87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 651–700 of 87,929 · page 14 of 1759

IDTitleSummary
CVE-2026-97898CVE-2026-97898Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplie…
CVE-2026-97897CVE-2026-97897
CVSS 3.5
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component Ti…
CVE-2026-97896CVE-2026-97896
CVSS 3.5
A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/…
CVE-2026-97895CVE-2026-97895
CVSS 6.3
A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/…
CVE-2026-97886CVE-2026-97886
CVSS 6.3
A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an …
CVE-2026-97885CVE-2026-97885
CVSS 7.3
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file up…
CVE-2026-97884CVE-2026-97884
CVSS 6.3
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the…
CVE-2026-97883CVE-2026-97883
CVSS 7.3
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown f…
CVE-2026-97882CVE-2026-97882
CVSS 7.3
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown fu…
CVE-2026-97879CVE-2026-97879
CVSS 5.3
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the …
CVE-2026-97878CVE-2026-97878
CVSS 7.3
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid …
CVE-2026-97877CVE-2026-97877
CVSS 7.3
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml…
CVE-2026-97876CVE-2026-97876
CVSS 6.4
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while …
CVE-2026-97875CVE-2026-97875
CVSS 8.1
Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all…
CVE-2026-97873CVE-2026-97873In Bouncy Castle for Java before 1.86, the raw JCA provider's legacy PBES1 (PKCS#5 scheme 1) and PKCS#12 PBE families ran their password-based key derivation w…
CVE-2026-97871CVE-2026-97871
CVSS 7.3
A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.…
CVE-2026-9787CVE-2026-9787
CVSS 8.8quest
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code…
CVE-2026-97869CVE-2026-97869
CVSS 4.1
A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson o…
CVE-2026-97868CVE-2026-97868
CVSS 3.5
A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/no…
CVE-2026-97866CVE-2026-97866
CVSS 5.6
A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Aut…
CVE-2026-97865CVE-2026-97865
CVSS 7.3
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Rem…
CVE-2026-97864CVE-2026-97864
CVSS 5.3
A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAja…
CVE-2026-97863CVE-2026-97863The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager A…
CVE-2026-9786CVE-2026-9786
CVSS 8.8quest
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …
CVE-2026-9785CVE-2026-9785
CVSS 8.8quest
Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-97846CVE-2026-97846
CVSS 6.8
Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding…
CVE-2026-9784CVE-2026-9784
CVSS 8.8quest
Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-9783CVE-2026-9783
CVSS 8.8quest
Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary cod…
CVE-2026-9782CVE-2026-9782
CVSS 8.8quest
Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o…
CVE-2026-97818CVE-2026-97818
CVSS 8.6
phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
CVE-2026-9781CVE-2026-9781
CVSS 8.8quest
Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …
CVE-2026-9780CVE-2026-9780
CVSS 8.8quest
Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication …
CVE-2026-9779CVE-2026-9779
CVSS 7.2aten
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attac…
CVE-2026-9778CVE-2026-9778
CVSS 7.2aten
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…
CVE-2026-9777CVE-2026-9777
CVSS 7.2aten
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…
CVE-2026-97764CVE-2026-97764
CVSS 3.7
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the h…
CVE-2026-9776CVE-2026-9776
CVSS 7.5aten
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sen…
CVE-2026-9775CVE-2026-9775
CVSS 6.5aten
ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affect…
CVE-2026-9774CVE-2026-9774
CVSS 6.5aten
ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on af…
CVE-2026-97737CVE-2026-97737
CVSS 7.4
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
CVE-2026-97736CVE-2026-97736
CVSS 5.4
tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.
CVE-2026-97735CVE-2026-97735
CVSS 8.0
ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrar…
CVE-2026-97732CVE-2026-97732
CVSS 5.1
IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate st…
CVE-2026-97731CVE-2026-97731
CVSS 7.1
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSigne…
CVE-2026-97730CVE-2026-97730
CVSS 8.5
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data …
CVE-2026-9773CVE-2026-9773
CVSS 8.8unraid
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…
CVE-2026-97724CVE-2026-97724
CVSS 4.3
A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ propert…
CVE-2026-97723CVE-2026-97723
CVSS 5.4
madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in ch…
CVE-2026-97721CVE-2026-97721
CVSS 2.7
A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-p…
CVE-2026-9772CVE-2026-9772
CVSS 8.8unraid
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.