89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,751–2,800 of 8,161 in High · page 56 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-22222 | CVE-2026-22222 CVSS 8.0 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successfu… |
| CVE-2026-22221 | CVE-2026-22221 CVSS 8.0tp-link | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary co… |
| CVE-2026-22206 | CVE-2026-22206 CVSS 8.8 | SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulat… |
| CVE-2026-22197 | CVE-2026-22197 CVSS 8.1 | GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, se… |
| CVE-2026-22196 | CVE-2026-22196 CVSS 8.1 | GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation … |
| CVE-2026-22195 | CVE-2026-22195 CVSS 8.1 | GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL q… |
| CVE-2026-22194 | CVE-2026-22194 CVSS 8.8 | GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of… |
| CVE-2026-2218 | CVE-2026-2218 CVSS 8.8 | A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This ma… |
| CVE-2026-22178 | CVE-2026-22178 CVSS 8.2 | OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex i… |
| CVE-2026-22177 | CVE-2026-22177 CVSS 8.8 | OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution.… |
| CVE-2026-22168 | CVE-2026-22168 CVSS 8.8 | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrar… |
| CVE-2026-22166 | CVE-2026-22166 CVSS 8.1imaginationtech | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared libra… |
| CVE-2026-22165 | CVE-2026-22165 CVSS 8.1imaginationtech | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared lib… |
| CVE-2026-22153 | CVE-2026-22153 CVSS 8.1 | An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacke… |
| CVE-2026-2206 | CVE-2026-2206 CVSS 8.8 | A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the compone… |
| CVE-2026-22047 | CVE-2026-22047 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-22046 | CVE-2026-22046 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-22044 | CVE-2026-22044 CVSS 8.8 | GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has… |
| CVE-2026-22042 | CVE-2026-22042 CVSS 8.8 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAc… |
| CVE-2026-22038 | CVE-2026-22038 CVSS 8.1 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autog… |
| CVE-2026-22037 | CVE-2026-22037 CVSS 8.4 | The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middle… |
| CVE-2026-22031 | CVE-2026-22031 CVSS 8.8 | @fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 wh… |
| CVE-2026-2203 | CVE-2026-2203 CVSS 8.8 | A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the com… |
| CVE-2026-22022 | CVE-2026-22022 CVSS 8.2 | Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain… |
| CVE-2026-2202 | CVE-2026-2202 CVSS 8.8 | A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. … |
| CVE-2026-21997 | CVE-2026-21997 CVSS 8.5 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are af… |
| CVE-2026-21990 | CVE-2026-21990 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi… |
| CVE-2026-21989 | CVE-2026-21989 CVSS 8.1 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi… |
| CVE-2026-21988 | CVE-2026-21988 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi… |
| CVE-2026-21987 | CVE-2026-21987 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi… |
| CVE-2026-21973 | CVE-2026-21973 CVSS 8.1 | Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported v… |
| CVE-2026-21967 | CVE-2026-21967 CVSS 8.6 | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected ar… |
| CVE-2026-21956 | CVE-2026-21956 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi… |
| CVE-2026-21955 | CVE-2026-21955 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi… |
| CVE-2026-2194 | CVE-2026-2194 CVSS 8.8 | A flaw has been found in D-Link DI-7100G C1 24.04.18D1. This affects the function start_proxy_client_email. Executing a manipulation can lead to command inject… |
| CVE-2026-2193 | CVE-2026-2193 CVSS 8.8 | A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argumen… |
| CVE-2026-21898 | CVE-2026-21898 CVSS 8.2 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between … |
| CVE-2026-21886 | CVE-2026-21886 CVSS 8.1 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualD… |
| CVE-2026-21884 | CVE-2026-21884 CVSS 8.2shopify | React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React … |
| CVE-2026-21882 | CVE-2026-21882 CVSS 8.4 | theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping a… |
| CVE-2026-2187 | CVE-2026-2187 CVSS 8.8 | A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manip… |
| CVE-2026-2186 | CVE-2026-2186 CVSS 8.8 | A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the a… |
| CVE-2026-21856 | CVE-2026-21856 CVSS 8.8 | The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vu… |
| CVE-2026-21853 | CVE-2026-21853 CVSS 8.8 | AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This… |
| CVE-2026-2185 | CVE-2026-2185 CVSS 8.8 | A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering… |
| CVE-2026-21821 | CVE-2026-21821 CVSS 8.3 | The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longe… |
| CVE-2026-2181 | CVE-2026-2181 CVSS 8.8 | A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Per… |
| CVE-2026-2180 | CVE-2026-2180 CVSS 8.8 | A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the ar… |
| CVE-2026-2178 | CVE-2026-2178 CVSS 8.8 | A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file… |
| CVE-2026-2176 | CVE-2026-2176 CVSS 8.8 | A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Suc… |