89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,351–2,400 of 8,161 in High · page 48 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-25924 | CVE-2026-25924 CVSS 8.4 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authentic… |
| CVE-2026-25922 | CVE-2026-25922 CVSS 8.8 | authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signa… |
| CVE-2026-25890 | CVE-2026-25890 CVSS 8.1 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.5… |
| CVE-2026-25888 | CVE-2026-25888 CVSS 8.8 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is… |
| CVE-2026-25884 | CVE-2026-25884 CVSS 8.1 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-… |
| CVE-2026-25859 | CVE-2026-25859 CVSS 8.8wekan_project | Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in u… |
| CVE-2026-25857 | CVE-2026-25857 CVSS 8.8 | Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). T… |
| CVE-2026-25817 | CVE-2026-25817 CVSS 8.8 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutral… |
| CVE-2026-25812 | CVE-2026-25812 CVSS 8.8 | PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does n… |
| CVE-2026-25807 | CVE-2026-25807 CVSS 8.8 | ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share … |
| CVE-2026-25805 | CVE-2026-25805 CVSS 8.0 | Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does… |
| CVE-2026-25794 | CVE-2026-25794 CVSS 8.2imagemagick | ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to com… |
| CVE-2026-25793 | CVE-2026-25793 CVSS 8.1 | Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is po… |
| CVE-2026-25781 | CVE-2026-25781 CVSS 8.4 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered. |
| CVE-2026-25767 | CVE-2026-25767 CVSS 8.1 | LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing… |
| CVE-2026-25761 | CVE-2026-25761 CVSS 8.8 | Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to… |
| CVE-2026-25759 | CVE-2026-25759 CVSS 8.7 | Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authent… |
| CVE-2026-25755 | CVE-2026-25755 CVSS 8.1parall | jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PD… |
| CVE-2026-25750 | CVE-2026-25750 CVSS 8.1 | Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection… |
| CVE-2026-25747 | CVE-2026-25747 CVSS 8.8apache | Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read fro… |
| CVE-2026-25746 | CVE-2026-25746 CVSS 8.8 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulner… |
| CVE-2026-25721 | CVE-2026-25721 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-25705 | CVE-2026-25705 CVSS 8.4 | A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicio… |
| CVE-2026-25654 | CVE-2026-25654 CVSS 8.8 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing passw… |
| CVE-2026-25649 | CVE-2026-25649 CVSS 8.7 | Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorizat… |
| CVE-2026-25648 | CVE-2026-25648 CVSS 8.7 | Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in … |
| CVE-2026-25646 | CVE-2026-25646 CVSS 8.1libpng | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an… |
| CVE-2026-2564 | CVE-2026-2564 CVSS 8.1 | A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /Outsi… |
| CVE-2026-25635 | CVE-2026-25635 CVSS 8.6 | calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user … |
| CVE-2026-2563 | CVE-2026-2563 CVSS 8.8 | A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file … |
| CVE-2026-25628 | CVE-2026-25628 CVSS 8.8 | Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint … |
| CVE-2026-2562 | CVE-2026-2562 CVSS 8.8 | A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jd… |
| CVE-2026-2561 | CVE-2026-2561 CVSS 8.8 | A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component… |
| CVE-2026-25593 | CVE-2026-25593 CVSS 8.4 | OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply a… |
| CVE-2026-25589 | CVE-2026-25589 CVSS 8.8redisbloom | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized v… |
| CVE-2026-25588 | CVE-2026-25588 CVSS 8.8redistimeseries | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values p… |
| CVE-2026-25580 | CVE-2026-25580 CVSS 8.6pydantic | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery … |
| CVE-2026-25545 | CVE-2026-25545 CVSS 8.6 | Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500… |
| CVE-2026-2554 | CVE-2026-2554 CVSS 8.1 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object R… |
| CVE-2026-25538 | CVE-2026-25538 CVSS 8.8 | Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, a… |
| CVE-2026-25533 | CVE-2026-25533 CVSS 8.8 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficie… |
| CVE-2026-25532 | CVE-2026-25532 CVSS 8.0 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (… |
| CVE-2026-25529 | CVE-2026-25529 CVSS 8.1 | Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admi… |
| CVE-2026-25524 | CVE-2026-25524 CVSS 8.1 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a … |
| CVE-2026-25521 | CVE-2026-25521 CVSS 8.8locutus | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution v… |
| CVE-2026-25514 | CVE-2026-25514 CVSS 8.8 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection … |
| CVE-2026-25513 | CVE-2026-25513 CVSS 8.8 | FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection … |
| CVE-2026-25512 | CVE-2026-25512 CVSS 8.8 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execu… |
| CVE-2026-25510 | CVE-2026-25510 CVSS 8.8 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version … |
| CVE-2026-25497 | CVE-2026-25497 CVSS 8.8 | Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalatio… |