89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,551–2,600 of 8,161 in High · page 52 of 164

IDTitleSummary
CVE-2026-24017CVE-2026-24017
CVSS 8.1
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, Fort…
CVE-2026-24010CVE-2026-24010
CVSS 8.0
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Enginee…
CVE-2026-23989CVE-2026-23989
CVSS 8.1
REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a mali…
CVE-2026-23971CVE-2026-23971
CVSS 8.1
Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8.
CVE-2026-23954CVE-2026-23954
CVSS 8.7
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g…
CVE-2026-23953CVE-2026-23953
CVSS 8.7
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configu…
CVE-2026-23949CVE-2026-23949
CVSS 8.6
jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `…
CVE-2026-23918CVE-2026-23918
CVSS 8.8apache
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommend…
CVE-2026-23902CVE-2026-23902
CVSS 8.1
Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined o…
CVE-2026-23899CVE-2026-23899
CVSS 8.8
An improper access check allows unauthorized access to webservice endpoints.
CVE-2026-23896CVE-2026-23896
CVSS 8.8
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling th…
CVE-2026-23891CVE-2026-23891
CVSS 8.7
Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name …
CVE-2026-23857CVE-2026-23857
CVSS 8.2
Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability.…
CVE-2026-23853CVE-2026-23853
CVSS 8.4
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 throug…
CVE-2026-23836CVE-2026-23836
CVSS 8.8
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which…
CVE-2026-23819CVE-2026-23819
CVSS 8.8arubanetworks
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execu…
CVE-2026-23814CVE-2026-23814
CVSS 8.8hpe
A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious command…
CVE-2026-23808CVE-2026-23808
CVSS 8.1
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Tem…
CVE-2026-23801CVE-2026-23801
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes The Issue theissue allows P…
CVE-2026-23798CVE-2026-23798
CVSS 8.8
Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: f…
CVE-2026-23780CVE-2026-23780
CVSS 8.8
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated atta…
CVE-2026-23776CVE-2026-23776
CVSS 8.8
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 throug…
CVE-2026-23754CVE-2026-23754
CVSS 8.8
D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an ar…
CVE-2026-23750CVE-2026-23750
CVSS 8.1
Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() alloc…
CVE-2026-23742CVE-2026-23742
CVSS 8.8
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem …
CVE-2026-23741CVE-2026-23741
CVSS 8.8
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/cont…
CVE-2026-23708CVE-2026-23708
CVSS 8.1
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through …
CVE-2026-23702CVE-2026-23702
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the…
CVE-2026-2370CVE-2026-2370
CVSS 8.1gitlab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Conn…
CVE-2026-23687CVE-2026-23687
CVSS 8.8sap
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modif…
CVE-2026-23678CVE-2026-23678
CVSS 8.8
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function…
CVE-2026-23669CVE-2026-23669
CVSS 8.8
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
CVE-2026-23654CVE-2026-23654
CVSS 8.8
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.
CVE-2026-23631CVE-2026-23631
CVSS 8.1redis
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchr…
CVE-2026-23627CVE-2026-23627
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability…
CVE-2026-23622CVE-2026-23622
CVSS 8.8
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST req…
CVE-2026-2361CVE-2026-2361
CVSS 8.0
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing mali…
CVE-2026-2360CVE-2026-2360
CVSS 8.0
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place mal…
CVE-2026-23595CVE-2026-23595
CVSS 8.8
An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability…
CVE-2026-23568CVE-2026-23568
CVSS 8.1
An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Win…
CVE-2026-23544CVE-2026-23544
CVSS 8.8
Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.
CVE-2026-23535CVE-2026-23535
CVSS 8.0
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instru…
CVE-2026-23526CVE-2026-23526
CVSS 8.8
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may …
CVE-2026-23525CVE-2026-23525
CVSS 8.4
1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel App Store…
CVE-2026-23523CVE-2026-23523
CVSS 8.8
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attac…
CVE-2026-23520CVE-2026-23520
CVSS 8.0
Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle …
CVE-2026-23517CVE-2026-23517
CVSS 8.1
Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenti…
CVE-2026-23515CVE-2026-23515
CVSS 8.8
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with…
CVE-2026-23480CVE-2026-23480
CVSS 8.8
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability. The upsertUser endpoint has 3 issues: …
CVE-2026-23479CVE-2026-23479
CVSS 8.8redis
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processComman…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.