89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,001–3,050 of 8,161 in High · page 61 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-1323 | CVE-2026-1323 CVSS 8.8 | The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted se… |
| CVE-2026-1322 | CVE-2026-1322 CVSS 8.1 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have a… |
| CVE-2026-1321 | CVE-2026-1321 CVSS 8.1 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due t… |
| CVE-2026-1313 | CVE-2026-1313 CVSS 8.3 | The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plu… |
| CVE-2026-1311 | CVE-2026-1311 CVSS 8.8 | The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. Th… |
| CVE-2026-1203 | CVE-2026-1203 CVSS 8.1 | A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php … |
| CVE-2026-1193 | CVE-2026-1193 CVSS 8.8 | A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface… |
| CVE-2026-1185 | CVE-2026-1185 CVSS 8.8 | A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This… |
| CVE-2026-1169 | CVE-2026-1169 CVSS 8.8 | A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cross-site r… |
| CVE-2026-1158 | CVE-2026-1158 CVSS 8.8 | A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.… |
| CVE-2026-1157 | CVE-2026-1157 CVSS 8.8 | A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipul… |
| CVE-2026-1156 | CVE-2026-1156 CVSS 8.8 | A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi… |
| CVE-2026-1155 | CVE-2026-1155 CVSS 8.8 | A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cste… |
| CVE-2026-1150 | CVE-2026-1150 CVSS 8.8 | A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the … |
| CVE-2026-1149 | CVE-2026-1149 CVSS 8.8 | A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the… |
| CVE-2026-1145 | CVE-2026-1145 CVSS 8.8 | A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. T… |
| CVE-2026-1144 | CVE-2026-1144 CVSS 8.8 | A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. Th… |
| CVE-2026-1143 | CVE-2026-1143 CVSS 8.8 | A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Execut… |
| CVE-2026-1141 | CVE-2026-1141 CVSS 8.8 | A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component… |
| CVE-2026-1140 | CVE-2026-1140 CVSS 8.8 | A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigExceptAli. The manipulation results in … |
| CVE-2026-1139 | CVE-2026-1139 CVSS 8.8 | A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulatio… |
| CVE-2026-1138 | CVE-2026-1138 CVSS 8.8 | A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. Executing a manipulation can lead to bu… |
| CVE-2026-1137 | CVE-2026-1137 CVSS 8.8 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing… |
| CVE-2026-1117 | CVE-2026-1117 CVSS 8.2 | A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. Th… |
| CVE-2026-1112 | CVE-2026-1112 CVSS 8.1 | A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/contro… |
| CVE-2026-1104 | CVE-2026-1104 CVSS 8.8 | The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capabil… |
| CVE-2026-1066 | CVE-2026-1066 CVSS 8.8 | A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Co… |
| CVE-2026-0980 | CVE-2026-0980 CVSS 8.8 | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creat… |
| CVE-2026-0974 | CVE-2026-0974 CVSS 8.8 | The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due… |
| CVE-2026-0969 | CVE-2026-0969 CVSS 8.8 | The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This v… |
| CVE-2026-0966 | CVE-2026-0966 CVSS 8.2libssh | A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited rem… |
| CVE-2026-0963 | CVE-2026-0963 CVSS 8.8 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform fil… |
| CVE-2026-0945 | CVE-2026-0945 CVSS 8.8 | Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before… |
| CVE-2026-0912 | CVE-2026-0912 CVSS 8.8 | The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability che… |
| CVE-2026-0910 | CVE-2026-0910 CVSS 8.8 | The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input… |
| CVE-2026-0908 | CVE-2026-0908 CVSS 8.8 | Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
| CVE-2026-0902 | CVE-2026-0902 CVSS 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML… |
| CVE-2026-0900 | CVE-2026-0900 CVSS 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTM… |
| CVE-2026-0899 | CVE-2026-0899 CVSS 8.8 | Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML… |
| CVE-2026-0891 | CVE-2026-0891 CVSS 8.1mozilla | Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruptio… |
| CVE-2026-0882 | CVE-2026-0882 CVSS 8.8mozilla | Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
| CVE-2026-0880 | CVE-2026-0880 CVSS 8.8mozilla | Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbi… |
| CVE-2026-0878 | CVE-2026-0878 CVSS 8.0mozilla | Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thu… |
| CVE-2026-0877 | CVE-2026-0877 CVSS 8.1mozilla | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thun… |
| CVE-2026-0869 | CVE-2026-0869 CVSS 8.8 | Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming conf… |
| CVE-2026-0861 | CVE-2026-0861 CVSS 8.4 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may resul… |
| CVE-2026-0855 | CVE-2026-0855 CVSS 8.8 | Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS comm… |
| CVE-2026-0854 | CVE-2026-0854 CVSS 8.8 | Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS comman… |
| CVE-2026-0844 | CVE-2026-0844 CVSS 8.8 | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction o… |
| CVE-2026-0841 | CVE-2026-0841 CVSS 8.8 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formPictureUrl. The manipulation of… |