89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,351–2,400 of 8,161 in High · page 48 of 164

IDTitleSummary
CVE-2026-25924CVE-2026-25924
CVSS 8.4
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authentic…
CVE-2026-25922CVE-2026-25922
CVSS 8.8
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signa…
CVE-2026-25890CVE-2026-25890
CVSS 8.1
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.5…
CVE-2026-25888CVE-2026-25888
CVSS 8.8
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is…
CVE-2026-25884CVE-2026-25884
CVSS 8.1
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-…
CVE-2026-25859CVE-2026-25859
CVSS 8.8wekan_project
Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in u…
CVE-2026-25857CVE-2026-25857
CVSS 8.8
Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). T…
CVE-2026-25817CVE-2026-25817
CVSS 8.8
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutral…
CVE-2026-25812CVE-2026-25812
CVSS 8.8
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does n…
CVE-2026-25807CVE-2026-25807
CVSS 8.8
ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share …
CVE-2026-25805CVE-2026-25805
CVSS 8.0
Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does…
CVE-2026-25794CVE-2026-25794
CVSS 8.2imagemagick
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to com…
CVE-2026-25793CVE-2026-25793
CVSS 8.1
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is po…
CVE-2026-25781CVE-2026-25781
CVSS 8.4
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
CVE-2026-25767CVE-2026-25767
CVSS 8.1
LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing…
CVE-2026-25761CVE-2026-25761
CVSS 8.8
Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to…
CVE-2026-25759CVE-2026-25759
CVSS 8.7
Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authent…
CVE-2026-25755CVE-2026-25755
CVSS 8.1parall
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PD…
CVE-2026-25750CVE-2026-25750
CVSS 8.1
Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection…
CVE-2026-25747CVE-2026-25747
CVSS 8.8apache
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read fro…
CVE-2026-25746CVE-2026-25746
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulner…
CVE-2026-25721CVE-2026-25721
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the…
CVE-2026-25705CVE-2026-25705
CVSS 8.4
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicio…
CVE-2026-25654CVE-2026-25654
CVSS 8.8
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing passw…
CVE-2026-25649CVE-2026-25649
CVSS 8.7
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorizat…
CVE-2026-25648CVE-2026-25648
CVSS 8.7
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in …
CVE-2026-25646CVE-2026-25646
CVSS 8.1libpng
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an…
CVE-2026-2564CVE-2026-2564
CVSS 8.1
A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /Outsi…
CVE-2026-25635CVE-2026-25635
CVSS 8.6
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user …
CVE-2026-2563CVE-2026-2563
CVSS 8.8
A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file …
CVE-2026-25628CVE-2026-25628
CVSS 8.8
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint …
CVE-2026-2562CVE-2026-2562
CVSS 8.8
A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jd…
CVE-2026-2561CVE-2026-2561
CVSS 8.8
A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component…
CVE-2026-25593CVE-2026-25593
CVSS 8.4
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply a…
CVE-2026-25589CVE-2026-25589
CVSS 8.8redisbloom
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized v…
CVE-2026-25588CVE-2026-25588
CVSS 8.8redistimeseries
RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values p…
CVE-2026-25580CVE-2026-25580
CVSS 8.6pydantic
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery …
CVE-2026-25545CVE-2026-25545
CVSS 8.6
Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500…
CVE-2026-2554CVE-2026-2554
CVSS 8.1
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object R…
CVE-2026-25538CVE-2026-25538
CVSS 8.8
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, a…
CVE-2026-25533CVE-2026-25533
CVSS 8.8
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficie…
CVE-2026-25532CVE-2026-25532
CVSS 8.0
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (…
CVE-2026-25529CVE-2026-25529
CVSS 8.1
Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admi…
CVE-2026-25524CVE-2026-25524
CVSS 8.1
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a …
CVE-2026-25521CVE-2026-25521
CVSS 8.8locutus
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution v…
CVE-2026-25514CVE-2026-25514
CVSS 8.8
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection …
CVE-2026-25513CVE-2026-25513
CVSS 8.8
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection …
CVE-2026-25512CVE-2026-25512
CVSS 8.8
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execu…
CVE-2026-25510CVE-2026-25510
CVSS 8.8
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version …
CVE-2026-25497CVE-2026-25497
CVSS 8.8
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalatio…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.