87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,151–1,200 of 87,929 · page 24 of 1759

IDTitleSummary
CVE-2026-9697CVE-2026-9697
CVSS 7.4nodejs
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection t…
CVE-2026-96962CVE-2026-96962
CVSS 3.7
The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid in…
CVE-2026-9695CVE-2026-9695
CVSS 9.8
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to th…
CVE-2026-96940CVE-2026-96940
CVSS 8.8
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
CVE-2026-9694CVE-2026-9694
CVSS 2.6gitlab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain…
CVE-2026-9693CVE-2026-9693
CVSS 3.5mattermost
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, wh…
CVE-2026-9692CVE-2026-9692
CVSS 5.3
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded w…
CVE-2026-9691CVE-2026-9691
CVSS 9.8
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
CVE-2026-96899CVE-2026-96899
CVSS 6.8
The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it …
CVE-2026-96898CVE-2026-96898
CVSS 7.3
A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the …
CVE-2026-96897CVE-2026-96897
CVSS 5.3
The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users,…
CVE-2026-96896CVE-2026-96896
CVSS 7.2
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowi…
CVE-2026-96895CVE-2026-96895
CVSS 6.8
The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when ren…
CVE-2026-96892CVE-2026-96892
CVSS 4.3
A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of …
CVE-2026-96891CVE-2026-96891
CVSS 9.8
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipul…
CVE-2026-96890CVE-2026-96890A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to i…
CVE-2026-9689CVE-2026-9689
CVSS 4.2redhat
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform …
CVE-2026-96889CVE-2026-96889
CVSS 7.8
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free …
CVE-2026-96886CVE-2026-96886
CVSS 5.3
The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, em…
CVE-2026-96884CVE-2026-96884
CVSS 6.3
A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the file MainWindow.UI.cs of the component…
CVE-2026-96883CVE-2026-96883
CVSS 8.8
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user…
CVE-2026-96882CVE-2026-96882
CVSS 5.3
A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/…
CVE-2026-96881CVE-2026-96881
CVSS 5.3
A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/lattic…
CVE-2026-96880CVE-2026-96880
CVSS 5.3
A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/con…
CVE-2026-96879CVE-2026-96879Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0.
CVE-2026-96878CVE-2026-96878Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This i…
CVE-2026-96877CVE-2026-96877Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This i…
CVE-2026-96876CVE-2026-96876Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This i…
CVE-2026-96875CVE-2026-96875Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This iss…
CVE-2026-96874CVE-2026-96874Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. …
CVE-2026-96873CVE-2026-96873Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. …
CVE-2026-96872CVE-2026-96872Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Win…
CVE-2026-96871CVE-2026-96871
CVSS 7.2
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due …
CVE-2026-96869CVE-2026-96869
CVSS 4.3mozilla
Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, …
CVE-2026-96838CVE-2026-96838
CVSS 8.8
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.
CVE-2026-96837CVE-2026-96837
CVSS 8.8
Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
CVE-2026-96836CVE-2026-96836
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.
CVE-2026-96835CVE-2026-96835
CVSS 6.5
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.
CVE-2026-96834CVE-2026-96834
CVSS 6.5
Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
CVE-2026-96833CVE-2026-96833
CVSS 7.2
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
CVE-2026-96832CVE-2026-96832
CVSS 7.2
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
CVE-2026-96831CVE-2026-96831
CVSS 8.8
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
CVE-2026-96830CVE-2026-96830
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
CVE-2026-96829CVE-2026-96829
CVSS 6.5
Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.
CVE-2026-96828CVE-2026-96828
CVSS 7.6
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
CVE-2026-96827CVE-2026-96827
CVSS 7.6
Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
CVE-2026-96826CVE-2026-96826
CVSS 7.6
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Inject…
CVE-2026-96825CVE-2026-96825
CVSS 4.2
Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.
CVE-2026-96824CVE-2026-96824
CVSS 6.8
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
CVE-2026-96823CVE-2026-96823
CVSS 7.5
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.