89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,051–3,100 of 8,161 in High · page 62 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-0840 | CVE-2026-0840 CVSS 8.8 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNot… |
| CVE-2026-0839 | CVE-2026-0839 CVSS 8.8 | A weakness has been identified in UTT 进取 520W 1.7.7-180627. Affected is the function strcpy of the file /goform/APSecurity. Executing a manipulation of the arg… |
| CVE-2026-0838 | CVE-2026-0838 CVSS 8.8 | A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/ConfigWirelessBase. Performing a manipula… |
| CVE-2026-0837 | CVE-2026-0837 CVSS 8.8 | A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFireWall. Such manipulation of the argumen… |
| CVE-2026-0836 | CVE-2026-0836 CVSS 8.8 | A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formConfigFastDirectionW. This mani… |
| CVE-2026-0834 | CVE-2026-0834 CVSS 8.8 | Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute admini… |
| CVE-2026-0822 | CVE-2026-0822 CVSS 8.8 | A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation … |
| CVE-2026-0805 | CVE-2026-0805 CVSS 8.8 | An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tamper… |
| CVE-2026-0803 | CVE-2026-0803 CVSS 8.8 | A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of … |
| CVE-2026-0796 | CVE-2026-0796 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0795 | CVE-2026-0795 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0786 | CVE-2026-0786 CVSS 8.8 | ALGO 8180 IP Audio Alerter SCI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a… |
| CVE-2026-0785 | CVE-2026-0785 CVSS 8.8 | ALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a… |
| CVE-2026-0784 | CVE-2026-0784 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0783 | CVE-2026-0783 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0782 | CVE-2026-0782 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0781 | CVE-2026-0781 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0780 | CVE-2026-0780 CVSS 8.8 | ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… |
| CVE-2026-0779 | CVE-2026-0779 CVSS 8.8 | ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on … |
| CVE-2026-0778 | CVE-2026-0778 CVSS 8.8 | Enel X JuiceBox 40 Telnet Service Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute a… |
| CVE-2026-0774 | CVE-2026-0774 CVSS 8.8 | WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra… |
| CVE-2026-0766 | CVE-2026-0766 | Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users gra… |
| CVE-2026-0765 | CVE-2026-0765 | Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users gr… |
| CVE-2026-0762 | CVE-2026-0762 CVSS 8.1 | GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… |
| CVE-2026-0757 | CVE-2026-0757 CVSS 8.8 | MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass the sandbox… |
| CVE-2026-0733 | CVE-2026-0733 CVSS 8.8 | A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/mana… |
| CVE-2026-0726 | CVE-2026-0726 CVSS 8.1 | The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via des… |
| CVE-2026-0719 | CVE-2026-0719 CVSS 8.6 | A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When pro… |
| CVE-2026-0710 | CVE-2026-0710 CVSS 8.4 | A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. T… |
| CVE-2026-0661 | CVE-2026-0661 CVSS 8.4autodesk | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerab… |
| CVE-2026-0660 | CVE-2026-0660 CVSS 8.4autodesk | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage thi… |
| CVE-2026-0656 | CVE-2026-0656 CVSS 8.2 | The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'ch… |
| CVE-2026-0655 | CVE-2026-0655 CVSS 8.0 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authenticated adjac… |
| CVE-2026-0654 | CVE-2026-0654 CVSS 8.0 | Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authent… |
| CVE-2026-0652 | CVE-2026-0652 CVSS 8.8 | On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. A… |
| CVE-2026-0641 | CVE-2026-0641 CVSS 8.8 | A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. … |
| CVE-2026-0631 | CVE-2026-0631 CVSS 8.0tp-link | An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent… |
| CVE-2026-0630 | CVE-2026-0630 CVSS 8.0 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arb… |
| CVE-2026-0628 | CVE-2026-0628 CVSS 8.8 | Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extensi… |
| CVE-2026-0603 | CVE-2026-0603 CVSS 8.3 | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, u… |
| CVE-2026-0574 | CVE-2026-0574 CVSS 8.8 | A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse… |
| CVE-2026-0562 | CVE-2026-0562 CVSS 8.3 | A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other … |
| CVE-2026-0547 | CVE-2026-0547 CVSS 8.8 | A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profil… |
| CVE-2026-0538 | CVE-2026-0538 CVSS 8.4autodesk | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulne… |
| CVE-2026-0537 | CVE-2026-0537 CVSS 8.4autodesk | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerab… |
| CVE-2026-0535 | CVE-2026-0535 CVSS 8.1autodesk | A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in… |
| CVE-2026-0534 | CVE-2026-0534 CVSS 8.1autodesk | A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Au… |
| CVE-2026-0533 | CVE-2026-0533 CVSS 8.1autodesk | A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-sit… |
| CVE-2026-0532 | CVE-2026-0532 CVSS 8.6 | External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure thr… |
| CVE-2026-0522 | CVE-2026-0522 CVSS 8.8 | A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated attackers to read arbitrary files from the… |