89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,451–2,500 of 8,161 in High · page 50 of 164

IDTitleSummary
CVE-2026-25059CVE-2026-25059
CVSS 8.8
OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability in multiple file operation handlers in…
CVE-2026-25056CVE-2026-25056
CVSS 8.8
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticat…
CVE-2026-25055CVE-2026-25055
CVSS 8.1
n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote ser…
CVE-2026-25047CVE-2026-25047
CVSS 8.8
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 o…
CVE-2026-25045CVE-2026-25045
CVSS 8.8
Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR…
CVE-2026-25044CVE-2026-25044
CVSS 8.8budibase
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper s…
CVE-2026-25040CVE-2026-25040
CVSS 8.8
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level user, who nor…
CVE-2026-25037CVE-2026-25037
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on th…
CVE-2026-25022CVE-2026-25022
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system …
CVE-2026-25017CVE-2026-25017
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalif…
CVE-2026-25007CVE-2026-25007
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor eleme…
CVE-2026-25001CVE-2026-25001
CVSS 8.5
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affec…
CVE-2026-24981CVE-2026-24981
CVSS 8.8
Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n…
CVE-2026-24978CVE-2026-24978
CVSS 8.8
Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <=…
CVE-2026-24977CVE-2026-24977
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Bli…
CVE-2026-24976CVE-2026-24976
CVSS 8.8
Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: …
CVE-2026-24974CVE-2026-24974
CVSS 8.8
Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <…
CVE-2026-24959CVE-2026-24959
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL I…
CVE-2026-24954CVE-2026-24954
CVSS 8.8
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a thro…
CVE-2026-24913CVE-2026-24913
CVSS 8.8icz
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained …
CVE-2026-24912CVE-2026-24912
CVSS 8.6
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifi…
CVE-2026-24901CVE-2026-24901
CVSS 8.8
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (IDOR) vulnerability in the document rest…
CVE-2026-24897CVE-2026-24897
CVSS 8.8
Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any sp…
CVE-2026-24893CVE-2026-24893
CVSS 8.8it-novum
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a comma…
CVE-2026-24892CVE-2026-24892
CVSS 8.8
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.…
CVE-2026-24887CVE-2026-24887
CVSS 8.8
Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prom…
CVE-2026-24885CVE-2026-24885
CVSS 8.0
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Project…
CVE-2026-24869CVE-2026-24869
CVSS 8.8mozilla
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
CVE-2026-24854CVE-2026-24854
CVSS 8.8
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7…
CVE-2026-24852CVE-2026-24852
CVSS 8.1
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2…
CVE-2026-24851CVE-2026-24851
CVSS 8.8
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( op…
CVE-2026-24844CVE-2026-24844
CVSS 8.8
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, bu…
CVE-2026-24843CVE-2026-24843
CVSS 8.4
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a…
CVE-2026-24842CVE-2026-24842
CVSS 8.2isaacs
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution se…
CVE-2026-24840CVE-2026-24840
CVSS 8.8
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located…
CVE-2026-24834CVE-2026-24834
CVSS 9.3katacontainers
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions…
CVE-2026-24792CVE-2026-24792
CVSS 8.1
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
CVE-2026-24790CVE-2026-24790
CVSS 8.2
The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
CVE-2026-24788CVE-2026-24788
CVSS 8.8
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who…
CVE-2026-24780CVE-2026-24780
CVSS 8.8
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autog…
CVE-2026-24763CVE-2026-24763
CVSS 8.8
OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClaw…
CVE-2026-24747CVE-2026-24747
CVSS 8.8linuxfoundation
PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker…
CVE-2026-24741CVE-2026-24741
CVSS 8.1
ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to construct a…
CVE-2026-24737CVE-2026-24737
CVSS 8.1parall
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitra…
CVE-2026-24736CVE-2026-24736
CVSS 8.8
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to …
CVE-2026-24708CVE-2026-24708
CVSS 8.2
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk…
CVE-2026-24695CVE-2026-24695
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on…
CVE-2026-24689CVE-2026-24689
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on th…
CVE-2026-24685CVE-2026-24685
CVSS 8.8
OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenPro…
CVE-2026-2465CVE-2026-2465
CVSS 8.8
Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.