89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,151–2,200 of 8,161 in High · page 44 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-28017 | CVE-2026-28017 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Green Thumb greenthumb allows… |
| CVE-2026-28016 | CVE-2026-28016 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Luxury Wine luxury-wine allow… |
| CVE-2026-28015 | CVE-2026-28015 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ShiftCV shift-cv allows PHP L… |
| CVE-2026-28014 | CVE-2026-28014 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Translogic translogic allows … |
| CVE-2026-28013 | CVE-2026-28013 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Kratz kratz allows PHP Local … |
| CVE-2026-28012 | CVE-2026-28012 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gridiron gridiron allows PHP … |
| CVE-2026-28011 | CVE-2026-28011 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yottis yottis allows PHP Loca… |
| CVE-2026-28010 | CVE-2026-28010 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Scientia scientia allows PHP … |
| CVE-2026-28009 | CVE-2026-28009 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX DroneX dronex allows PHP Loca… |
| CVE-2026-28007 | CVE-2026-28007 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coinpress coinpress allows PH… |
| CVE-2026-28006 | CVE-2026-28006 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yungen yungen allows PHP Loca… |
| CVE-2026-27998 | CVE-2026-27998 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Vixus vixus allows PHP Local … |
| CVE-2026-27997 | CVE-2026-27997 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Maxify maxify allows PHP Loca… |
| CVE-2026-27996 | CVE-2026-27996 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Lingvico lingvico allows PHP … |
| CVE-2026-27995 | CVE-2026-27995 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Justitia justitia allows PHP … |
| CVE-2026-27994 | CVE-2026-27994 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tediss tediss allows PHP Loca… |
| CVE-2026-27993 | CVE-2026-27993 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aldo aldo allows PHP Local Fi… |
| CVE-2026-27992 | CVE-2026-27992 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Meals & Wheels meals-wheels a… |
| CVE-2026-27991 | CVE-2026-27991 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Avventure avventure allows PH… |
| CVE-2026-27990 | CVE-2026-27990 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ConFix confix allows PHP Loca… |
| CVE-2026-27989 | CVE-2026-27989 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Quanzo quanzo allows PHP Loca… |
| CVE-2026-27988 | CVE-2026-27988 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Equadio equadio allows PHP Lo… |
| CVE-2026-27987 | CVE-2026-27987 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX The Qlean the-qlean allows PH… |
| CVE-2026-27986 | CVE-2026-27986 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX OsTende ostende allows PHP Lo… |
| CVE-2026-27985 | CVE-2026-27985 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Humanum humanum allows PHP Lo… |
| CVE-2026-2798 | CVE-2026-2798 CVSS 8.8mozilla | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
| CVE-2026-27976 | CVE-2026-27976 CVSS 8.8 | Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates sy… |
| CVE-2026-27969 | CVE-2026-27969 CVSS 8.8 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storag… |
| CVE-2026-27961 | CVE-2026-27961 CVSS 8.8 | Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evalu… |
| CVE-2026-27947 | CVE-2026-27947 CVSS 8.8 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote … |
| CVE-2026-27939 | CVE-2026-27939 CVSS 8.8 | Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users… |
| CVE-2026-27928 | CVE-2026-27928 CVSS 8.7 | Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-27912 | CVE-2026-27912 CVSS 8.0 | Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. |
| CVE-2026-27899 | CVE-2026-27899 CVSS 8.8 | WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user c… |
| CVE-2026-27895 | CVE-2026-27895 CVSS 8.8 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF… |
| CVE-2026-27894 | CVE-2026-27894 CVSS 8.8 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local… |
| CVE-2026-27893 | CVE-2026-27893 CVSS 8.8vllm | vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation file… |
| CVE-2026-27890 | CVE-2026-27890 CVSS 8.2 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments dur… |
| CVE-2026-27841 | CVE-2026-27841 CVSS 8.1 | A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF)… |
| CVE-2026-27832 | CVE-2026-27832 CVSS 8.8 | Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injection (SQLi) v… |
| CVE-2026-27826 | CVE-2026-27826 CVSS 8.2 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, an unauthenticated attacker who c… |
| CVE-2026-27825 | CVE-2026-27825 CVSS 8.0 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachme… |
| CVE-2026-27811 | CVE-2026-27811 CVSS 8.8 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability exists in th… |
| CVE-2026-27808 | CVE-2026-27808 CVSS 8.6 | Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is vulnerable to Server-… |
| CVE-2026-27803 | CVE-2026-27803 CVSS 8.3 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=fa… |
| CVE-2026-27802 | CVE-2026-27802 CVSS 8.3 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalat… |
| CVE-2026-27785 | CVE-2026-27785 CVSS 8.8 | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. |
| CVE-2026-27776 | CVE-2026-27776 CVSS 8.8 | IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on t… |
| CVE-2026-27764 | CVE-2026-27764 CVSS 8.6 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifi… |
| CVE-2026-27760 | CVE-2026-27760 CVSS 8.1 | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute ar… |