89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,401–2,450 of 8,161 in High · page 49 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-25495 | CVE-2026-25495 CVSS 8.8 | Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-element… |
| CVE-2026-25471 | CVE-2026-25471 CVSS 8.1 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitatio… |
| CVE-2026-25464 | CVE-2026-25464 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local… |
| CVE-2026-25458 | CVE-2026-25458 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Moments moments allows P… |
| CVE-2026-25457 | CVE-2026-25457 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows P… |
| CVE-2026-25445 | CVE-2026-25445 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a… |
| CVE-2026-25414 | CVE-2026-25414 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a th… |
| CVE-2026-25406 | CVE-2026-25406 CVSS 8.1 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse.This issue affects Tutor … |
| CVE-2026-25400 | CVE-2026-25400 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0. |
| CVE-2026-25382 | CVE-2026-25382 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes IdealAuto idealauto allows P… |
| CVE-2026-25381 | CVE-2026-25381 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP… |
| CVE-2026-25380 | CVE-2026-25380 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Feedy feedy allows PHP Local… |
| CVE-2026-25379 | CVE-2026-25379 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes StreamVid streamvid allows P… |
| CVE-2026-25360 | CVE-2026-25360 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9. |
| CVE-2026-25359 | CVE-2026-25359 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5. |
| CVE-2026-25358 | CVE-2026-25358 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2. |
| CVE-2026-25357 | CVE-2026-25357 CVSS 8.1 | Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.Th… |
| CVE-2026-2535 | CVE-2026-2535 CVSS 8.8 | A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET§ion=ptes… |
| CVE-2026-2534 | CVE-2026-2534 CVSS 8.8 | A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET§ion… |
| CVE-2026-25334 | CVE-2026-25334 CVSS 8.1 | Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects … |
| CVE-2026-2530 | CVE-2026-2530 CVSS 8.8 | A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of t… |
| CVE-2026-2526 | CVE-2026-2526 CVSS 8.8 | A vulnerability was found in Wavlink WL-WN579A3 up to 20210219. This impacts the function multi_ssid of the file /cgi-bin/wireless.cgi. Performing a manipulati… |
| CVE-2026-25253 | CVE-2026-25253 CVSS 8.8 | OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without promp… |
| CVE-2026-25243 | CVE-2026-25243 CVSS 8.8redis | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authe… |
| CVE-2026-25232 | CVE-2026-25232 CVSS 8.8 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator … |
| CVE-2026-25221 | CVE-2026-25221 CVSS 8.1 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for GitHub and Google login providers is vu… |
| CVE-2026-25201 | CVE-2026-25201 CVSS 8.8 | An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9… |
| CVE-2026-25197 | CVE-2026-25197 CVSS 9.1mygardyn | A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. |
| CVE-2026-25196 | CVE-2026-25196 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-25193 | CVE-2026-25193 CVSS 8.1gallagher | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitig… |
| CVE-2026-25188 | CVE-2026-25188 CVSS 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. |
| CVE-2026-25177 | CVE-2026-25177 CVSS 8.8 | Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a netw… |
| CVE-2026-25173 | CVE-2026-25173 CVSS 8.0 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2026-25172 | CVE-2026-25172 CVSS 8.0 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2026-25164 | CVE-2026-25164 CVSS 8.1 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `a… |
| CVE-2026-25161 | CVE-2026-25161 CVSS 8.8 | Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vuln… |
| CVE-2026-25153 | CVE-2026-25153 CVSS 7.7linuxfoundation | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In ver… |
| CVE-2026-25146 | CVE-2026-25146 CVSS 8.1 | OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two p… |
| CVE-2026-25134 | CVE-2026-25134 CVSS 8.8 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an … |
| CVE-2026-25131 | CVE-2026-25131 CVSS 8.8 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulner… |
| CVE-2026-25116 | CVE-2026-25116 CVSS 8.8 | Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated Path Traversal vulnerability in the `Us… |
| CVE-2026-25111 | CVE-2026-25111 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-25109 | CVE-2026-25109 CVSS 8.0copeland | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on t… |
| CVE-2026-25108 | Soliton Systems K.K FileZen OS Command Injection Vulnerability KEVCVSS 8.8Soliton Systems K.K | Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP requ… |
| CVE-2026-25105 | CVE-2026-25105 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution o… |
| CVE-2026-25099 | CVE-2026-25099 CVSS 8.8 | Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be ex… |
| CVE-2026-25088 | CVE-2026-25088 CVSS 8.8 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 … |
| CVE-2026-25083 | CVE-2026-25083 CVSS 8.3 | GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assist… |
| CVE-2026-25077 | CVE-2026-25077 CVSS 8.8 | Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. D… |
| CVE-2026-25060 | CVE-2026-25060 CVSS 8.1 | OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The T… |