89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,301–2,350 of 8,161 in High · page 47 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-2649 | CVE-2026-2649 CVSS 8.8 | Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
| CVE-2026-2648 | CVE-2026-2648 CVSS 8.8 | Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF fi… |
| CVE-2026-2646 | CVE-2026-2646 CVSS 8.1 | A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certif… |
| CVE-2026-26417 | CVE-2026-26417 CVSS 8.1 | A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to r… |
| CVE-2026-26416 | CVE-2026-26416 CVSS 8.8 | An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across role bound… |
| CVE-2026-26368 | CVE-2026-26368 CVSS 8.8 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authenticated lo… |
| CVE-2026-26367 | CVE-2026-26367 CVSS 8.1 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated l… |
| CVE-2026-26362 | CVE-2026-26362 CVSS 8.1 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentiall… |
| CVE-2026-26360 | CVE-2026-26360 CVSS 8.1 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access c… |
| CVE-2026-26359 | CVE-2026-26359 CVSS 8.8 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access c… |
| CVE-2026-26358 | CVE-2026-26358 CVSS 8.8 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially … |
| CVE-2026-26337 | CVE-2026-26337 CVSS 8.2hyland | Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolut… |
| CVE-2026-26331 | CVE-2026-26331 CVSS 8.8 | yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line optio… |
| CVE-2026-26323 | CVE-2026-26323 CVSS 8.8 | OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts… |
| CVE-2026-26318 | CVE-2026-26318 CVSS 8.8systeminformation | systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` out… |
| CVE-2026-26308 | CVE-2026-26308 CVSS 8.2 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains… |
| CVE-2026-2630 | CVE-2026-2630 CVSS 8.8 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security C… |
| CVE-2026-26289 | CVE-2026-26289 CVSS 8.2 | PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally r… |
| CVE-2026-26286 | CVE-2026-26286 CVSS 8.5 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-… |
| CVE-2026-26264 | CVE-2026-26264 CVSS 8.1 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigg… |
| CVE-2026-2626 | CVE-2026-2626 CVSS 8.1 | The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to mod… |
| CVE-2026-26234 | CVE-2026-26234 CVSS 8.8 | JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injectin… |
| CVE-2026-2623 | CVE-2026-2623 CVSS 8.8 | A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/common-iaas/src/main/java/com/blossom/com… |
| CVE-2026-26189 | CVE-2026-26189 CVSS 8.1 | Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-… |
| CVE-2026-26187 | CVE-2026-26187 CVSS 8.1 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go… |
| CVE-2026-26186 | CVE-2026-26186 CVSS 8.8 | Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL … |
| CVE-2026-26178 | CVE-2026-26178 CVSS 8.8 | Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-2617 | CVE-2026-2617 CVSS 8.8 | A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Service/SSH Service. The manipulation resul… |
| CVE-2026-26148 | CVE-2026-26148 CVSS 8.1 | External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-26139 | CVE-2026-26139 CVSS 8.6 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-26135 | CVE-2026-26135 CVSS 9.6microsoft | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-26119 | CVE-2026-26119 CVSS 8.8 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-26118 | CVE-2026-26118 CVSS 8.8 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-26116 | CVE-2026-26116 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n… |
| CVE-2026-26115 | CVE-2026-26115 CVSS 8.8 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-26114 | CVE-2026-26114 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-26111 | CVE-2026-26111 CVSS 8.0 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2026-26106 | CVE-2026-26106 CVSS 8.8 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-26065 | CVE-2026-26065 CVSS 8.8 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal … |
| CVE-2026-26064 | CVE-2026-26064 CVSS 8.8 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerab… |
| CVE-2026-26060 | CVE-2026-26060 CVSS 8.8 | Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password r… |
| CVE-2026-26056 | CVE-2026-26056 CVSS 8.8 | Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) compon… |
| CVE-2026-2603 | CVE-2026-2603 CVSS 8.1redhat | A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the… |
| CVE-2026-26020 | CVE-2026-26020 CVSS 8.8 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.4… |
| CVE-2026-26016 | CVE-2026-26016 CVSS 8.1 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in … |
| CVE-2026-26001 | CVE-2026-26001 CVSS 8.8 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user in… |
| CVE-2026-25947 | CVE-2026-25947 CVSS 8.8 | Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affec… |
| CVE-2026-25941 | CVE-2026-25941 CVSS 8.1 | FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an ou… |
| CVE-2026-25940 | CVE-2026-25940 CVSS 8.1parall | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitra… |
| CVE-2026-25936 | CVE-2026-25936 CVSS 8.8 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injecti… |