89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,201–2,250 of 8,161 in High · page 45 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-27747 | CVE-2026-27747 CVSS 8.8 | The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability in interface_traduction_objets_pipelin… |
| CVE-2026-27745 | CVE-2026-27745 CVSS 8.8 | The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface w… |
| CVE-2026-27732 | CVE-2026-27732 CVSS 8.1 | WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and fetches th… |
| CVE-2026-27728 | CVE-2026-27728 CVSS 8.8 | OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.perf… |
| CVE-2026-27696 | CVE-2026-27696 CVSS 8.6 | changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request F… |
| CVE-2026-2769 | CVE-2026-2769 CVSS 8.8mozilla | Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th… |
| CVE-2026-27668 | CVE-2026-27668 CVSS 8.8 | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to admin… |
| CVE-2026-27654 | CVE-2026-27654 CVSS 8.2f5 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX … |
| CVE-2026-27648 | CVE-2026-27648 CVSS 8.8 | in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps. |
| CVE-2026-27636 | CVE-2026-27636 CVSS 8.8 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/M… |
| CVE-2026-27635 | CVE-2026-27635 CVSS 8.8 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.0, … |
| CVE-2026-27629 | CVE-2026-27629 CVSS 8.8 | InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to… |
| CVE-2026-27608 | CVE-2026-27608 CVSS 8.1parseplatform | Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /a… |
| CVE-2026-27593 | CVE-2026-27593 CVSS 8.8 | Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the pa… |
| CVE-2026-27566 | CVE-2026-27566 CVSS 8.8 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatch wrapper … |
| CVE-2026-27510 | CVE-2026-27510 CVSS 8.8 | Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code exec… |
| CVE-2026-27509 | CVE-2026-27509 CVSS 8.0 | Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt… |
| CVE-2026-27498 | CVE-2026-27498 CVSS 8.8 | n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows co… |
| CVE-2026-27497 | CVE-2026-27497 CVSS 8.8 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify wo… |
| CVE-2026-2749 | CVE-2026-2749 CVSS 8.8 | Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central S… |
| CVE-2026-27487 | CVE-2026-27487 CVSS 8.0 | OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell com… |
| CVE-2026-27483 | CVE-2026-27483 CVSS 8.8 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb'… |
| CVE-2026-27475 | CVE-2026-27475 CVSS 8.1 | SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An at… |
| CVE-2026-27470 | CVE-2026-27470 CVSS 8.8 | ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-o… |
| CVE-2026-27468 | CVE-2026-27468 CVSS 8.2 | Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 t… |
| CVE-2026-27466 | CVE-2026-27466 CVSS 8.2 | BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as… |
| CVE-2026-2745 | CVE-2026-2745 CVSS 8.1 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have all… |
| CVE-2026-27428 | CVE-2026-27428 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle Booking eagle-booking allows SQL Injec… |
| CVE-2026-2740 | CVE-2026-2740 CVSS 8.4 | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticate… |
| CVE-2026-27390 | CVE-2026-27390 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon … |
| CVE-2026-27383 | CVE-2026-27383 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Metro metro allows PHP Loc… |
| CVE-2026-27381 | CVE-2026-27381 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local Fil… |
| CVE-2026-27379 | CVE-2026-27379 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue af… |
| CVE-2026-27373 | CVE-2026-27373 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome tablesome allows Blind SQL Injection.Th… |
| CVE-2026-27369 | CVE-2026-27369 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through <= 1.3.6. |
| CVE-2026-27342 | CVE-2026-27342 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopFit - Fitness and Gym… |
| CVE-2026-27341 | CVE-2026-27341 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordP… |
| CVE-2026-27340 | CVE-2026-27340 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Apollo | Night Club, DJ E… |
| CVE-2026-27339 | CVE-2026-27339 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Buzz Stone | Magazine & V… |
| CVE-2026-27338 | CVE-2026-27338 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7. |
| CVE-2026-27337 | CVE-2026-27337 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chronicle - Lifestyle Mag… |
| CVE-2026-27336 | CVE-2026-27336 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, A… |
| CVE-2026-27335 | CVE-2026-27335 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ekoterra - NonProfit, Gre… |
| CVE-2026-27334 | CVE-2026-27334 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dan_fisher Alchemists alchemists allow… |
| CVE-2026-27326 | CVE-2026-27326 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Co… |
| CVE-2026-27314 | CVE-2026-27314 CVSS 8.8 | Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their o… |
| CVE-2026-27306 | CVE-2026-27306 CVSS 8.4adobe | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the… |
| CVE-2026-27305 | CVE-2026-27305 CVSS 8.6adobe | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability… |
| CVE-2026-27290 | CVE-2026-27290 CVSS 8.6adobe | Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the… |
| CVE-2026-27206 | CVE-2026-27206 CVSS 8.1 | Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects fr… |