89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,051–2,100 of 8,161 in High · page 42 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-28399 | CVE-2026-28399 CVSS 8.8 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Creator role can inject arbitrary SQL via the D… |
| CVE-2026-28387 | CVE-2026-28387 CVSS 8.1openssl | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may r… |
| CVE-2026-28363 | CVE-2026-28363 CVSS 8.8 | In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlis… |
| CVE-2026-2836 | CVE-2026-2836 CVSS 8.1 | A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP … |
| CVE-2026-28298 | CVE-2026-28298 CVSS 8.1 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended scri… |
| CVE-2026-28297 | CVE-2026-28297 CVSS 8.7 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended scri… |
| CVE-2026-28291 | CVE-2026-28291 CVSS 8.1simple-git_project | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option ma… |
| CVE-2026-28289 | CVE-2026-28289 CVSS 8.1 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and ear… |
| CVE-2026-28287 | CVE-2026-28287 CVSS 8.8 | FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilit… |
| CVE-2026-28284 | CVE-2026-28284 CVSS 8.8 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilitie… |
| CVE-2026-28280 | CVE-2026-28280 CVSS 8.7 | osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exists in the `osctrl-admin` on-demand quer… |
| CVE-2026-28279 | CVE-2026-28279 CVSS 8.4 | osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration.… |
| CVE-2026-28275 | CVE-2026-28275 CVSS 8.1 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens afte… |
| CVE-2026-28274 | CVE-2026-28274 CVSS 8.7 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the… |
| CVE-2026-28269 | CVE-2026-28269 CVSS 8.8 | Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to re… |
| CVE-2026-2824 | CVE-2026-2824 CVSS 8.8 | A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the com… |
| CVE-2026-2823 | CVE-2026-2823 CVSS 8.8 | A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET§ion=ntp_… |
| CVE-2026-28228 | CVE-2026-28228 CVSS 8.8 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to versions 19.1.31, 20.1.18, and 20.2.5, … |
| CVE-2026-28224 | CVE-2026-28224 CVSS 8.2 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callba… |
| CVE-2026-28221 | CVE-2026-28221 CVSS 8.2 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer… |
| CVE-2026-2822 | CVE-2026-2822 CVSS 8.8 | A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag… |
| CVE-2026-28216 | CVE-2026-28216 CVSS 8.3 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal enviro… |
| CVE-2026-28210 | CVE-2026-28210 CVSS 8.8 | FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue … |
| CVE-2026-2818 | CVE-2026-2818 CVSS 8.2 | A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction di… |
| CVE-2026-28135 | CVE-2026-28135 CVSS 8.2 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality… |
| CVE-2026-28134 | CVE-2026-28134 CVSS 8.5 | Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetE… |
| CVE-2026-28133 | CVE-2026-28133 CVSS 8.5 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Fil… |
| CVE-2026-28129 | CVE-2026-28129 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-bird… |
| CVE-2026-28128 | CVE-2026-28128 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local … |
| CVE-2026-28125 | CVE-2026-28125 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Midi midi allows PHP Loca… |
| CVE-2026-28124 | CVE-2026-28124 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Notarius notarius allows … |
| CVE-2026-28123 | CVE-2026-28123 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allows PHP Loca… |
| CVE-2026-28121 | CVE-2026-28121 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Anderson andersonclinic a… |
| CVE-2026-28120 | CVE-2026-28120 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dr.Patterson dr-patterson all… |
| CVE-2026-28119 | CVE-2026-28119 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Nirvana nir-vana allows PH… |
| CVE-2026-28118 | CVE-2026-28118 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Welldone welldone allows P… |
| CVE-2026-28117 | CVE-2026-28117 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows … |
| CVE-2026-28107 | CVE-2026-28107 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Muzicon muzicon allows PHP Lo… |
| CVE-2026-28098 | CVE-2026-28098 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Save Life save-life allows PH… |
| CVE-2026-28097 | CVE-2026-28097 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Artrium artrium allows PHP Lo… |
| CVE-2026-28096 | CVE-2026-28096 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX WealthCo wealthco allows PHP … |
| CVE-2026-28095 | CVE-2026-28095 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Marcell marcell allows PHP Lo… |
| CVE-2026-28094 | CVE-2026-28094 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX RexCoin rexcoin allows PHP Lo… |
| CVE-2026-28093 | CVE-2026-28093 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Ozisti ozisti allows PHP Loca… |
| CVE-2026-28092 | CVE-2026-28092 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Sounder sounder allows PHP Lo… |
| CVE-2026-28091 | CVE-2026-28091 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coleo coleo allows PHP Local … |
| CVE-2026-28090 | CVE-2026-28090 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gamezone gamezone allows PHP … |
| CVE-2026-28089 | CVE-2026-28089 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Daiquiri daiquiri allows PHP … |
| CVE-2026-28088 | CVE-2026-28088 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aqualots aqualots allows PHP … |
| CVE-2026-28087 | CVE-2026-28087 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Filmax filmax allows PHP Loca… |