | A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipula… |
| CVE-2026-2873 | CVE-2026-2873 CVSS 8.8 | A vulnerability was detected in Tenda A21 1.0.0.0. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. Performing a manipulation of… |
| CVE-2026-2872 | CVE-2026-2872 CVSS 8.8 | A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of th… |
| CVE-2026-2871 | CVE-2026-2871 CVSS 8.8 | A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argu… |
| CVE-2026-2870 | CVE-2026-2870 CVSS 8.8 | A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipu… |
| CVE-2026-28693 | CVE-2026-28693 CVSS 8.1imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in… |
| CVE-2026-28683 | CVE-2026-28683 CVSS 8.7 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads… |
| CVE-2026-28681 | CVE-2026-28681 CVSS 8.1 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and… |
| CVE-2026-28677 | CVE-2026-28677 CVSS 8.2 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline a… |
| CVE-2026-28676 | CVE-2026-28676 CVSS 8.8 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers … |
| CVE-2026-2857 | CVE-2026-2857 CVSS 8.8 | A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Po… |
| CVE-2026-2856 | CVE-2026-2856 CVSS 8.8 | A vulnerability was found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_424AFC of the file /boafrm/formFilter of the component… |
| CVE-2026-2855 | CVE-2026-2855 CVSS 8.8 | A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Hand… |
| CVE-2026-2854 | CVE-2026-2854 CVSS 8.8 | A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint.… |
| CVE-2026-28536 | CVE-2026-28536 CVSS 8.1 | Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confid… |
| CVE-2026-2853 | CVE-2026-2853 CVSS 8.8 | A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Config… |
| CVE-2026-28520 | CVE-2026-28520 CVSS 8.4 | arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connect… |
| CVE-2026-28519 | CVE-2026-28519 CVSS 8.8 | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area networ… |
| CVE-2026-28516 | CVE-2026-28516 CVSS 8.8opendcim | openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php h… |
| CVE-2026-28515 | CVE-2026-28515 CVSS 8.8opendcim | openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upg… |
| CVE-2026-28508 | CVE-2026-28508 CVSS 8.6 | Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service… |
| CVE-2026-28502 | CVE-2026-28502 CVSS 8.8 | WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo relate… |
| CVE-2026-28495 | CVE-2026-28495 CVSS 8.8 | GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to ov… |
| CVE-2026-28473 | CVE-2026-28473 CVSS 8.1 | OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval req… |
| CVE-2026-28467 | CVE-2026-28467 CVSS 8.6 | OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to f… |
| CVE-2026-28459 | CVE-2026-28459 CVSS 8.1 | OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitr… |
| CVE-2026-28450 | CVE-2026-28450 CVSS 8.2 | OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and… |
| CVE-2026-28445 | CVE-2026-28445 CVSS 8.7 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg fie… |
| CVE-2026-28442 | CVE-2026-28442 CVSS 8.5 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting inter… |
| CVE-2026-28425 | CVE-2026-28425 CVSS 8.0 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to… |
| CVE-2026-28423 | CVE-2026-28423 CVSS 8.6 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure … |
| CVE-2026-28416 | CVE-2026-28416 CVSS 8.6 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio al… |
| CVE-2026-28410 | CVE-2026-28410 CVSS 8.1 | The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vestin… |
| CVE-2026-28406 | CVE-2026-28406 CVSS 8.2chainguard | kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10… |