89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,751–2,800 of 8,161 in High · page 56 of 164

IDTitleSummary
CVE-2026-22222CVE-2026-22222
CVSS 8.0
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successfu…
CVE-2026-22221CVE-2026-22221
CVSS 8.0tp-link
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary co…
CVE-2026-22206CVE-2026-22206
CVSS 8.8
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulat…
CVE-2026-22197CVE-2026-22197
CVSS 8.1
GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, se…
CVE-2026-22196CVE-2026-22196
CVSS 8.1
GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation …
CVE-2026-22195CVE-2026-22195
CVSS 8.1
GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL q…
CVE-2026-22194CVE-2026-22194
CVSS 8.8
GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of…
CVE-2026-2218CVE-2026-2218
CVSS 8.8
A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This ma…
CVE-2026-22178CVE-2026-22178
CVSS 8.2
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex i…
CVE-2026-22177CVE-2026-22177
CVSS 8.8
OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars, allowing startup-time code execution.…
CVE-2026-22168CVE-2026-22168
CVSS 8.8
OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows authenticated operators to execute arbitrar…
CVE-2026-22166CVE-2026-22166
CVSS 8.1imaginationtech
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared libra…
CVE-2026-22165CVE-2026-22165
CVSS 8.1imaginationtech
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared lib…
CVE-2026-22153CVE-2026-22153
CVSS 8.1
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacke…
CVE-2026-2206CVE-2026-2206
CVSS 8.8
A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the compone…
CVE-2026-22047CVE-2026-22047
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-22046CVE-2026-22046
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-22044CVE-2026-22044
CVSS 8.8
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has…
CVE-2026-22042CVE-2026-22042
CVSS 8.8
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAc…
CVE-2026-22038CVE-2026-22038
CVSS 8.1
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autog…
CVE-2026-22037CVE-2026-22037
CVSS 8.4
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middle…
CVE-2026-22031CVE-2026-22031
CVSS 8.8
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 wh…
CVE-2026-2203CVE-2026-2203
CVSS 8.8
A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the com…
CVE-2026-22022CVE-2026-22022
CVSS 8.2
Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain…
CVE-2026-2202CVE-2026-2202
CVSS 8.8
A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet of the component httpd. …
CVE-2026-21997CVE-2026-21997
CVSS 8.5
Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are af…
CVE-2026-21990CVE-2026-21990
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi…
CVE-2026-21989CVE-2026-21989
CVSS 8.1
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi…
CVE-2026-21988CVE-2026-21988
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi…
CVE-2026-21987CVE-2026-21987
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi…
CVE-2026-21973CVE-2026-21973
CVSS 8.1
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported v…
CVE-2026-21967CVE-2026-21967
CVSS 8.6
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected ar…
CVE-2026-21956CVE-2026-21956
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi…
CVE-2026-21955CVE-2026-21955
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easi…
CVE-2026-2194CVE-2026-2194
CVSS 8.8
A flaw has been found in D-Link DI-7100G C1 24.04.18D1. This affects the function start_proxy_client_email. Executing a manipulation can lead to command inject…
CVE-2026-2193CVE-2026-2193
CVSS 8.8
A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argumen…
CVE-2026-21898CVE-2026-21898
CVSS 8.2
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between …
CVE-2026-21886CVE-2026-21886
CVSS 8.1
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualD…
CVE-2026-21884CVE-2026-21884
CVSS 8.2shopify
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React …
CVE-2026-21882CVE-2026-21882
CVSS 8.4
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping a…
CVE-2026-2187CVE-2026-2187
CVSS 8.8
A vulnerability was found in Tenda RX3 16.03.13.11. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manip…
CVE-2026-2186CVE-2026-2186
CVSS 8.8
A vulnerability has been found in Tenda RX3 16.03.13.11. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the a…
CVE-2026-21856CVE-2026-21856
CVSS 8.8
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vu…
CVE-2026-21853CVE-2026-21853
CVSS 8.8
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This…
CVE-2026-2185CVE-2026-2185
CVSS 8.8
A flaw has been found in Tenda RX3 16.03.13.11. This issue affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering…
CVE-2026-21821CVE-2026-21821
CVSS 8.3
The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longe…
CVE-2026-2181CVE-2026-2181
CVSS 8.8
A security flaw has been discovered in Tenda RX3 16.03.13.11. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. Per…
CVE-2026-2180CVE-2026-2180
CVSS 8.8
A vulnerability was identified in Tenda RX3 16.03.13.11. Affected is an unknown function of the file /goform/fast_setting_wifi_set. Such manipulation of the ar…
CVE-2026-2178CVE-2026-2178
CVSS 8.8
A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file…
CVE-2026-2176CVE-2026-2176
CVSS 8.8
A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Suc…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.