89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,051–3,100 of 8,161 in High · page 62 of 164

IDTitleSummary
CVE-2026-0840CVE-2026-0840
CVSS 8.8
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNot…
CVE-2026-0839CVE-2026-0839
CVSS 8.8
A weakness has been identified in UTT 进取 520W 1.7.7-180627. Affected is the function strcpy of the file /goform/APSecurity. Executing a manipulation of the arg…
CVE-2026-0838CVE-2026-0838
CVSS 8.8
A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/ConfigWirelessBase. Performing a manipula…
CVE-2026-0837CVE-2026-0837
CVSS 8.8
A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFireWall. Such manipulation of the argumen…
CVE-2026-0836CVE-2026-0836
CVSS 8.8
A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formConfigFastDirectionW. This mani…
CVE-2026-0834CVE-2026-0834
CVSS 8.8
Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute admini…
CVE-2026-0822CVE-2026-0822
CVSS 8.8
A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation …
CVE-2026-0805CVE-2026-0805
CVSS 8.8
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tamper…
CVE-2026-0803CVE-2026-0803
CVSS 8.8
A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of …
CVE-2026-0796CVE-2026-0796
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0795CVE-2026-0795
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0786CVE-2026-0786
CVSS 8.8
ALGO 8180 IP Audio Alerter SCI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…
CVE-2026-0785CVE-2026-0785
CVSS 8.8
ALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…
CVE-2026-0784CVE-2026-0784
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0783CVE-2026-0783
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0782CVE-2026-0782
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0781CVE-2026-0781
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0780CVE-2026-0780
CVSS 8.8
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-0779CVE-2026-0779
CVSS 8.8
ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …
CVE-2026-0778CVE-2026-0778
CVSS 8.8
Enel X JuiceBox 40 Telnet Service Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute a…
CVE-2026-0774CVE-2026-0774
CVSS 8.8
WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra…
CVE-2026-0766CVE-2026-0766Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users gra…
CVE-2026-0765CVE-2026-0765Rejected reason: Open WebU's investigation further investigation  showed that this is intended functionality of the Plugins extension system, in which users gr…
CVE-2026-0762CVE-2026-0762
CVSS 8.1
GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…
CVE-2026-0757CVE-2026-0757
CVSS 8.8
MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass the sandbox…
CVE-2026-0733CVE-2026-0733
CVSS 8.8
A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/mana…
CVE-2026-0726CVE-2026-0726
CVSS 8.1
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via des…
CVE-2026-0719CVE-2026-0719
CVSS 8.6
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When pro…
CVE-2026-0710CVE-2026-0710
CVSS 8.4
A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. T…
CVE-2026-0661CVE-2026-0661
CVSS 8.4autodesk
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerab…
CVE-2026-0660CVE-2026-0660
CVSS 8.4autodesk
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage thi…
CVE-2026-0656CVE-2026-0656
CVSS 8.2
The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'ch…
CVE-2026-0655CVE-2026-0655
CVSS 8.0
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authenticated adjac…
CVE-2026-0654CVE-2026-0654
CVSS 8.0
Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authent…
CVE-2026-0652CVE-2026-0652
CVSS 8.8
On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. A…
CVE-2026-0641CVE-2026-0641
CVSS 8.8
A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. …
CVE-2026-0631CVE-2026-0631
CVSS 8.0tp-link
An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent…
CVE-2026-0630CVE-2026-0630
CVSS 8.0
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arb…
CVE-2026-0628CVE-2026-0628
CVSS 8.8
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extensi…
CVE-2026-0603CVE-2026-0603
CVSS 8.3
A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, u…
CVE-2026-0574CVE-2026-0574
CVSS 8.8
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse…
CVE-2026-0562CVE-2026-0562
CVSS 8.3
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other …
CVE-2026-0547CVE-2026-0547
CVSS 8.8
A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profil…
CVE-2026-0538CVE-2026-0538
CVSS 8.4autodesk
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulne…
CVE-2026-0537CVE-2026-0537
CVSS 8.4autodesk
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerab…
CVE-2026-0535CVE-2026-0535
CVSS 8.1autodesk
A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in…
CVE-2026-0534CVE-2026-0534
CVSS 8.1autodesk
A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Au…
CVE-2026-0533CVE-2026-0533
CVSS 8.1autodesk
A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-sit…
CVE-2026-0532CVE-2026-0532
CVSS 8.6
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure thr…
CVE-2026-0522CVE-2026-0522
CVSS 8.8
A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated attackers to read arbitrary files from the…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.