89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,951–3,000 of 8,161 in High · page 60 of 164

IDTitleSummary
CVE-2026-1803CVE-2026-1803
CVSS 8.1
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes u…
CVE-2026-1779CVE-2026-1779
CVSS 8.1
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrec…
CVE-2026-1761CVE-2026-1761
CVSS 8.6
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length ca…
CVE-2026-1756CVE-2026-1756
CVSS 8.8
The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::file_and_ex…
CVE-2026-1750CVE-2026-1750
CVSS 8.8
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is…
CVE-2026-1746CVE-2026-1746
CVSS 8.8
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the componen…
CVE-2026-1730CVE-2026-1730
CVSS 8.8
The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_…
CVE-2026-1720CVE-2026-1720
CVSS 8.8
The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin …
CVE-2026-1714CVE-2026-1714
CVSS 8.6
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all…
CVE-2026-1702CVE-2026-1702
CVSS 8.8
A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/operation/user.php of t…
CVE-2026-1699CVE-2026-1699
CVSS 8.8
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and exec…
CVE-2026-1691CVE-2026-1691
CVSS 8.8
A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/Backu…
CVE-2026-1686CVE-2026-1686
CVSS 8.8
A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig in the library /lib/cste_modules/app.s…
CVE-2026-1638CVE-2026-1638
CVSS 8.8
A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. …
CVE-2026-1637CVE-2026-1637
CVSS 8.8
A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The man…
CVE-2026-1627CVE-2026-1627
CVSS 8.1
An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, all…
CVE-2026-1625CVE-2026-1625
CVSS 8.8
A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boafrm/formSmsManage of the component SMS …
CVE-2026-1624CVE-2026-1624
CVSS 8.8
A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom…
CVE-2026-1620CVE-2026-1620
CVSS 8.8
The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due to insuffic…
CVE-2026-1619CVE-2026-1619
CVSS 8.3uni-yaz
Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers. This issu…
CVE-2026-1618CVE-2026-1618
CVSS 8.8uni-yaz
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation. This issue affec…
CVE-2026-1610CVE-2026-1610
CVSS 8.1
A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing…
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
KEVCVSS 7.5Ivanti
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated atta…
CVE-2026-1597CVE-2026-1597
CVSS 8.8
A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such man…
CVE-2026-1596CVE-2026-1596
CVSS 8.8
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipul…
CVE-2026-1580CVE-2026-1580
CVSS 8.8
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration int…
CVE-2026-1566CVE-2026-1566
CVSS 8.8
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versio…
CVE-2026-1565CVE-2026-1565
CVSS 8.8
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file up…
CVE-2026-1560CVE-2026-1560
CVSS 8.8
The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple fun…
CVE-2026-1551CVE-2026-1551
CVSS 8.8
A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/course/controller.php. Executin…
CVE-2026-1550CVE-2026-1550
CVSS 8.8
A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospita…
CVE-2026-1548CVE-2026-1548
CVSS 8.8
A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. This manipulation …
CVE-2026-1544CVE-2026-1544
CVSS 8.8
A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of t…
CVE-2026-1531CVE-2026-1531
CVSS 8.1
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certif…
CVE-2026-1530CVE-2026-1530
CVSS 8.1
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validati…
CVE-2026-1529CVE-2026-1529
CVSS 8.1
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token…
CVE-2026-1499CVE-2026-1499
CVSS 8.8
The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This i…
CVE-2026-1486CVE-2026-1486
CVSS 8.8
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enab…
CVE-2026-1463CVE-2026-1463
CVSS 8.8
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi…
CVE-2026-1462CVE-2026-1462
CVSS 7.8keras
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserial…
CVE-2026-1457CVE-2026-1457
CVSS 8.8
An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corruption leading to remote code execution.…
CVE-2026-1428CVE-2026-1428
CVSS 8.8
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS c…
CVE-2026-1427CVE-2026-1427
CVSS 8.8
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS c…
CVE-2026-1426CVE-2026-1426
CVSS 8.8
The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization …
CVE-2026-1375CVE-2026-1375
CVSS 8.1
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and …
CVE-2026-1367CVE-2026-1367
CVSS 8.3
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.
CVE-2026-1329CVE-2026-1329
CVSS 8.8
A flaw has been found in Tenda AX1803 1.0.0.1. The affected element is the function fromGetWifiGuestBasic of the file /goform/WifiGuestSet. Executing a manipul…
CVE-2026-1328CVE-2026-1328
CVSS 8.8
A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. Impacted is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component…
CVE-2026-1327CVE-2026-1327
CVSS 8.8
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cst…
CVE-2026-1326CVE-2026-1326
CVSS 8.8
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.