87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,101–1,150 of 87,929 · page 23 of 1759

IDTitleSummary
CVE-2026-97164CVE-2026-97164Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` paramete…
CVE-2026-97163CVE-2026-97163Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97162CVE-2026-97162Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97161CVE-2026-97161Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97160CVE-2026-97160Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-9716CVE-2026-9716
CVSS 7.5schneider-electric
CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionalit…
CVE-2026-97155CVE-2026-97155
CVSS 6.5
Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict whi…
CVE-2026-97152CVE-2026-97152Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-W…
CVE-2026-97151CVE-2026-97151mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allo…
CVE-2026-97150CVE-2026-97150
CVSS 7.2
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is …
CVE-2026-97149CVE-2026-97149In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, ex…
CVE-2026-9714CVE-2026-9714
CVSS 6.4
The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up…
CVE-2026-9713CVE-2026-9713
CVSS 7.5
The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON f…
CVE-2026-9711CVE-2026-9711
CVSS 9.8
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versio…
CVE-2026-9710CVE-2026-9710
CVSS 7.7
The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to ca…
CVE-2026-9709CVE-2026-9709
CVSS 7.7
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the…
CVE-2026-9708CVE-2026-9708
CVSS 4.9mattermost
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target te…
CVE-2026-97079CVE-2026-97079
CVSS 4.3
Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.
CVE-2026-97078CVE-2026-97078
CVSS 5.3
Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.
CVE-2026-97077CVE-2026-97077
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.
CVE-2026-97074CVE-2026-97074
CVSS 4.3
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
CVE-2026-97071CVE-2026-97071
CVSS 5.3
Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
CVE-2026-97070CVE-2026-97070Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Se…
CVE-2026-97067CVE-2026-97067
CVSS 6.5
Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.
CVE-2026-97066CVE-2026-97066
CVSS 5.3
Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.
CVE-2026-97065CVE-2026-97065
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
CVE-2026-97064CVE-2026-97064
CVSS 9.1
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers…
CVE-2026-97063CVE-2026-97063
CVSS 9.1
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without…
CVE-2026-97062CVE-2026-97062
CVSS 5.4
Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the application origin, allowing authentic…
CVE-2026-97061CVE-2026-97061
CVSS 4.3
Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists …
CVE-2026-97060CVE-2026-97060
CVSS 7.2
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership…
CVE-2026-97059CVE-2026-97059
CVSS 8.2
DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length…
CVE-2026-97058CVE-2026-97058
CVSS 5.3
sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeErr…
CVE-2026-97057CVE-2026-97057
CVSS 7.5
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supp…
CVE-2026-97056CVE-2026-97056
CVSS 6.8
SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0…
CVE-2026-97055CVE-2026-97055
CVSS 8.1
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIG…
CVE-2026-9705CVE-2026-9705
CVSS 6.5redhat
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit th…
CVE-2026-9704CVE-2026-9704
CVSS 6.8redhat
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JW…
CVE-2026-97029CVE-2026-97029
CVSS 5.7
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the san…
CVE-2026-97027CVE-2026-97027
CVSS 3.6
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, …
CVE-2026-97026CVE-2026-97026
CVSS 3.9
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive uma…
CVE-2026-97025CVE-2026-97025
CVSS 3.2
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local user…
CVE-2026-97024CVE-2026-97024
CVSS 7.1
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host syst…
CVE-2026-97023CVE-2026-97023
CVSS 7.1
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of atta…
CVE-2026-9702CVE-2026-9702
CVSS 7.5
The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-…
CVE-2026-9701CVE-2026-9701
CVSS 9.8
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plainte…
CVE-2026-9700CVE-2026-9700
CVSS 7.5
The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insuffic…
CVE-2026-96990CVE-2026-96990Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Use…
CVE-2026-9699CVE-2026-9699
CVSS 6.8
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with acces…
CVE-2026-9698CVE-2026-9698
CVSS 9.8perl
DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were s…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.