89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,301–2,350 of 8,161 in High · page 47 of 164

IDTitleSummary
CVE-2026-2649CVE-2026-2649
CVSS 8.8
Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…
CVE-2026-2648CVE-2026-2648
CVSS 8.8
Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF fi…
CVE-2026-2646CVE-2026-2646
CVSS 8.1
A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session data with SESSION_CERTS enabled, certif…
CVE-2026-26417CVE-2026-26417
CVSS 8.1
A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to r…
CVE-2026-26416CVE-2026-26416
CVSS 8.8
An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across role bound…
CVE-2026-26368CVE-2026-26368
CVSS 8.8
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authenticated lo…
CVE-2026-26367CVE-2026-26367
CVSS 8.1
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated l…
CVE-2026-26362CVE-2026-26362
CVSS 8.1
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentiall…
CVE-2026-26360CVE-2026-26360
CVSS 8.1
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access c…
CVE-2026-26359CVE-2026-26359
CVSS 8.8
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access c…
CVE-2026-26358CVE-2026-26358
CVSS 8.8
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially …
CVE-2026-26337CVE-2026-26337
CVSS 8.2hyland
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolut…
CVE-2026-26331CVE-2026-26331
CVSS 8.8
yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line optio…
CVE-2026-26323CVE-2026-26323
CVSS 8.8
OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts…
CVE-2026-26318CVE-2026-26318
CVSS 8.8systeminformation
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` out…
CVE-2026-26308CVE-2026-26308
CVSS 8.2
Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Role-Based Access Control) filter contains…
CVE-2026-2630CVE-2026-2630
CVSS 8.8
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security C…
CVE-2026-26289CVE-2026-26289
CVSS 8.2
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally r…
CVE-2026-26286CVE-2026-26286
CVSS 8.5
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-…
CVE-2026-26264CVE-2026-26264
CVSS 8.1
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigg…
CVE-2026-2626CVE-2026-2626
CVSS 8.1
The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to mod…
CVE-2026-26234CVE-2026-26234
CVSS 8.8
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injectin…
CVE-2026-2623CVE-2026-2623
CVSS 8.8
A flaw has been found in Blossom up to 1.17.1. This issue affects the function put of the file blossom-backend/common/common-iaas/src/main/java/com/blossom/com…
CVE-2026-26189CVE-2026-26189
CVSS 8.1
Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-…
CVE-2026-26187CVE-2026-26187
CVSS 8.1
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go…
CVE-2026-26186CVE-2026-26186
CVSS 8.8
Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbitrary SQL …
CVE-2026-26178CVE-2026-26178
CVSS 8.8
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-2617CVE-2026-2617
CVSS 8.8
A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Service/SSH Service. The manipulation resul…
CVE-2026-26148CVE-2026-26148
CVSS 8.1
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
CVE-2026-26139CVE-2026-26139
CVSS 8.6
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-26135CVE-2026-26135
CVSS 9.6microsoft
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
CVE-2026-26119CVE-2026-26119
CVSS 8.8
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-26118CVE-2026-26118
CVSS 8.8
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26116CVE-2026-26116
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n…
CVE-2026-26115CVE-2026-26115
CVSS 8.8
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26114CVE-2026-26114
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26111CVE-2026-26111
CVSS 8.0
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2026-26106CVE-2026-26106
CVSS 8.8
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26065CVE-2026-26065
CVSS 8.8
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal …
CVE-2026-26064CVE-2026-26064
CVSS 8.8
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerab…
CVE-2026-26060CVE-2026-26060
CVSS 8.8
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic could allow previously issued password r…
CVE-2026-26056CVE-2026-26056
CVSS 8.8
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) compon…
CVE-2026-2603CVE-2026-2603
CVSS 8.1redhat
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the…
CVE-2026-26020CVE-2026-26020
CVSS 8.8
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.4…
CVE-2026-26016CVE-2026-26016
CVSS 8.1
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in …
CVE-2026-26001CVE-2026-26001
CVSS 8.8
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user in…
CVE-2026-25947CVE-2026-25947
CVSS 8.8
Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affec…
CVE-2026-25941CVE-2026-25941
CVSS 8.1
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an ou…
CVE-2026-25940CVE-2026-25940
CVSS 8.1parall
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitra…
CVE-2026-25936CVE-2026-25936
CVSS 8.8
GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injecti…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.