89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,801–2,850 of 8,161 in High · page 57 of 164

IDTitleSummary
CVE-2026-21721CVE-2026-21721
CVSS 8.1grafana
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permi…
CVE-2026-21697CVE-2026-21697
CVSS 8.1
axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaul…
CVE-2026-21694CVE-2026-21694
CVSS 8.1
Titra is open source project time tracking software. Versions 0.99.49 and below have Improper Access Control, allowing users to view and edit other users' time…
CVE-2026-21693CVE-2026-21693
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-21692CVE-2026-21692
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-2169CVE-2026-2169
CVSS 8.8
A vulnerability has been found in D-Link DWR-M921 1.1.50. This impacts an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of …
CVE-2026-21688CVE-2026-21688
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-21683CVE-2026-21683
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-21682CVE-2026-21682
CVSS 8.8
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color manage…
CVE-2026-2168CVE-2026-2168
CVSS 8.8
A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the a…
CVE-2026-21677CVE-2026-21677
CVSS 8.8
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its CIccCLUT::…
CVE-2026-21676CVE-2026-21676
CVSS 8.8
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overflow in its …
CVE-2026-21672CVE-2026-21672
CVSS 8.8
A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
CVE-2026-2167CVE-2026-2167
CVSS 8.8
A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The ma…
CVE-2026-21667CVE-2026-21667
CVSS 8.8
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21666CVE-2026-21666
CVSS 8.8
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21638CVE-2026-21638
CVSS 8.8
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE…
CVE-2026-21633CVE-2026-21633
CVSS 8.8
A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by exploiting a discovery protocol vulnerabili…
CVE-2026-21630CVE-2026-21630
CVSS 8.8
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
CVE-2026-21625CVE-2026-21625
CVSS 8.8
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks ar…
CVE-2026-21537CVE-2026-21537
CVSS 8.8
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent netw…
CVE-2026-21533Microsoft Windows Improper Privilege Management Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges…
CVE-2026-21532CVE-2026-21532
CVSS 8.2
Azure Function Information Disclosure Vulnerability
CVE-2026-21523CVE-2026-21523
CVSS 8.0
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CVE-2026-21519Microsoft Windows Type Confusion Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21518CVE-2026-21518
CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to…
CVE-2026-21514Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privilege…
CVE-2026-21513Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
KEVCVSS 8.8Microsoft
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a …
CVE-2026-21510Microsoft Windows Shell Protection Mechanism Failure Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a net…
CVE-2026-21509Microsoft Office Security Feature Bypass Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow …
CVE-2026-21485CVE-2026-21485
CVSS 8.8
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (U…
CVE-2026-2146CVE-2026-2146
CVSS 8.8
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the co…
CVE-2026-21451CVE-2026-21451
CVSS 8.4
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CM…
CVE-2026-21449CVE-2026-21449
CVSS 8.8
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name fr…
CVE-2026-2144CVE-2026-2144
CVSS 8.1
The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugi…
CVE-2026-21411CVE-2026-21411
CVSS 8.8
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and chang…
CVE-2026-2141CVE-2026-2141
CVSS 6.35kcrm
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gat…
CVE-2026-2140CVE-2026-2140
CVSS 8.8
A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Suc…
CVE-2026-2139CVE-2026-2139
CVSS 8.8
A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting…
CVE-2026-21389CVE-2026-21389
CVSS 8.8
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the…
CVE-2026-21385Qualcomm Multiple Chipsets Memory Corruption Vulnerability
KEVCVSS 7.8Qualcomm
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
CVE-2026-2138CVE-2026-2138
CVSS 8.8
A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of …
CVE-2026-2137CVE-2026-2137
CVSS 8.8
A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the…
CVE-2026-21361CVE-2026-21361
CVSS 8.1adobe
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvuln…
CVE-2026-2135CVE-2026-2135
CVSS 8.8
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file /goform/formPdbUpConfig. Performing a m…
CVE-2026-21333CVE-2026-21333
CVSS 8.6adobe
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in th…
CVE-2026-21311CVE-2026-21311
CVSS 8.0adobe
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulne…
CVE-2026-2131CVE-2026-2131
CVSS 8.8
A vulnerability was identified in XixianLiang HarmonyOS-mcp-server 0.1.0. This vulnerability affects the function input_text. The manipulation of the argument …
CVE-2026-21290CVE-2026-21290
CVSS 8.7adobe
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulne…
CVE-2026-21284CVE-2026-21284
CVSS 8.1adobe
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulne…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.