89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,901–2,950 of 8,161 in High · page 59 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-2067 | CVE-2026-2067 CVSS 8.8 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig.… |
| CVE-2026-20667 | CVE-2026-20667 CVSS 8.8 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3,… |
| CVE-2026-2066 | CVE-2026-2066 CVSS 8.8 | A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpGroupConfig. Executing a manipulation of… |
| CVE-2026-2065 | CVE-2026-2065 CVSS 8.8 | A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low… |
| CVE-2026-20631 | CVE-2026-20631 CVSS 8.8 | A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges. |
| CVE-2026-20616 | CVE-2026-20616 CVSS 8.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe… |
| CVE-2026-2052 | CVE-2026-2052 CVSS 8.8 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all … |
| CVE-2026-20433 | CVE-2026-20433 CVSS 8.8 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a … |
| CVE-2026-20432 | CVE-2026-20432 CVSS 8.0mediatek | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a … |
| CVE-2026-20430 | CVE-2026-20430 CVSS 8.8 | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege … |
| CVE-2026-2043 | CVE-2026-2043 CVSS 8.8 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a… |
| CVE-2026-2042 | CVE-2026-2042 CVSS 8.8 | Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff… |
| CVE-2026-2041 | CVE-2026-2041 CVSS 8.8 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… |
| CVE-2026-20408 | CVE-2026-20408 CVSS 8.8 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no a… |
| CVE-2026-2037 | CVE-2026-2037 CVSS 8.8 | GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… |
| CVE-2026-2036 | CVE-2026-2036 CVSS 8.8 | GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … |
| CVE-2026-2033 | CVE-2026-2033 CVSS 7.3 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… |
| CVE-2026-20224 | CVE-2026-20224 CVSS 8.6cisco | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary file… |
| CVE-2026-20155 | CVE-2026-20155 CVSS 8.0cisco | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with l… |
| CVE-2026-2015 | CVE-2026-2015 CVSS 6.3portabilis | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Fin… |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability KEVCVSS 7.5Cisco | Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view se… |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability KEVCVSS 7.5Cisco | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user … |
| CVE-2026-20103 | CVE-2026-20103 CVSS 8.6cisco | A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defen… |
| CVE-2026-20101 | CVE-2026-20101 CVSS 8.6cisco | A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remo… |
| CVE-2026-20098 | CVE-2026-20098 CVSS 8.8 | A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, exec… |
| CVE-2026-20094 | CVE-2026-20094 CVSS 8.8cisco | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command i… |
| CVE-2026-20086 | CVE-2026-20086 CVSS 8.6 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the C… |
| CVE-2026-20084 | CVE-2026-20084 CVSS 8.6cisco | A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded be… |
| CVE-2026-20082 | CVE-2026-20082 CVSS 8.6 | A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthent… |
| CVE-2026-2008 | CVE-2026-2008 CVSS 8.8 | A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability affects the function eqn_chart of the f… |
| CVE-2026-2007 | CVE-2026-2007 CVSS 8.2postgresql | Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over… |
| CVE-2026-2006 | CVE-2026-2006 CVSS 8.8postgresql | Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.… |
| CVE-2026-2005 | CVE-2026-2005 CVSS 8.8postgresql | Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions… |
| CVE-2026-20046 | CVE-2026-20046 CVSS 8.8cisco | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges… |
| CVE-2026-20040 | CVE-2026-20040 CVSS 8.8cisco | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operat… |
| CVE-2026-2004 | CVE-2026-2004 CVSS 8.8postgresql | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the o… |
| CVE-2026-20039 | CVE-2026-20039 CVSS 8.6cisco | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Softwa… |
| CVE-2026-20034 | CVE-2026-20034 CVSS 8.8cisco | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an a… |
| CVE-2026-20012 | CVE-2026-20012 CVSS 8.6cisco | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Ap… |
| CVE-2026-2001 | CVE-2026-2001 CVSS 8.8 | The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin… |
| CVE-2026-20002 | CVE-2026-20002 CVSS 8.1cisco | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attac… |
| CVE-2026-1993 | CVE-2026-1993 CVSS 8.8 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due … |
| CVE-2026-1992 | CVE-2026-1992 CVSS 8.8 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is d… |
| CVE-2026-1961 | CVE-2026-1961 CVSS 8.0 | A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability … |
| CVE-2026-1929 | CVE-2026-1929 CVSS 8.8 | The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.37. This is due to the use of `call… |
| CVE-2026-1862 | CVE-2026-1862 CVSS 8.8 | Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
| CVE-2026-1861 | CVE-2026-1861 CVSS 8.8 | Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |
| CVE-2026-1819 | CVE-2026-1819 CVSS 8.8 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort a… |
| CVE-2026-1811 | CVE-2026-1811 CVSS 8.8 | A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/prop/Backu… |
| CVE-2026-1810 | CVE-2026-1810 CVSS 8.8 | A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org/b3log/sol… |