89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,251–2,300 of 8,161 in High · page 46 of 164

IDTitleSummary
CVE-2026-27203CVE-2026-27203
CVSS 8.3
eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to En…
CVE-2026-27198CVE-2026-27198
CVSS 8.8
Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorizat…
CVE-2026-27192CVE-2026-27192
CVSS 8.1
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses …
CVE-2026-27182CVE-2026-27182
CVSS 8.4
Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially …
CVE-2026-27173CVE-2026-27173
CVSS 8.7apache
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users wit…
CVE-2026-27172CVE-2026-27172
CVSS 8.8apache
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) …
CVE-2026-27169CVE-2026-27169
CVSS 8.9
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/mo…
CVE-2026-27140CVE-2026-27140
CVSS 8.8golang
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVE-2026-27134CVE-2026-27134
CVSS 8.1linuxfoundation
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when…
CVE-2026-27099CVE-2026-27099
CVSS 8.0
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporari…
CVE-2026-27098CVE-2026-27098
CVSS 8.1
Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue aff…
CVE-2026-27097CVE-2026-27097
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental…
CVE-2026-27096CVE-2026-27096
CVSS 8.1
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows Object Injection.This issue affects Colo…
CVE-2026-27093CVE-2026-27093
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Tripgo tripgo allows PHP Loca…
CVE-2026-27081CVE-2026-27081
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Rosebud rosebud allows P…
CVE-2026-27080CVE-2026-27080
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Deston deston allows PHP…
CVE-2026-27079CVE-2026-27079
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows P…
CVE-2026-27078CVE-2026-27078
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Emaurri emaurri allows P…
CVE-2026-27077CVE-2026-27077
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes MultiOffice multioffice …
CVE-2026-27076CVE-2026-27076
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes LuxeDrive luxedrive allo…
CVE-2026-27075CVE-2026-27075
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Belfort belfort allows P…
CVE-2026-2705CVE-2026-2705
CVSS 8.1
A vulnerability was detected in Open Babel up to 3.1.1. The impacted element is the function OBAtom::SetFormalCharge in the library include/openbabel/atom.h of…
CVE-2026-27048CVE-2026-27048
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle Core theaisle-…
CVE-2026-27047CVE-2026-27047
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly Core curly-core al…
CVE-2026-27045CVE-2026-27045
CVSS 8.8
Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection.This issue affec…
CVE-2026-27040CVE-2026-27040
CVSS 8.8
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal.This issue affects …
CVE-2026-2704CVE-2026-2704
CVSS 8.1
A security vulnerability has been detected in Open Babel up to 3.1.1. The affected element is the function OpenBabel::transform3d::DescribeAsString of the file…
CVE-2026-27039CVE-2026-27039
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection.This iss…
CVE-2026-2701CVE-2026-2701
CVSS 8.8
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-26990CVE-2026-26990
CVSS 8.8
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in…
CVE-2026-26984CVE-2026-26984
CVSS 8.8
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. …
CVE-2026-26982CVE-2026-26982
CVSS 8.8
Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute…
CVE-2026-26975CVE-2026-26975
CVSS 8.8
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthentica…
CVE-2026-2697CVE-2026-2697
CVSS 8.8
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
CVE-2026-26965CVE-2026-26965
CVSS 8.8freerdp
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes…
CVE-2026-26955CVE-2026-26955
CVSS 8.8freerdp
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP …
CVE-2026-26944CVE-2026-26944
CVSS 8.8
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1…
CVE-2026-26862CVE-2026-26862
CVSS 8.3
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The ori…
CVE-2026-26861CVE-2026-26861
CVSS 8.3
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent fu…
CVE-2026-26794CVE-2026-26794
CVSS 8.8
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execut…
CVE-2026-26746CVE-2026-26746
CVSS 8.8
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the we…
CVE-2026-26742CVE-2026-26742
CVSS 8.1
PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. The system incorrectly applies the in-a…
CVE-2026-26741CVE-2026-26741
CVSS 8.1
PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from Auto mode to Manual mode while the drone…
CVE-2026-26740CVE-2026-26740
CVSS 8.2giflib_project
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphi…
CVE-2026-26736CVE-2026-26736
CVSS 8.8
TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.
CVE-2026-26732CVE-2026-26732
CVSS 8.8
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter fun…
CVE-2026-26731CVE-2026-26731
CVSS 8.8totolink
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
CVE-2026-26723CVE-2026-26723
CVSS 8.2
Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via…
CVE-2026-2652CVE-2026-2652
CVSS 8.6
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authenticat…
CVE-2026-2650CVE-2026-2650
CVSS 8.8
Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.