89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,551–2,600 of 8,161 in High · page 52 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-24017 | CVE-2026-24017 CVSS 8.1 | An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, Fort… |
| CVE-2026-24010 | CVE-2026-24010 CVSS 8.0 | Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Enginee… |
| CVE-2026-23989 | CVE-2026-23989 CVSS 8.1 | REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Reva" component of OpenCloud allows a mali… |
| CVE-2026-23971 | CVE-2026-23971 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8. |
| CVE-2026-23954 | CVE-2026-23954 CVSS 8.7 | Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g… |
| CVE-2026-23953 | CVE-2026-23953 CVSS 8.7 | Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configu… |
| CVE-2026-23949 | CVE-2026-23949 CVSS 8.6 | jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `… |
| CVE-2026-23918 | CVE-2026-23918 CVSS 8.8apache | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommend… |
| CVE-2026-23902 | CVE-2026-23902 CVSS 8.1 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined o… |
| CVE-2026-23899 | CVE-2026-23899 CVSS 8.8 | An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2026-23896 | CVE-2026-23896 CVSS 8.8 | immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling th… |
| CVE-2026-23891 | CVE-2026-23891 CVSS 8.7 | Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the user name … |
| CVE-2026-23857 | CVE-2026-23857 CVSS 8.2 | Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability.… |
| CVE-2026-23853 | CVE-2026-23853 CVSS 8.4 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 throug… |
| CVE-2026-23836 | CVE-2026-23836 CVSS 8.8 | HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which… |
| CVE-2026-23819 | CVE-2026-23819 CVSS 8.8arubanetworks | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execu… |
| CVE-2026-23814 | CVE-2026-23814 CVSS 8.8hpe | A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious command… |
| CVE-2026-23808 | CVE-2026-23808 CVSS 8.1 | A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Tem… |
| CVE-2026-23801 | CVE-2026-23801 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes The Issue theissue allows P… |
| CVE-2026-23798 | CVE-2026-23798 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: f… |
| CVE-2026-23780 | CVE-2026-23780 CVSS 8.8 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated atta… |
| CVE-2026-23776 | CVE-2026-23776 CVSS 8.8 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 throug… |
| CVE-2026-23754 | CVE-2026-23754 CVSS 8.8 | D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an ar… |
| CVE-2026-23750 | CVE-2026-23750 CVSS 8.1 | Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() alloc… |
| CVE-2026-23742 | CVE-2026-23742 CVSS 8.8 | Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem … |
| CVE-2026-23741 | CVE-2026-23741 CVSS 8.8 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/cont… |
| CVE-2026-23708 | CVE-2026-23708 CVSS 8.1 | A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through … |
| CVE-2026-23702 | CVE-2026-23702 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-2370 | CVE-2026-2370 CVSS 8.1gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Conn… |
| CVE-2026-23687 | CVE-2026-23687 CVSS 8.8sap | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modif… |
| CVE-2026-23678 | CVE-2026-23678 CVSS 8.8 | Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function… |
| CVE-2026-23669 | CVE-2026-23669 CVSS 8.8 | Use after free in RPC Runtime allows an authorized attacker to execute code over a network. |
| CVE-2026-23654 | CVE-2026-23654 CVSS 8.8 | Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. |
| CVE-2026-23631 | CVE-2026-23631 CVSS 8.1redis | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchr… |
| CVE-2026-23627 | CVE-2026-23627 CVSS 8.8 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability… |
| CVE-2026-23622 | CVE-2026-23622 CVSS 8.8 | Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST req… |
| CVE-2026-2361 | CVE-2026-2361 CVSS 8.0 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing mali… |
| CVE-2026-2360 | CVE-2026-2360 CVSS 8.0 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place mal… |
| CVE-2026-23595 | CVE-2026-23595 CVSS 8.8 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability… |
| CVE-2026-23568 | CVE-2026-23568 CVSS 8.1 | An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Win… |
| CVE-2026-23544 | CVE-2026-23544 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5. |
| CVE-2026-23535 | CVE-2026-23535 CVSS 8.0 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instru… |
| CVE-2026-23526 | CVE-2026-23526 CVSS 8.8 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may … |
| CVE-2026-23525 | CVE-2026-23525 CVSS 8.4 | 1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel App Store… |
| CVE-2026-23523 | CVE-2026-23523 CVSS 8.8 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attac… |
| CVE-2026-23520 | CVE-2026-23520 CVSS 8.0 | Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle … |
| CVE-2026-23517 | CVE-2026-23517 CVSS 8.1 | Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenti… |
| CVE-2026-23515 | CVE-2026-23515 CVSS 8.8 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with… |
| CVE-2026-23480 | CVE-2026-23480 CVSS 8.8 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability. The upsertUser endpoint has 3 issues: … |
| CVE-2026-23479 | CVE-2026-23479 CVSS 8.8redis | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processComman… |