89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,951–3,000 of 8,161 in High · page 60 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-1803 | CVE-2026-1803 CVSS 8.1 | A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes u… |
| CVE-2026-1779 | CVE-2026-1779 CVSS 8.1 | The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrec… |
| CVE-2026-1761 | CVE-2026-1761 CVSS 8.6 | A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length ca… |
| CVE-2026-1756 | CVE-2026-1756 CVSS 8.8 | The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::file_and_ex… |
| CVE-2026-1750 | CVE-2026-1750 CVSS 8.8 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is… |
| CVE-2026-1746 | CVE-2026-1746 CVSS 8.8 | A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the componen… |
| CVE-2026-1730 | CVE-2026-1730 CVSS 8.8 | The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_… |
| CVE-2026-1720 | CVE-2026-1720 CVSS 8.8 | The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin … |
| CVE-2026-1714 | CVE-2026-1714 CVSS 8.6 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all… |
| CVE-2026-1702 | CVE-2026-1702 CVSS 8.8 | A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/user.php of t… |
| CVE-2026-1699 | CVE-2026-1699 CVSS 8.8 | In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and exec… |
| CVE-2026-1691 | CVE-2026-1691 CVSS 8.8 | A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/Backu… |
| CVE-2026-1686 | CVE-2026-1686 CVSS 8.8 | A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.s… |
| CVE-2026-1638 | CVE-2026-1638 CVSS 8.8 | A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. … |
| CVE-2026-1637 | CVE-2026-1637 CVSS 8.8 | A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The man… |
| CVE-2026-1627 | CVE-2026-1627 CVSS 8.1 | An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, all… |
| CVE-2026-1625 | CVE-2026-1625 CVSS 8.8 | A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boafrm/formSmsManage of the component SMS … |
| CVE-2026-1624 | CVE-2026-1624 CVSS 8.8 | A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom… |
| CVE-2026-1620 | CVE-2026-1620 CVSS 8.8 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insuffic… |
| CVE-2026-1619 | CVE-2026-1619 CVSS 8.3uni-yaz | Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers. This issu… |
| CVE-2026-1618 | CVE-2026-1618 CVSS 8.8uni-yaz | Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation. This issue affec… |
| CVE-2026-1610 | CVE-2026-1610 CVSS 8.1 | A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing… |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability KEVCVSS 7.5Ivanti | Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated atta… |
| CVE-2026-1597 | CVE-2026-1597 CVSS 8.8 | A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such man… |
| CVE-2026-1596 | CVE-2026-1596 CVSS 8.8 | A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipul… |
| CVE-2026-1580 | CVE-2026-1580 CVSS 8.8 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration int… |
| CVE-2026-1566 | CVE-2026-1566 CVSS 8.8 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versio… |
| CVE-2026-1565 | CVE-2026-1565 CVSS 8.8 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file up… |
| CVE-2026-1560 | CVE-2026-1560 CVSS 8.8 | The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple fun… |
| CVE-2026-1551 | CVE-2026-1551 CVSS 8.8 | A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/course/controller.php. Executin… |
| CVE-2026-1550 | CVE-2026-1550 CVSS 8.8 | A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospita… |
| CVE-2026-1548 | CVE-2026-1548 CVSS 8.8 | A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation … |
| CVE-2026-1544 | CVE-2026-1544 CVSS 8.8 | A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of t… |
| CVE-2026-1531 | CVE-2026-1531 CVSS 8.1 | A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certif… |
| CVE-2026-1530 | CVE-2026-1530 CVSS 8.1 | A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validati… |
| CVE-2026-1529 | CVE-2026-1529 CVSS 8.1 | A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token… |
| CVE-2026-1499 | CVE-2026-1499 CVSS 8.8 | The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This i… |
| CVE-2026-1486 | CVE-2026-1486 CVSS 8.8 | A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enab… |
| CVE-2026-1463 | CVE-2026-1463 CVSS 8.8 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… |
| CVE-2026-1462 | CVE-2026-1462 CVSS 7.8keras | A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserial… |
| CVE-2026-1457 | CVE-2026-1457 CVSS 8.8 | An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corruption leading to remote code execution.… |
| CVE-2026-1428 | CVE-2026-1428 CVSS 8.8 | Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS c… |
| CVE-2026-1427 | CVE-2026-1427 CVSS 8.8 | Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS c… |
| CVE-2026-1426 | CVE-2026-1426 CVSS 8.8 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization … |
| CVE-2026-1375 | CVE-2026-1375 CVSS 8.1 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and … |
| CVE-2026-1367 | CVE-2026-1367 CVSS 8.3 | Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option. |
| CVE-2026-1329 | CVE-2026-1329 CVSS 8.8 | A flaw has been found in Tenda AX1803 1.0.0.1. The affected element is the function fromGetWifiGuestBasic of the file /goform/WifiGuestSet. Executing a manipul… |
| CVE-2026-1328 | CVE-2026-1328 CVSS 8.8 | A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. Impacted is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component… |
| CVE-2026-1327 | CVE-2026-1327 CVSS 8.8 | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cst… |
| CVE-2026-1326 | CVE-2026-1326 CVSS 8.8 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of… |