87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,251–1,300 of 87,929 · page 26 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-96740 | CVE-2026-96740 CVSS 6.5 | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the conso… |
| CVE-2026-96739 | CVE-2026-96739 CVSS 4.3 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEdit… |
| CVE-2026-9673 | CVE-2026-9673 CVSS 6.8 | Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An a… |
| CVE-2026-9669 | CVE-2026-9669 | bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor,… |
| CVE-2026-96680 | CVE-2026-96680 CVSS 4.3 | A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.a… |
| CVE-2026-9668 | CVE-2026-9668 CVSS 6.3 | With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database querie… |
| CVE-2026-96678 | CVE-2026-96678 CVSS 6.3 | A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of… |
| CVE-2026-96676 | CVE-2026-96676 CVSS 6.3 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation … |
| CVE-2026-96675 | CVE-2026-96675 CVSS 3.3 | alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access.… |
| CVE-2026-96674 | CVE-2026-96674 CVSS 4.4 | alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds … |
| CVE-2026-96673 | CVE-2026-96673 CVSS 7.5 | Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating… |
| CVE-2026-96672 | CVE-2026-96672 CVSS 6.4 | Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing … |
| CVE-2026-9667 | CVE-2026-9667 CVSS 5.3ibm | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause … |
| CVE-2026-96659 | CVE-2026-96659 CVSS 9.1 | A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by … |
| CVE-2026-96658 | CVE-2026-96658 CVSS 9.9 | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox wit… |
| CVE-2026-96656 | CVE-2026-96656 CVSS 7.2plex | Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appen… |
| CVE-2026-96655 | CVE-2026-96655 CVSS 4.3plex | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' p… |
| CVE-2026-96654 | CVE-2026-96654 CVSS 6.5plex | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions a… |
| CVE-2026-96652 | CVE-2026-96652 CVSS 4.3plex | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' par… |
| CVE-2026-96651 | CVE-2026-96651 CVSS 6.5plex | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/age… |
| CVE-2026-96650 | CVE-2026-96650 CVSS 7.2 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and inc… |
| CVE-2026-96649 | CVE-2026-96649 CVSS 7.2 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via p… |
| CVE-2026-96647 | CVE-2026-96647 CVSS 6.4 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Pa… |
| CVE-2026-9662 | CVE-2026-9662 CVSS 8.1 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insuffici… |
| CVE-2026-96613 | CVE-2026-96613 CVSS 6.5 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any… |
| CVE-2026-96611 | CVE-2026-96611 CVSS 6.9 | FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored … |
| CVE-2026-96609 | CVE-2026-96609 | Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condi… |
| CVE-2026-96606 | CVE-2026-96606 CVSS 5.3 | A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configu… |
| CVE-2026-96604 | CVE-2026-96604 CVSS 7.3 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the … |
| CVE-2026-96603 | CVE-2026-96603 CVSS 7.3 | A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the compo… |
| CVE-2026-96602 | CVE-2026-96602 CVSS 7.3 | A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler… |
| CVE-2026-96601 | CVE-2026-96601 CVSS 7.3 | A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The… |
| CVE-2026-96600 | CVE-2026-96600 CVSS 5.5 | Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administ… |
| CVE-2026-96599 | CVE-2026-96599 CVSS 5.9 | Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to gu… |
| CVE-2026-96594 | CVE-2026-96594 | The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the respo… |
| CVE-2026-96589 | CVE-2026-96589 | When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the… |
| CVE-2026-96587 | CVE-2026-96587 CVSS 10.0 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critic… |
| CVE-2026-96580 | CVE-2026-96580 | Gitea expanded a workflow's static `strategy.matrix` into its full Cartesian product without a size limit when creating a run, before the fork pull request app… |
| CVE-2026-9658 | CVE-2026-9658 CVSS 7.3 | Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffectiv… |
| CVE-2026-96578 | CVE-2026-96578 CVSS 7.2 | The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, … |
| CVE-2026-96577 | CVE-2026-96577 CVSS 7.1 | A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encrypt… |
| CVE-2026-96575 | CVE-2026-96575 CVSS 7.2 | The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Pr… |
| CVE-2026-96573 | CVE-2026-96573 CVSS 7.2 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field … |
| CVE-2026-96568 | CVE-2026-96568 CVSS 7.2 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to,… |
| CVE-2026-96567 | CVE-2026-96567 CVSS 7.2 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to… |
| CVE-2026-96566 | CVE-2026-96566 CVSS 7.2 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all v… |
| CVE-2026-96564 | CVE-2026-96564 CVSS 7.2 | The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and… |
| CVE-2026-96561 | CVE-2026-96561 CVSS 7.2 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… |
| CVE-2026-96560 | CVE-2026-96560 CVSS 9.8 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauth… |
| CVE-2026-9656 | CVE-2026-9656 CVSS 4.3 | The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… |