87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 701–750 of 87,929 · page 15 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-97711 | CVE-2026-97711 | Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function value… |
| CVE-2026-9771 | CVE-2026-9771 CVSS 8.8 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the ker… |
| CVE-2026-9770 | CVE-2026-9770 CVSS 5.3tp-link | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with… |
| CVE-2026-9769 | CVE-2026-9769 CVSS 7.5 | justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.fini… |
| CVE-2026-97689 | CVE-2026-97689 | urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded mem… |
| CVE-2026-97688 | CVE-2026-97688 | urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the … |
| CVE-2026-97687 | CVE-2026-97687 | urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cer… |
| CVE-2026-97686 | CVE-2026-97686 CVSS 5.5 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and s… |
| CVE-2026-97685 | CVE-2026-97685 | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question o… |
| CVE-2026-97680 | CVE-2026-97680 CVSS 8.3 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper acce… |
| CVE-2026-9768 | CVE-2026-9768 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-97679 | CVE-2026-97679 CVSS 8.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … |
| CVE-2026-97678 | CVE-2026-97678 CVSS 8.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation. |
| CVE-2026-97676 | CVE-2026-97676 CVSS 8.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … |
| CVE-2026-97674 | CVE-2026-97674 CVSS 8.1 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special el… |
| CVE-2026-97673 | CVE-2026-97673 CVSS 8.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation. |
| CVE-2026-97671 | CVE-2026-97671 CVSS 6.5 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability. |
| CVE-2026-9767 | CVE-2026-9767 CVSS 6.5 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions … |
| CVE-2026-97663 | CVE-2026-97663 CVSS 7.2 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and inclu… |
| CVE-2026-97662 | CVE-2026-97662 CVSS 8.2 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to cre… |
| CVE-2026-97661 | CVE-2026-97661 CVSS 7.2 | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, an… |
| CVE-2026-97660 | CVE-2026-97660 CVSS 7.2 | The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all… |
| CVE-2026-9766 | CVE-2026-9766 CVSS 4.3 | The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not… |
| CVE-2026-97655 | CVE-2026-97655 CVSS 8.8 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an incomplete blocklist in the code security scanner. |
| CVE-2026-97652 | CVE-2026-97652 CVSS 6.1 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI … |
| CVE-2026-97650 | CVE-2026-97650 CVSS 4.3 | A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function e… |
| CVE-2026-9765 | CVE-2026-9765 CVSS 7.1 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resourc… |
| CVE-2026-97649 | CVE-2026-97649 CVSS 4.7 | A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown func… |
| CVE-2026-97648 | CVE-2026-97648 CVSS 4.3 | A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performin… |
| CVE-2026-97647 | CVE-2026-97647 CVSS 5.3 | A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown func… |
| CVE-2026-97646 | CVE-2026-97646 CVSS 7.3 | A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the … |
| CVE-2026-97644 | CVE-2026-97644 CVSS 8.8 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all ve… |
| CVE-2026-97641 | CVE-2026-97641 CVSS 7.2 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.… |
| CVE-2026-97637 | CVE-2026-97637 CVSS 9.8 | The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2.… |
| CVE-2026-97636 | CVE-2026-97636 CVSS 6.5 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deploymen… |
| CVE-2026-97634 | CVE-2026-97634 CVSS 6.5 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including… |
| CVE-2026-97626 | CVE-2026-97626 | Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the … |
| CVE-2026-97622 | CVE-2026-97622 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-62062. Reason: This candidate is a reservation duplicate of CVE-2026-62062… |
| CVE-2026-97621 | CVE-2026-97621 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: fix unchecked bound endpoint name length rockchip_dp_drm_encod… |
| CVE-2026-97620 | CVE-2026-97620 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches emit_render_cache_flush… |
| CVE-2026-9762 | CVE-2026-9762 CVSS 7.8ibm | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. |
| CVE-2026-97619 | CVE-2026-97619 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: end write accounting from ->ki_complete Commit b000145e9907 moved both the f… |
| CVE-2026-97618 | CVE-2026-97618 | In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overconsume buffers when using MSG_TRUNC When a recv/recvmsg is issue… |
| CVE-2026-97617 | CVE-2026-97617 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Check resize_disabled before publishing the new subbuf order ring_buffer_sub… |
| CVE-2026-97616 | CVE-2026-97616 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: release all action references on NEWACTION failure When a batched RTM… |
| CVE-2026-97615 | CVE-2026-97615 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: use option bits for CFM/MRP frame handlers CFM and MRP register a global br_… |
| CVE-2026-97614 | CVE-2026-97614 | In the Linux kernel, the following vulnerability has been resolved: net: dsa: tag_brcm: legacy FCS: request needed tailroom The legacy FCS tagger calculates … |
| CVE-2026-97613 | CVE-2026-97613 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Reserve extra CQ slot for the fence completion CQE The RX completion queue is … |
| CVE-2026-97612 | CVE-2026-97612 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: net: mpls: clear inner_protocol when the last label is popped skb_mpls_push() records the… |
| CVE-2026-97611 | CVE-2026-97611 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix use-after-free of the flow table mask array tbl_mask_array_realloc(… |