89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,501–2,550 of 8,161 in High · page 51 of 164

IDTitleSummary
CVE-2026-2460CVE-2026-2460
CVSS 8.1
A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol t…
CVE-2026-2459CVE-2026-2459
CVSS 8.1
A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized …
CVE-2026-24572CVE-2026-24572
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio Content nelio-content allows Blind S…
CVE-2026-2454CVE-2026-2454
CVSS 8.6
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to ca…
CVE-2026-24516CVE-2026-24516
CVSS 8.8
A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner…
CVE-2026-24512CVE-2026-24512
CVSS 8.8
A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead …
CVE-2026-2448CVE-2026-2448
CVSS 8.8
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate_template(…
CVE-2026-24470CVE-2026-24470
CVSS 8.1
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permiss…
CVE-2026-2447CVE-2026-2447
CVSS 8.8mozilla
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbir…
CVE-2026-24452CVE-2026-24452
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on th…
CVE-2026-24443CVE-2026-24443
CVSS 8.8
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface…
CVE-2026-24440CVE-2026-24440
CVSS 8.8
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without …
CVE-2026-24428CVE-2026-24428
CVSS 8.8
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privi…
CVE-2026-24425CVE-2026-24425
CVSS 8.8symfony
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template ren…
CVE-2026-24412CVE-2026-24412
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have aHeap Buffe…
CVE-2026-24411CVE-2026-24411
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B…
CVE-2026-24410CVE-2026-24410
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B…
CVE-2026-2441Google Chromium CSS Use-After-Free Vulnerability
KEVCVSS 8.8Google
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
CVE-2026-24409CVE-2026-24409
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B…
CVE-2026-24407CVE-2026-24407
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined B…
CVE-2026-24406CVE-2026-24406
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buff…
CVE-2026-24405CVE-2026-24405
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have a Heap Buff…
CVE-2026-24404CVE-2026-24404
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArray…
CVE-2026-24403CVE-2026-24403
CVSS 8.8
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an integer o…
CVE-2026-24373CVE-2026-24373
CVSS 8.1
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalatio…
CVE-2026-24367CVE-2026-24367
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.T…
CVE-2026-2436CVE-2026-2436
CVSS 8.2
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees co…
CVE-2026-24359CVE-2026-24359
CVSS 8.8
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: fr…
CVE-2026-2435CVE-2026-2435
CVSS 8.8
Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-24345CVE-2026-24345
CVSS 8.8
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI
CVE-2026-24343CVE-2026-24343
CVSS 8.8
Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.…
CVE-2026-24304CVE-2026-24304
CVSS 9.9microsoft
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-24283CVE-2026-24283
CVSS 8.8
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
CVE-2026-24222CVE-2026-24222
CVSS 8.6
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by se…
CVE-2026-24218CVE-2026-24218
CVSS 8.1nvidia
NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed ac…
CVE-2026-24217CVE-2026-24217
CVSS 8.8nvidia
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vuln…
CVE-2026-24189CVE-2026-24189
CVSS 8.2
NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted req…
CVE-2026-24187CVE-2026-24187
CVSS 8.8nvidia
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead …
CVE-2026-24186CVE-2026-24186
CVSS 8.8
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message.…
CVE-2026-24165CVE-2026-24165
CVSS 7.8nvidia
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to …
CVE-2026-24135CVE-2026-24135
CVSS 8.1
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The …
CVE-2026-24129CVE-2026-24129
CVSS 8.8
Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an authentica…
CVE-2026-24096CVE-2026-24096
CVSS 8.8
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 …
CVE-2026-24072CVE-2026-24072
CVSS 8.8
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the htt…
CVE-2026-24070CVE-2026-24070
CVSS 8.8
During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to …
CVE-2026-24068CVE-2026-24068
CVSS 8.8
The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, which is used by the NSXPC framework to v…
CVE-2026-24063CVE-2026-24063
CVSS 8.2
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written…
CVE-2026-24038CVE-2026-24038
CVSS 8.1
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be byp…
CVE-2026-24031CVE-2026-24031
CVSS 7.7dovecot
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user …
CVE-2026-24028CVE-2026-24028
CVSS 5.3powerdns
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.