87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,201–1,250 of 87,929 · page 25 of 1759

IDTitleSummary
CVE-2026-96822CVE-2026-96822
CVSS 9.3
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
CVE-2026-96821CVE-2026-96821
CVSS 6.3
Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.
CVE-2026-96820CVE-2026-96820
CVSS 7.1
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
CVE-2026-96819CVE-2026-96819
CVSS 7.1
Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.
CVE-2026-96818CVE-2026-96818
CVSS 7.5
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
CVE-2026-96817CVE-2026-96817
CVSS 8.2
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
CVE-2026-96816CVE-2026-96816
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
CVE-2026-96815CVE-2026-96815
CVSS 7.2
Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
CVE-2026-96814CVE-2026-96814
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
CVE-2026-96813CVE-2026-96813
CVSS 7.2
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Lo…
CVE-2026-96812CVE-2026-96812Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enab…
CVE-2026-96810CVE-2026-96810
CVSS 3.5
A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-a…
CVE-2026-96808CVE-2026-96808
CVSS 7.4
In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by …
CVE-2026-96807CVE-2026-96807
CVSS 4.0
In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbit…
CVE-2026-96804CVE-2026-96804
CVSS 8.8
MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which all…
CVE-2026-96803CVE-2026-96803
CVSS 7.3
A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the c…
CVE-2026-9680CVE-2026-9680
CVSS 5.8
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP end…
CVE-2026-96795CVE-2026-96795
CVSS 8.8
Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns PO…
CVE-2026-9679CVE-2026-9679
CVSS 5.9nodejs
Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into th…
CVE-2026-96780CVE-2026-96780figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded…
CVE-2026-9678CVE-2026-9678
CVSS 5.9nodejs
Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified p…
CVE-2026-96777CVE-2026-96777
CVSS 6.3
A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.adm_server…
CVE-2026-96775CVE-2026-96775
CVSS 8.8
MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which all…
CVE-2026-96774CVE-2026-96774
CVSS 5.3
A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/s…
CVE-2026-96773CVE-2026-96773
CVSS 4.3
A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::authorize of the file front/login.php o…
CVE-2026-96772CVE-2026-96772
CVSS 5.3
A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The man…
CVE-2026-96770CVE-2026-96770All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when ski…
CVE-2026-9677CVE-2026-9677
CVSS 4.8
The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the front…
CVE-2026-96766CVE-2026-96766
CVSS 6.4
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bu…
CVE-2026-96764CVE-2026-96764
CVSS 4.3
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component R…
CVE-2026-96763CVE-2026-96763
CVSS 5.4
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegm…
CVE-2026-96762CVE-2026-96762
CVSS 7.3
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. Th…
CVE-2026-96760CVE-2026-96760
CVSS 9.8
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization …
CVE-2026-9676CVE-2026-9676
CVSS 4.3
The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated…
CVE-2026-96759CVE-2026-96759
CVSS 9.8
orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can in…
CVE-2026-96758CVE-2026-96758
CVSS 9.8
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated …
CVE-2026-96757CVE-2026-96757
CVSS 9.8
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can…
CVE-2026-96756CVE-2026-96756
CVSS 8.1
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date()…
CVE-2026-96755CVE-2026-96755
CVSS 9.8
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template …
CVE-2026-96754CVE-2026-96754
CVSS 9.8
orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted rout…
CVE-2026-96752CVE-2026-96752
CVSS 7.2
The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in all …
CVE-2026-96751CVE-2026-96751
CVSS 7.3
A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the…
CVE-2026-96750CVE-2026-96750
CVSS 7.1
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that dat…
CVE-2026-9675CVE-2026-9675
CVSS 7.5nodejs
Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious…
CVE-2026-96749CVE-2026-96749
CVSS 8.4
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built f…
CVE-2026-96748CVE-2026-96748
CVSS 6.5
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an applica…
CVE-2026-96747CVE-2026-96747
CVSS 5.0
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain …
CVE-2026-96746CVE-2026-96746
CVSS 6.5
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the respo…
CVE-2026-96745CVE-2026-96745
CVSS 5.6
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored …
CVE-2026-96744CVE-2026-96744
CVSS 7.1
Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supp…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.