87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,251–1,300 of 87,929 · page 26 of 1759

IDTitleSummary
CVE-2026-96740CVE-2026-96740
CVSS 6.5
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the conso…
CVE-2026-96739CVE-2026-96739
CVSS 4.3
A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEdit…
CVE-2026-9673CVE-2026-9673
CVSS 6.8
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An a…
CVE-2026-9669CVE-2026-9669bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor,…
CVE-2026-96680CVE-2026-96680
CVSS 4.3
A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.a…
CVE-2026-9668CVE-2026-9668
CVSS 6.3
With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database querie…
CVE-2026-96678CVE-2026-96678
CVSS 6.3
A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of…
CVE-2026-96676CVE-2026-96676
CVSS 6.3
A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation …
CVE-2026-96675CVE-2026-96675
CVSS 3.3
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access.…
CVE-2026-96674CVE-2026-96674
CVSS 4.4
alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds …
CVE-2026-96673CVE-2026-96673
CVSS 7.5
Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating…
CVE-2026-96672CVE-2026-96672
CVSS 6.4
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing …
CVE-2026-9667CVE-2026-9667
CVSS 5.3ibm
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause …
CVE-2026-96659CVE-2026-96659
CVSS 9.1
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by …
CVE-2026-96658CVE-2026-96658
CVSS 9.9
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox wit…
CVE-2026-96656CVE-2026-96656
CVSS 7.2plex
Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appen…
CVE-2026-96655CVE-2026-96655
CVSS 4.3plex
Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' p…
CVE-2026-96654CVE-2026-96654
CVSS 6.5plex
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions a…
CVE-2026-96652CVE-2026-96652
CVSS 4.3plex
Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' par…
CVE-2026-96651CVE-2026-96651
CVSS 6.5plex
Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/age…
CVE-2026-96650CVE-2026-96650
CVSS 7.2
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and inc…
CVE-2026-96649CVE-2026-96649
CVSS 7.2
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via p…
CVE-2026-96647CVE-2026-96647
CVSS 6.4
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Pa…
CVE-2026-9662CVE-2026-9662
CVSS 8.1
The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insuffici…
CVE-2026-96613CVE-2026-96613
CVSS 6.5
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any…
CVE-2026-96611CVE-2026-96611
CVSS 6.9
FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored …
CVE-2026-96609CVE-2026-96609Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condi…
CVE-2026-96606CVE-2026-96606
CVSS 5.3
A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configu…
CVE-2026-96604CVE-2026-96604
CVSS 7.3
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the …
CVE-2026-96603CVE-2026-96603
CVSS 7.3
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the compo…
CVE-2026-96602CVE-2026-96602
CVSS 7.3
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler…
CVE-2026-96601CVE-2026-96601
CVSS 7.3
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The…
CVE-2026-96600CVE-2026-96600
CVSS 5.5
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administ…
CVE-2026-96599CVE-2026-96599
CVSS 5.9
Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to gu…
CVE-2026-96594CVE-2026-96594The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the respo…
CVE-2026-96589CVE-2026-96589When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the…
CVE-2026-96587CVE-2026-96587
CVSS 10.0
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critic…
CVE-2026-96580CVE-2026-96580Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request app…
CVE-2026-9658CVE-2026-9658
CVSS 7.3
Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffectiv…
CVE-2026-96578CVE-2026-96578
CVSS 7.2
The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, …
CVE-2026-96577CVE-2026-96577
CVSS 7.1
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encrypt…
CVE-2026-96575CVE-2026-96575
CVSS 7.2
The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Pr…
CVE-2026-96573CVE-2026-96573
CVSS 7.2
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field …
CVE-2026-96568CVE-2026-96568
CVSS 7.2
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to,…
CVE-2026-96567CVE-2026-96567
CVSS 7.2
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to…
CVE-2026-96566CVE-2026-96566
CVSS 7.2
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all v…
CVE-2026-96564CVE-2026-96564
CVSS 7.2
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and…
CVE-2026-96561CVE-2026-96561
CVSS 7.2
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin…
CVE-2026-96560CVE-2026-96560
CVSS 9.8
LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauth…
CVE-2026-9656CVE-2026-9656
CVSS 4.3
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.