89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,001–2,050 of 8,161 in High · page 41 of 164

IDTitleSummary
CVE-2026-2883CVE-2026-2883
CVSS 8.8
A vulnerability was determined in D-Link DWR-M960 1.01.07. Impacted is the function sub_427D74 of the file /boafrm/formIpQoS. Executing a manipulation of the a…
CVE-2026-28821CVE-2026-28821
CVSS 8.4
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed i…
CVE-2026-2882CVE-2026-2882
CVSS 8.8
A vulnerability was found in D-Link DWR-M960 1.01.07. This issue affects the function sub_46385C of the file /boafrm/formDosCfg. Performing a manipulation of t…
CVE-2026-28817CVE-2026-28817
CVSS 8.1
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed pr…
CVE-2026-2881CVE-2026-2881
CVSS 8.8
A vulnerability has been found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_425FF8 of the file /boafrm/formFirewallAdv of the compon…
CVE-2026-28805CVE-2026-28805
CVSS 8.8
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAM…
CVE-2026-28800CVE-2026-28800
CVSS 8.0
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a non-priva…
CVE-2026-28797CVE-2026-28797
CVSS 8.8infiniflow
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exis…
CVE-2026-28793CVE-2026-28793
CVSS 8.4
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal,…
CVE-2026-28774CVE-2026-28774
CVSS 8.8
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex…
CVE-2026-28773CVE-2026-28773
CVSS 8.8
The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver Web Manageme…
CVE-2026-28770CVE-2026-28770
CVSS 8.8
Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Sate…
CVE-2026-2877CVE-2026-2877
CVSS 8.8
A vulnerability has been found in Tenda A18 15.13.07.13. This affects the function strcpy of the file /goform/WifiExtraSet of the component Httpd Service. The …
CVE-2026-28761CVE-2026-28761
CVSS 8.1
Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious…
CVE-2026-2876CVE-2026-2876
CVSS 8.8
A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of …
CVE-2026-28741CVE-2026-28741
CVSS 8.1
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which …
CVE-2026-2874CVE-2026-2874
CVSS 8.8
A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipula…
CVE-2026-2873CVE-2026-2873
CVSS 8.8
A vulnerability was detected in Tenda A21 1.0.0.0. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. Performing a manipulation of…
CVE-2026-2872CVE-2026-2872
CVSS 8.8
A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of th…
CVE-2026-2871CVE-2026-2871
CVSS 8.8
A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argu…
CVE-2026-2870CVE-2026-2870
CVSS 8.8
A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipu…
CVE-2026-28693CVE-2026-28693
CVSS 8.1imagemagick
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in…
CVE-2026-28683CVE-2026-28683
CVSS 8.7
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads…
CVE-2026-28681CVE-2026-28681
CVSS 8.1
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and…
CVE-2026-28677CVE-2026-28677
CVSS 8.2
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline a…
CVE-2026-28676CVE-2026-28676
CVSS 8.8
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers …
CVE-2026-2857CVE-2026-2857
CVSS 8.8
A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Po…
CVE-2026-2856CVE-2026-2856
CVSS 8.8
A vulnerability was found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_424AFC of the file /boafrm/formFilter of the component…
CVE-2026-2855CVE-2026-2855
CVSS 8.8
A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Hand…
CVE-2026-2854CVE-2026-2854
CVSS 8.8
A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint.…
CVE-2026-28536CVE-2026-28536
CVSS 8.1
Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confid…
CVE-2026-2853CVE-2026-2853
CVSS 8.8
A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Config…
CVE-2026-28520CVE-2026-28520
CVSS 8.4
arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connect…
CVE-2026-28519CVE-2026-28519
CVSS 8.8
arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area networ…
CVE-2026-28516CVE-2026-28516
CVSS 8.8opendcim
openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php h…
CVE-2026-28515CVE-2026-28515
CVSS 8.8opendcim
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upg…
CVE-2026-28508CVE-2026-28508
CVSS 8.6
Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service…
CVE-2026-28502CVE-2026-28502
CVSS 8.8
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo relate…
CVE-2026-28495CVE-2026-28495
CVSS 8.8
GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to ov…
CVE-2026-28473CVE-2026-28473
CVSS 8.1
OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scope can approve or deny exec approval req…
CVE-2026-28467CVE-2026-28467
CVSS 8.6
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to f…
CVE-2026-28459CVE-2026-28459
CVSS 8.1
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitr…
CVE-2026-28450CVE-2026-28450
CVSS 8.2
OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and…
CVE-2026-28445CVE-2026-28445
CVSS 8.7
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg fie…
CVE-2026-28442CVE-2026-28442
CVSS 8.5
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting inter…
CVE-2026-28425CVE-2026-28425
CVSS 8.0
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to…
CVE-2026-28423CVE-2026-28423
CVSS 8.6
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure …
CVE-2026-28416CVE-2026-28416
CVSS 8.6
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio al…
CVE-2026-28410CVE-2026-28410
CVSS 8.1
The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vestin…
CVE-2026-28406CVE-2026-28406
CVSS 8.2chainguard
kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.