89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,251–2,300 of 8,161 in High · page 46 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-27203 | CVE-2026-27203 CVSS 8.3 | eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to En… |
| CVE-2026-27198 | CVE-2026-27198 CVSS 8.8 | Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorizat… |
| CVE-2026-27192 | CVE-2026-27192 CVSS 8.1 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses … |
| CVE-2026-27182 | CVE-2026-27182 CVSS 8.4 | Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially … |
| CVE-2026-27173 | CVE-2026-27173 CVSS 8.7apache | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users wit… |
| CVE-2026-27172 | CVE-2026-27172 CVSS 8.8apache | The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) … |
| CVE-2026-27169 | CVE-2026-27169 CVSS 8.9 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/mo… |
| CVE-2026-27140 | CVE-2026-27140 CVSS 8.8golang | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. |
| CVE-2026-27134 | CVE-2026-27134 CVSS 8.1linuxfoundation | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when… |
| CVE-2026-27099 | CVE-2026-27099 CVSS 8.0 | Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporari… |
| CVE-2026-27098 | CVE-2026-27098 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue aff… |
| CVE-2026-27097 | CVE-2026-27097 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental… |
| CVE-2026-27096 | CVE-2026-27096 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects Colo… |
| CVE-2026-27093 | CVE-2026-27093 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Tripgo tripgo allows PHP Loca… |
| CVE-2026-27081 | CVE-2026-27081 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Rosebud rosebud allows P… |
| CVE-2026-27080 | CVE-2026-27080 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Deston deston allows PHP… |
| CVE-2026-27079 | CVE-2026-27079 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows P… |
| CVE-2026-27078 | CVE-2026-27078 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Emaurri emaurri allows P… |
| CVE-2026-27077 | CVE-2026-27077 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes MultiOffice multioffice … |
| CVE-2026-27076 | CVE-2026-27076 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes LuxeDrive luxedrive allo… |
| CVE-2026-27075 | CVE-2026-27075 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Belfort belfort allows P… |
| CVE-2026-2705 | CVE-2026-2705 CVSS 8.1 | A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of… |
| CVE-2026-27048 | CVE-2026-27048 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle Core theaisle-… |
| CVE-2026-27047 | CVE-2026-27047 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly Core curly-core al… |
| CVE-2026-27045 | CVE-2026-27045 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affec… |
| CVE-2026-27040 | CVE-2026-27040 CVSS 8.8 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects … |
| CVE-2026-2704 | CVE-2026-2704 CVSS 8.1 | A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file… |
| CVE-2026-27039 | CVE-2026-27039 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This iss… |
| CVE-2026-2701 | CVE-2026-2701 CVSS 8.8 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. |
| CVE-2026-26990 | CVE-2026-26990 CVSS 8.8 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in… |
| CVE-2026-26984 | CVE-2026-26984 CVSS 8.8 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. … |
| CVE-2026-26982 | CVE-2026-26982 CVSS 8.8 | Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute… |
| CVE-2026-26975 | CVE-2026-26975 CVSS 8.8 | Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthentica… |
| CVE-2026-2697 | CVE-2026-2697 CVSS 8.8 | An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. |
| CVE-2026-26965 | CVE-2026-26965 CVSS 8.8freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes… |
| CVE-2026-26955 | CVE-2026-26955 CVSS 8.8freerdp | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP … |
| CVE-2026-26944 | CVE-2026-26944 CVSS 8.8 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1… |
| CVE-2026-26862 | CVE-2026-26862 CVSS 8.3 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The ori… |
| CVE-2026-26861 | CVE-2026-26861 CVSS 8.3 | CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent fu… |
| CVE-2026-26794 | CVE-2026-26794 CVSS 8.8 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execut… |
| CVE-2026-26746 | CVE-2026-26746 CVSS 8.8 | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the we… |
| CVE-2026-26742 | CVE-2026-26742 CVSS 8.1 | PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-a… |
| CVE-2026-26741 | CVE-2026-26741 CVSS 8.1 | PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone… |
| CVE-2026-26740 | CVE-2026-26740 CVSS 8.2giflib_project | Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphi… |
| CVE-2026-26736 | CVE-2026-26736 CVSS 8.8 | TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function. |
| CVE-2026-26732 | CVE-2026-26732 CVSS 8.8 | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter fun… |
| CVE-2026-26731 | CVE-2026-26731 CVSS 8.8totolink | TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function. |
| CVE-2026-26723 | CVE-2026-26723 CVSS 8.2 | Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via… |
| CVE-2026-2652 | CVE-2026-2652 CVSS 8.6 | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authenticat… |
| CVE-2026-2650 | CVE-2026-2650 CVSS 8.8 | Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… |