87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 951–1,000 of 87,929 · page 20 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-97413 | CVE-2026-97413 CVSS 9.8 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read fr… |
| CVE-2026-97412 | CVE-2026-97412 | In the Linux kernel, the following vulnerability has been resolved: pds_core: quiesce DMA before freeing resources pdsc_teardown() frees DMA buffers but does… |
| CVE-2026-97411 | CVE-2026-97411 | In the Linux kernel, the following vulnerability has been resolved: net: ibm: emac: mal: fix potential system hang in mal_remove() napi_disable() is not idem… |
| CVE-2026-97410 | CVE-2026-97410 | In the Linux kernel, the following vulnerability has been resolved: netconsole: take target_cleanup_list_lock in drop_netconsole_target() drop_netconsole_tar… |
| CVE-2026-9741 | CVE-2026-9741 CVSS 6.5mongodb | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results … |
| CVE-2026-97409 | CVE-2026-97409 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Do not cancel requests in io target before it is initialized A new nvme-fc contr… |
| CVE-2026-97408 | CVE-2026-97408 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate connectionless PSM length Connectionless L2CAP frames carry a … |
| CVE-2026-97407 | CVE-2026-97407 | In the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt rockchip_pdm_s… |
| CVE-2026-97404 | CVE-2026-97404 | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticat… |
| CVE-2026-9740 | CVE-2026-9740 CVSS 7.5mongodb | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. Th… |
| CVE-2026-97399 | CVE-2026-97399 CVSS 3.7 | The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may cra… |
| CVE-2026-97395 | CVE-2026-97395 CVSS 8.1 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint… |
| CVE-2026-9738 | CVE-2026-9738 CVSS 4.4 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versio… |
| CVE-2026-9737 | CVE-2026-9737 CVSS 6.5mongodb | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to i… |
| CVE-2026-97368 | CVE-2026-97368 CVSS 6.3 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-syste… |
| CVE-2026-97366 | CVE-2026-97366 CVSS 6.3 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/wind… |
| CVE-2026-97365 | CVE-2026-97365 CVSS 6.3 | A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a man… |
| CVE-2026-97363 | CVE-2026-97363 CVSS 7.5 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacke… |
| CVE-2026-97362 | CVE-2026-97362 CVSS 7.5 | HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of avai… |
| CVE-2026-97360 | CVE-2026-97360 CVSS 10.0 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, an… |
| CVE-2026-9736 | CVE-2026-9736 CVSS 5.3ibm | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of speci… |
| CVE-2026-97359 | CVE-2026-97359 CVSS 10.0 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve rem… |
| CVE-2026-9735 | CVE-2026-9735 CVSS 5.5mongodb | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is… |
| CVE-2026-97347 | CVE-2026-97347 CVSS 7.2 | The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.… |
| CVE-2026-97344 | CVE-2026-97344 CVSS 6.4 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User M… |
| CVE-2026-97343 | CVE-2026-97343 CVSS 4.3 | The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Accou… |
| CVE-2026-97342 | CVE-2026-97342 CVSS 7.2 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Pos… |
| CVE-2026-97341 | CVE-2026-97341 CVSS 7.2 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all version… |
| CVE-2026-9734 | CVE-2026-9734 CVSS 4.3 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to mis… |
| CVE-2026-97338 | CVE-2026-97338 CVSS 6.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to ins… |
| CVE-2026-97337 | CVE-2026-97337 CVSS 7.5 | The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and inclu… |
| CVE-2026-97336 | CVE-2026-97336 CVSS 7.2 | The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insuf… |
| CVE-2026-97335 | CVE-2026-97335 CVSS 7.7 | Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux al… |
| CVE-2026-97332 | CVE-2026-97332 CVSS 5.3 | The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it … |
| CVE-2026-9733 | CVE-2026-9733 CVSS 9.1 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the co… |
| CVE-2026-97326 | CVE-2026-97326 CVSS 7.3 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of t… |
| CVE-2026-97325 | CVE-2026-97325 CVSS 4.3 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCac… |
| CVE-2026-97324 | CVE-2026-97324 CVSS 7.3 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/s… |
| CVE-2026-97323 | CVE-2026-97323 CVSS 6.3 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/s… |
| CVE-2026-97322 | CVE-2026-97322 CVSS 4.3 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn… |
| CVE-2026-97321 | CVE-2026-97321 CVSS 6.3 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of … |
| CVE-2026-97320 | CVE-2026-97320 CVSS 6.3 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the f… |
| CVE-2026-9732 | CVE-2026-9732 CVSS 4.3 | The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… |
| CVE-2026-97319 | CVE-2026-97319 CVSS 6.8 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, whic… |
| CVE-2026-97318 | CVE-2026-97318 CVSS 6.1 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later r… |
| CVE-2026-97317 | CVE-2026-97317 CVSS 5.3 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in pub… |
| CVE-2026-97316 | CVE-2026-97316 CVSS 5.8 | The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attack… |
| CVE-2026-97311 | CVE-2026-97311 CVSS 4.3 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specifi… |
| CVE-2026-9731 | CVE-2026-9731 CVSS 4.3 | The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorr… |
| CVE-2026-97309 | CVE-2026-97309 | Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy… |