89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,801–2,850 of 8,161 in High · page 57 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-21721 | CVE-2026-21721 CVSS 8.1grafana | The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permi… |
| CVE-2026-21697 | CVE-2026-21697 CVSS 8.1 | axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaul… |
| CVE-2026-21694 | CVE-2026-21694 CVSS 8.1 | Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time… |
| CVE-2026-21693 | CVE-2026-21693 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-21692 | CVE-2026-21692 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-2169 | CVE-2026-2169 CVSS 8.8 | A vulnerability has been found in D-Link DWR-M921 1.1.50. This impacts an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of … |
| CVE-2026-21688 | CVE-2026-21688 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-21683 | CVE-2026-21683 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-21682 | CVE-2026-21682 CVSS 8.8 | iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage… |
| CVE-2026-2168 | CVE-2026-2168 CVSS 8.8 | A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the a… |
| CVE-2026-21677 | CVE-2026-21677 CVSS 8.8 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its CIccCLUT::… |
| CVE-2026-21676 | CVE-2026-21676 CVSS 8.8 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overflow in its … |
| CVE-2026-21672 | CVE-2026-21672 CVSS 8.8 | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. |
| CVE-2026-2167 | CVE-2026-2167 CVSS 8.8 | A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The ma… |
| CVE-2026-21667 | CVE-2026-21667 CVSS 8.8 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
| CVE-2026-21666 | CVE-2026-21666 CVSS 8.8 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
| CVE-2026-21638 | CVE-2026-21638 CVSS 8.8 | A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE… |
| CVE-2026-21633 | CVE-2026-21633 CVSS 8.8 | A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerabili… |
| CVE-2026-21630 | CVE-2026-21630 CVSS 8.8 | Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. |
| CVE-2026-21625 | CVE-2026-21625 CVSS 8.8 | User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks ar… |
| CVE-2026-21537 | CVE-2026-21537 CVSS 8.8 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent netw… |
| CVE-2026-21533 | Microsoft Windows Improper Privilege Management Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges… |
| CVE-2026-21532 | CVE-2026-21532 CVSS 8.2 | Azure Function Information Disclosure Vulnerability |
| CVE-2026-21523 | CVE-2026-21523 CVSS 8.0 | Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. |
| CVE-2026-21519 | Microsoft Windows Type Confusion Vulnerability KEVCVSS 7.8Microsoft | Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. |
| CVE-2026-21518 | CVE-2026-21518 CVSS 8.8 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to… |
| CVE-2026-21514 | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability KEVCVSS 7.8Microsoft | Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privilege… |
| CVE-2026-21513 | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability KEVCVSS 8.8Microsoft | Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a … |
| CVE-2026-21510 | Microsoft Windows Shell Protection Mechanism Failure Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a net… |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability KEVCVSS 7.8Microsoft | Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow … |
| CVE-2026-21485 | CVE-2026-21485 CVSS 8.8 | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (U… |
| CVE-2026-2146 | CVE-2026-2146 CVSS 8.8 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the co… |
| CVE-2026-21451 | CVE-2026-21451 CVSS 8.4 | Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CM… |
| CVE-2026-21449 | CVE-2026-21449 CVSS 8.8 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name fr… |
| CVE-2026-2144 | CVE-2026-2144 CVSS 8.1 | The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugi… |
| CVE-2026-21411 | CVE-2026-21411 CVSS 8.8 | Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and chang… |
| CVE-2026-2141 | CVE-2026-2141 CVSS 6.35kcrm | A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gat… |
| CVE-2026-2140 | CVE-2026-2140 CVSS 8.8 | A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Suc… |
| CVE-2026-2139 | CVE-2026-2139 CVSS 8.8 | A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting… |
| CVE-2026-21389 | CVE-2026-21389 CVSS 8.8 | An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the… |
| CVE-2026-21385 | Qualcomm Multiple Chipsets Memory Corruption Vulnerability KEVCVSS 7.8Qualcomm | Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. |
| CVE-2026-2138 | CVE-2026-2138 CVSS 8.8 | A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of … |
| CVE-2026-2137 | CVE-2026-2137 CVSS 8.8 | A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the… |
| CVE-2026-21361 | CVE-2026-21361 CVSS 8.1adobe | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvuln… |
| CVE-2026-2135 | CVE-2026-2135 CVSS 8.8 | A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file /goform/formPdbUpConfig. Performing a m… |
| CVE-2026-21333 | CVE-2026-21333 CVSS 8.6adobe | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in th… |
| CVE-2026-21311 | CVE-2026-21311 CVSS 8.0adobe | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulne… |
| CVE-2026-2131 | CVE-2026-2131 CVSS 8.8 | A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument … |
| CVE-2026-21290 | CVE-2026-21290 CVSS 8.7adobe | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulne… |
| CVE-2026-21284 | CVE-2026-21284 CVSS 8.1adobe | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulne… |