87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,301–1,350 of 87,929 · page 27 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-96559 | CVE-2026-96559 | Rejected reason: This ID was for testing |
| CVE-2026-96556 | CVE-2026-96556 CVSS 7.3 | A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a mani… |
| CVE-2026-96552 | CVE-2026-96552 CVSS 3.1 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the fi… |
| CVE-2026-96551 | CVE-2026-96551 CVSS 4.3 | A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/m… |
| CVE-2026-96550 | CVE-2026-96550 CVSS 3.7 | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_… |
| CVE-2026-9655 | CVE-2026-9655 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-96549 | CVE-2026-96549 CVSS 3.3 | A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_p… |
| CVE-2026-96548 | CVE-2026-96548 CVSS 5.6 | A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resource… |
| CVE-2026-96546 | CVE-2026-96546 CVSS 2.5 | A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in pe… |
| CVE-2026-96545 | CVE-2026-96545 CVSS 4.4 | An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the fi… |
| CVE-2026-96541 | CVE-2026-96541 CVSS 7.5 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and re… |
| CVE-2026-96538 | CVE-2026-96538 | WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_writ… |
| CVE-2026-96533 | CVE-2026-96533 CVSS 5.8 | The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a publi… |
| CVE-2026-96532 | CVE-2026-96532 CVSS 7.5 | The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form… |
| CVE-2026-96531 | CVE-2026-96531 CVSS 6.8 | The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper e… |
| CVE-2026-9653 | CVE-2026-9653 | A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection pac… |
| CVE-2026-96526 | CVE-2026-96526 CVSS 2.7 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing u… |
| CVE-2026-96525 | CVE-2026-96525 CVSS 2.7 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and del… |
| CVE-2026-96524 | CVE-2026-96524 CVSS 8.8 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a con… |
| CVE-2026-9652 | CVE-2026-9652 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-96515 | CVE-2026-96515 | This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import fun… |
| CVE-2026-96514 | CVE-2026-96514 CVSS 7.3 | A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. T… |
| CVE-2026-96513 | CVE-2026-96513 CVSS 7.3 | A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation … |
| CVE-2026-96512 | CVE-2026-96512 CVSS 7.8 | A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indic… |
| CVE-2026-9651 | CVE-2026-9651 CVSS 4.4schneider-electric | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account c… |
| CVE-2026-9650 | CVE-2026-9650 CVSS 7.5schneider-electric | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated atta… |
| CVE-2026-9648 | CVE-2026-9648 CVSS 9.1 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names… |
| CVE-2026-9646 | CVE-2026-9646 CVSS 6.1scadabr | A reflected cross-site scripting issue exists in URL handling. |
| CVE-2026-96456 | CVE-2026-96456 CVSS 6.3 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an a… |
| CVE-2026-96455 | CVE-2026-96455 CVSS 8.8 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps… |
| CVE-2026-96454 | CVE-2026-96454 CVSS 8.2 | Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together t… |
| CVE-2026-96451 | CVE-2026-96451 CVSS 8.8 | Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affect… |
| CVE-2026-96450 | CVE-2026-96450 CVSS 5.4 | Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions. |
| CVE-2026-9645 | CVE-2026-9645 CVSS 9.9scadabr | Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complet… |
| CVE-2026-96448 | CVE-2026-96448 CVSS 6.6 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the sys… |
| CVE-2026-96446 | CVE-2026-96446 CVSS 4.2 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, … |
| CVE-2026-96445 | CVE-2026-96445 CVSS 6.8 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates speci… |
| CVE-2026-96443 | CVE-2026-96443 CVSS 6.5 | Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE. |
| CVE-2026-96442 | CVE-2026-96442 CVSS 7.8 | A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary co… |
| CVE-2026-96440 | CVE-2026-96440 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 ve… |
| CVE-2026-96431 | CVE-2026-96431 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allo… |
| CVE-2026-96430 | CVE-2026-96430 | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated u… |
| CVE-2026-9643 | CVE-2026-9643 CVSS 7.2 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, an… |
| CVE-2026-96429 | CVE-2026-96429 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arb… |
| CVE-2026-96428 | CVE-2026-96428 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbi… |
| CVE-2026-96423 | CVE-2026-96423 CVSS 5.5wireshark | X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96422 | CVE-2026-96422 CVSS 5.5wireshark | Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96421 | CVE-2026-96421 CVSS 5.5wireshark | USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96420 | CVE-2026-96420 CVSS 4.7wireshark | Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-9642 | CVE-2026-9642 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |