89,492 indexed
CVECVE vulnerabilities
89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,101–3,150 of 8,161 in High · page 63 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2026-0511 | CVE-2026-0511 CVSS 8.1 | SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privile… |
| CVE-2026-0508 | CVE-2026-0508 CVSS 8.1 | The SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker with high privileges to insert malicious URL within the application. Up… |
| CVE-2026-0507 | CVE-2026-0507 CVSS 8.4 | Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access … |
| CVE-2026-0506 | CVE-2026-0506 CVSS 8.1 | Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to exec… |
| CVE-2026-0500 | CVE-2026-0500 CVSS 8.8 | Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malici… |
| CVE-2026-0492 | CVE-2026-0492 CVSS 8.8 | SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining a… |
| CVE-2026-0408 | CVE-2026-0408 CVSS 8.0 | A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents o… |
| CVE-2026-0407 | CVE-2026-0407 CVSS 8.0 | An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethern… |
| CVE-2026-0406 | CVE-2026-0406 CVSS 8.0 | An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections. |
| CVE-2026-0404 | CVE-2026-0404 CVSS 8.0 | An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on … |
| CVE-2026-0403 | CVE-2026-0403 CVSS 8.0 | An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections. |
| CVE-2026-0204 | CVE-2026-0204 CVSS 8.0 | A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. |
| CVE-2026-0123 | CVE-2026-0123 CVSS 8.4 | In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala… |
| CVE-2026-0122 | CVE-2026-0122 CVSS 8.4 | In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution pri… |
| CVE-2026-0118 | CVE-2026-0118 CVSS 8.4 | In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege with no additional exec… |
| CVE-2026-0117 | CVE-2026-0117 CVSS 8.4 | In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege … |
| CVE-2026-0107 | CVE-2026-0107 CVSS 8.4 | In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of pr… |
| CVE-2026-0073 | CVE-2026-0073 CVSS 8.8 | In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remo… |
| CVE-2026-0047 | CVE-2026-0047 CVSS 8.4 | In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This co… |
| CVE-2026-0038 | CVE-2026-0038 CVSS 8.4 | In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation… |
| CVE-2026-0037 | CVE-2026-0037 CVSS 8.4 | In multiple functions of ffa.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with n… |
| CVE-2026-0035 | CVE-2026-0035 CVSS 8.4 | In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. Th… |
| CVE-2026-0034 | CVE-2026-0034 CVSS 8.4 | In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could lead to lo… |
| CVE-2026-0031 | CVE-2026-0031 CVSS 8.4 | In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege wi… |
| CVE-2026-0030 | CVE-2026-0030 CVSS 8.4 | In __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalatio… |
| CVE-2026-0029 | CVE-2026-0029 CVSS 8.4 | In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no a… |
| CVE-2026-0028 | CVE-2026-0028 CVSS 8.4 | In __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privile… |
| CVE-2026-0025 | CVE-2026-0025 CVSS 8.4 | In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation o… |
| CVE-2026-0021 | CVE-2026-0021 CVSS 8.4 | In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to loca… |
| CVE-2026-0020 | CVE-2026-0020 CVSS 8.4 | In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. Th… |
| CVE-2026-0013 | CVE-2026-0013 CVSS 8.4google | In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local esca… |
| CVE-2026-0011 | CVE-2026-0011 CVSS 8.4google | In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead t… |
| CVE-2026-0010 | CVE-2026-0010 CVSS 8.4google | In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privileg… |
| CVE-2026-0008 | CVE-2026-0008 CVSS 8.4google | In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege wit… |
| CVE-2026-0007 | CVE-2026-0007 CVSS 8.6 | In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to … |
| CVE-2025-9993 | CVE-2025-9993 CVSS 8.1 | The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. Th… |
| CVE-2025-9991 | CVE-2025-9991 CVSS 8.1 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' pa… |
| CVE-2025-9990 | CVE-2025-9990 CVSS 8.1 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type … |
| CVE-2025-9986 | CVE-2025-9986 CVSS 8.2 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information Systems Ltd. Co. DIGIKENT allows Excavat… |
| CVE-2025-9974 | CVE-2025-9974 CVSS 8.0 | The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level comma… |
| CVE-2025-9942 | CVE-2025-9942 CVSS 8.8 | A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulatio… |
| CVE-2025-9941 | CVE-2025-9941 CVSS 8.8 | A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the… |
| CVE-2025-9938 | CVE-2025-9938 CVSS 8.8 | A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of th… |
| CVE-2025-9900 | CVE-2025-9900 CVSS 8.8 | A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file. B… |
| CVE-2025-9890 | CVE-2025-9890 CVSS 8.8 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrec… |
| CVE-2025-9872 | CVE-2025-9872 CVSS 8.8ivanti | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote cod… |
| CVE-2025-9866 | CVE-2025-9866 CVSS 8.8google | Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HT… |
| CVE-2025-9844 | CVE-2025-9844 CVSS 8.8 | Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: bef… |
| CVE-2025-9841 | CVE-2025-9841 CVSS 8.8 | A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. … |
| CVE-2025-9813 | CVE-2025-9813 CVSS 8.8tenda | A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of th… |