89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,501–2,550 of 8,161 in High · page 51 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-2460 | CVE-2026-2460 CVSS 8.1 | A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol t… |
| CVE-2026-2459 | CVE-2026-2459 CVSS 8.1 | A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized … |
| CVE-2026-24572 | CVE-2026-24572 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio Content nelio-content allows Blind S… |
| CVE-2026-2454 | CVE-2026-2454 CVSS 8.6 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to ca… |
| CVE-2026-24516 | CVE-2026-24516 CVSS 8.8 | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner… |
| CVE-2026-24512 | CVE-2026-24512 CVSS 8.8 | A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead … |
| CVE-2026-2448 | CVE-2026-2448 CVSS 8.8 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template(… |
| CVE-2026-24470 | CVE-2026-24470 CVSS 8.1 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permiss… |
| CVE-2026-2447 | CVE-2026-2447 CVSS 8.8mozilla | Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbir… |
| CVE-2026-24452 | CVE-2026-24452 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on th… |
| CVE-2026-24443 | CVE-2026-24443 CVSS 8.8 | EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface… |
| CVE-2026-24440 | CVE-2026-24440 CVSS 8.8 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without … |
| CVE-2026-24428 | CVE-2026-24428 CVSS 8.8 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privi… |
| CVE-2026-24425 | CVE-2026-24425 CVSS 8.8symfony | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template ren… |
| CVE-2026-24412 | CVE-2026-24412 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aHeap Buffe… |
| CVE-2026-24411 | CVE-2026-24411 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B… |
| CVE-2026-24410 | CVE-2026-24410 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B… |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability KEVCVSS 8.8Google | Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. … |
| CVE-2026-24409 | CVE-2026-24409 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B… |
| CVE-2026-24407 | CVE-2026-24407 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B… |
| CVE-2026-24406 | CVE-2026-24406 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buff… |
| CVE-2026-24405 | CVE-2026-24405 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buff… |
| CVE-2026-24404 | CVE-2026-24404 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArray… |
| CVE-2026-24403 | CVE-2026-24403 CVSS 8.8 | iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an integer o… |
| CVE-2026-24373 | CVE-2026-24373 CVSS 8.1 | Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalatio… |
| CVE-2026-24367 | CVE-2026-24367 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.T… |
| CVE-2026-2436 | CVE-2026-2436 CVSS 8.2 | A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees co… |
| CVE-2026-24359 | CVE-2026-24359 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: fr… |
| CVE-2026-2435 | CVE-2026-2435 CVSS 8.8 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2026-24345 | CVE-2026-24345 CVSS 8.8 | Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI |
| CVE-2026-24343 | CVE-2026-24343 CVSS 8.8 | Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.… |
| CVE-2026-24304 | CVE-2026-24304 CVSS 9.9microsoft | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-24283 | CVE-2026-24283 CVSS 8.8 | Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-24222 | CVE-2026-24222 CVSS 8.6 | NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by se… |
| CVE-2026-24218 | CVE-2026-24218 CVSS 8.1nvidia | NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed ac… |
| CVE-2026-24217 | CVE-2026-24217 CVSS 8.8nvidia | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vuln… |
| CVE-2026-24189 | CVE-2026-24189 CVSS 8.2 | NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted req… |
| CVE-2026-24187 | CVE-2026-24187 CVSS 8.8nvidia | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead … |
| CVE-2026-24186 | CVE-2026-24186 CVSS 8.8 | NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message.… |
| CVE-2026-24165 | CVE-2026-24165 CVSS 7.8nvidia | NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … |
| CVE-2026-24135 | CVE-2026-24135 CVSS 8.1 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The … |
| CVE-2026-24129 | CVE-2026-24129 CVSS 8.8 | Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an authentica… |
| CVE-2026-24096 | CVE-2026-24096 CVSS 8.8 | Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 … |
| CVE-2026-24072 | CVE-2026-24072 CVSS 8.8 | An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the htt… |
| CVE-2026-24070 | CVE-2026-24070 CVSS 8.8 | During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to … |
| CVE-2026-24068 | CVE-2026-24068 CVSS 8.8 | The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC framework to v… |
| CVE-2026-24063 | CVE-2026-24063 CVSS 8.2 | When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written… |
| CVE-2026-24038 | CVE-2026-24038 CVSS 8.1 | Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be byp… |
| CVE-2026-24031 | CVE-2026-24031 CVSS 7.7dovecot | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user … |
| CVE-2026-24028 | CVE-2026-24028 CVSS 5.3powerdns | An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS… |