87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 951–1,000 of 87,929 · page 20 of 1759

IDTitleSummary
CVE-2026-97413CVE-2026-97413
CVSS 9.8
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read fr…
CVE-2026-97412CVE-2026-97412In the Linux kernel, the following vulnerability has been resolved: pds_core: quiesce DMA before freeing resources pdsc_teardown() frees DMA buffers but does…
CVE-2026-97411CVE-2026-97411In the Linux kernel, the following vulnerability has been resolved: net: ibm: emac: mal: fix potential system hang in mal_remove() napi_disable() is not idem…
CVE-2026-97410CVE-2026-97410In the Linux kernel, the following vulnerability has been resolved: netconsole: take target_cleanup_list_lock in drop_netconsole_target() drop_netconsole_tar…
CVE-2026-9741CVE-2026-9741
CVSS 6.5mongodb
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results …
CVE-2026-97409CVE-2026-97409
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Do not cancel requests in io target before it is initialized A new nvme-fc contr…
CVE-2026-97408CVE-2026-97408In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate connectionless PSM length Connectionless L2CAP frames carry a …
CVE-2026-97407CVE-2026-97407In the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt rockchip_pdm_s…
CVE-2026-97404CVE-2026-97404In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticat…
CVE-2026-9740CVE-2026-9740
CVSS 7.5mongodb
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. Th…
CVE-2026-97399CVE-2026-97399
CVSS 3.7
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may cra…
CVE-2026-97395CVE-2026-97395
CVSS 8.1
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint…
CVE-2026-9738CVE-2026-9738
CVSS 4.4
The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versio…
CVE-2026-9737CVE-2026-9737
CVSS 6.5mongodb
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to i…
CVE-2026-97368CVE-2026-97368
CVSS 6.3
A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-syste…
CVE-2026-97366CVE-2026-97366
CVSS 6.3
A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/wind…
CVE-2026-97365CVE-2026-97365
CVSS 6.3
A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a man…
CVE-2026-97363CVE-2026-97363
CVSS 7.5
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacke…
CVE-2026-97362CVE-2026-97362
CVSS 7.5
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of avai…
CVE-2026-97360CVE-2026-97360
CVSS 10.0
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, an…
CVE-2026-9736CVE-2026-9736
CVSS 5.3ibm
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of speci…
CVE-2026-97359CVE-2026-97359
CVSS 10.0
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve rem…
CVE-2026-9735CVE-2026-9735
CVSS 5.5mongodb
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is…
CVE-2026-97347CVE-2026-97347
CVSS 7.2
The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.…
CVE-2026-97344CVE-2026-97344
CVSS 6.4
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User M…
CVE-2026-97343CVE-2026-97343
CVSS 4.3
The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Accou…
CVE-2026-97342CVE-2026-97342
CVSS 7.2
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Pos…
CVE-2026-97341CVE-2026-97341
CVSS 7.2
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all version…
CVE-2026-9734CVE-2026-9734
CVSS 4.3
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to mis…
CVE-2026-97338CVE-2026-97338
CVSS 6.4
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to ins…
CVE-2026-97337CVE-2026-97337
CVSS 7.5
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and inclu…
CVE-2026-97336CVE-2026-97336
CVSS 7.2
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insuf…
CVE-2026-97335CVE-2026-97335
CVSS 7.7
Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux al…
CVE-2026-97332CVE-2026-97332
CVSS 5.3
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it …
CVE-2026-9733CVE-2026-9733
CVSS 9.1
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the co…
CVE-2026-97326CVE-2026-97326
CVSS 7.3
A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of t…
CVE-2026-97325CVE-2026-97325
CVSS 4.3
A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCac…
CVE-2026-97324CVE-2026-97324
CVSS 7.3
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/s…
CVE-2026-97323CVE-2026-97323
CVSS 6.3
A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/s…
CVE-2026-97322CVE-2026-97322
CVSS 4.3
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn…
CVE-2026-97321CVE-2026-97321
CVSS 6.3
A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of …
CVE-2026-97320CVE-2026-97320
CVSS 6.3
A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the f…
CVE-2026-9732CVE-2026-9732
CVSS 4.3
The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,…
CVE-2026-97319CVE-2026-97319
CVSS 6.8
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, whic…
CVE-2026-97318CVE-2026-97318
CVSS 6.1
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later r…
CVE-2026-97317CVE-2026-97317
CVSS 5.3
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in pub…
CVE-2026-97316CVE-2026-97316
CVSS 5.8
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attack…
CVE-2026-97311CVE-2026-97311
CVSS 4.3
A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specifi…
CVE-2026-9731CVE-2026-9731
CVSS 4.3
The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorr…
CVE-2026-97309CVE-2026-97309Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.