89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,001–3,050 of 8,161 in High · page 61 of 164

IDTitleSummary
CVE-2026-1323CVE-2026-1323
CVSS 8.8
The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted se…
CVE-2026-1322CVE-2026-1322
CVSS 8.1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have a…
CVE-2026-1321CVE-2026-1321
CVSS 8.1
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due t…
CVE-2026-1313CVE-2026-1313
CVSS 8.3
The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plu…
CVE-2026-1311CVE-2026-1311
CVSS 8.8
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. Th…
CVE-2026-1203CVE-2026-1203
CVSS 8.1
A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php …
CVE-2026-1193CVE-2026-1193
CVSS 8.8
A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface…
CVE-2026-1185CVE-2026-1185
CVSS 8.8
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This…
CVE-2026-1169CVE-2026-1169
CVSS 8.8
A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cross-site r…
CVE-2026-1158CVE-2026-1158
CVSS 8.8
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.…
CVE-2026-1157CVE-2026-1157
CVSS 8.8
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipul…
CVE-2026-1156CVE-2026-1156
CVSS 8.8
A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi…
CVE-2026-1155CVE-2026-1155
CVSS 8.8
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cste…
CVE-2026-1150CVE-2026-1150
CVSS 8.8
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the …
CVE-2026-1149CVE-2026-1149
CVSS 8.8
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the…
CVE-2026-1145CVE-2026-1145
CVSS 8.8
A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. T…
CVE-2026-1144CVE-2026-1144
CVSS 8.8
A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. Th…
CVE-2026-1143CVE-2026-1143
CVSS 8.8
A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Execut…
CVE-2026-1141CVE-2026-1141
CVSS 8.8
A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component…
CVE-2026-1140CVE-2026-1140
CVSS 8.8
A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigExceptAli. The manipulation results in …
CVE-2026-1139CVE-2026-1139
CVSS 8.8
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulatio…
CVE-2026-1138CVE-2026-1138
CVSS 8.8
A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. Executing a manipulation can lead to bu…
CVE-2026-1137CVE-2026-1137
CVSS 8.8
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing…
CVE-2026-1117CVE-2026-1117
CVSS 8.2
A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. Th…
CVE-2026-1112CVE-2026-1112
CVSS 8.1
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/contro…
CVE-2026-1104CVE-2026-1104
CVSS 8.8
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capabil…
CVE-2026-1066CVE-2026-1066
CVSS 8.8
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Co…
CVE-2026-0980CVE-2026-0980
CVSS 8.8
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creat…
CVE-2026-0974CVE-2026-0974
CVSS 8.8
The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due…
CVE-2026-0969CVE-2026-0969
CVSS 8.8
The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This v…
CVE-2026-0966CVE-2026-0966
CVSS 8.2libssh
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited rem…
CVE-2026-0963CVE-2026-0963
CVSS 8.8
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform fil…
CVE-2026-0945CVE-2026-0945
CVSS 8.8
Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before…
CVE-2026-0912CVE-2026-0912
CVSS 8.8
The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability che…
CVE-2026-0910CVE-2026-0910
CVSS 8.8
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input…
CVE-2026-0908CVE-2026-0908
CVSS 8.8
Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…
CVE-2026-0902CVE-2026-0902
CVSS 8.8
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML…
CVE-2026-0900CVE-2026-0900
CVSS 8.8
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTM…
CVE-2026-0899CVE-2026-0899
CVSS 8.8
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML…
CVE-2026-0891CVE-2026-0891
CVSS 8.1mozilla
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruptio…
CVE-2026-0882CVE-2026-0882
CVSS 8.8mozilla
Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVE-2026-0880CVE-2026-0880
CVSS 8.8mozilla
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbi…
CVE-2026-0878CVE-2026-0878
CVSS 8.0mozilla
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thu…
CVE-2026-0877CVE-2026-0877
CVSS 8.1mozilla
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thun…
CVE-2026-0869CVE-2026-0869
CVSS 8.8
Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming conf…
CVE-2026-0861CVE-2026-0861
CVSS 8.4
Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may resul…
CVE-2026-0855CVE-2026-0855
CVSS 8.8
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS comm…
CVE-2026-0854CVE-2026-0854
CVSS 8.8
Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS comman…
CVE-2026-0844CVE-2026-0844
CVSS 8.8
The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction o…
CVE-2026-0841CVE-2026-0841
CVSS 8.8
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formPictureUrl. The manipulation of…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.