89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,601–2,650 of 8,161 in High · page 53 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-23462 | CVE-2026-23462 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the following trace caused by not dropping l… |
| CVE-2026-23461 | CVE-2026-23461 CVSS 8.8linux | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user After commit ab4eedb790ca (… |
| CVE-2026-23459 | CVE-2026-23459 CVSS 8.2linux | In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot t… |
| CVE-2026-23457 | CVE-2026-23457 CVSS 8.6linux | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() sip_help… |
| CVE-2026-23456 | CVE-2026-23456 CVSS 8.2linux | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case In decode_int(), the… |
| CVE-2026-23395 | CVE-2026-23395 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ Currently the code attempts… |
| CVE-2026-23246 | CVE-2026-23246 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken fro… |
| CVE-2026-2321 | CVE-2026-2321 CVSS 8.8 | Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially… |
| CVE-2026-2315 | CVE-2026-2315 CVSS 8.8 | Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via… |
| CVE-2026-2314 | CVE-2026-2314 CVSS 8.8 | Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… |
| CVE-2026-2313 | CVE-2026-2313 CVSS 8.8 | Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
| CVE-2026-22918 | CVE-2026-22918 CVSS 8.2 | An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, lea… |
| CVE-2026-22861 | CVE-2026-22861 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-22856 | CVE-2026-22856 CVSS 8.1 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free… |
| CVE-2026-22850 | CVE-2026-22850 CVSS 8.3 | Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped analytics … |
| CVE-2026-22828 | CVE-2026-22828 CVSS 8.1 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unaut… |
| CVE-2026-22822 | CVE-2026-22822 CVSS 8.8external-secrets | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 … |
| CVE-2026-22812 | CVE-2026-22812 CVSS 8.8 | OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or an… |
| CVE-2026-22810 | CVE-2026-22810 CVSS 8.2joplinapp | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vuln… |
| CVE-2026-22805 | CVE-2026-22805 CVSS 8.6 | Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions cou… |
| CVE-2026-22799 | CVE-2026-22799 CVSS 8.8 | Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The … |
| CVE-2026-22794 | CVE-2026-22794 CVSS 8.8 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the e… |
| CVE-2026-22790 | CVE-2026-22790 CVSS 8.8 | EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the ch… |
| CVE-2026-22789 | CVE-2026-22789 CVSS 8.8 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass v… |
| CVE-2026-22788 | CVE-2026-22788 CVSS 8.2 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive… |
| CVE-2026-22783 | CVE-2026-22783 CVSS 8.1 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore fil… |
| CVE-2026-22771 | CVE-2026-22771 CVSS 8.8envoyproxy | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtens… |
| CVE-2026-22765 | CVE-2026-22765 CVSS 8.8 | Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potent… |
| CVE-2026-22747 | CVE-2026-22747 CVSS 6.8vmware | Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead … |
| CVE-2026-22742 | CVE-2026-22742 CVSS 8.6 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages… |
| CVE-2026-22739 | CVE-2026-22739 CVSS 8.6vmware | Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file syste… |
| CVE-2026-22734 | CVE-2026-22734 CVSS 8.6 | Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability… |
| CVE-2026-22733 | CVE-2026-22733 CVSS 8.1 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication … |
| CVE-2026-22731 | CVE-2026-22731 CVSS 8.1 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication … |
| CVE-2026-22730 | CVE-2026-22730 CVSS 8.8 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute ar… |
| CVE-2026-22729 | CVE-2026-22729 CVSS 8.6 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through… |
| CVE-2026-22719 | Broadcom VMware Aria Operations Command Injection Vulnerability KEVCVSS 8.1Broadcom | Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacke… |
| CVE-2026-22688 | CVE-2026-22688 CVSS 8.8 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulne… |
| CVE-2026-22683 | CVE-2026-22683 CVSS 8.8 | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity cr… |
| CVE-2026-22665 | CVE-2026-22665 CVSS 8.1fka | prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of username… |
| CVE-2026-22661 | CVE-2026-22661 CVSS 8.1fka | prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the clien… |
| CVE-2026-22627 | CVE-2026-22627 CVSS 8.8 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthen… |
| CVE-2026-22595 | CVE-2026-22595 CVSS 8.1 | Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token … |
| CVE-2026-22594 | CVE-2026-22594 CVSS 8.1 | Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows sta… |
| CVE-2026-22559 | CVE-2026-22559 CVSS 8.8 | An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into… |
| CVE-2026-22550 | CVE-2026-22550 CVSS 8.8 | OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command executio… |
| CVE-2026-22516 | CVE-2026-22516 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wizor's wizors-investment… |
| CVE-2026-22515 | CVE-2026-22515 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows … |
| CVE-2026-22514 | CVE-2026-22514 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Unica unica allows PHP Lo… |
| CVE-2026-22513 | CVE-2026-22513 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Triompher triompher allow… |