87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,301–1,350 of 87,929 · page 27 of 1759

IDTitleSummary
CVE-2026-96559CVE-2026-96559Rejected reason: This ID was for testing
CVE-2026-96556CVE-2026-96556
CVSS 7.3
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a mani…
CVE-2026-96552CVE-2026-96552
CVSS 3.1
A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the fi…
CVE-2026-96551CVE-2026-96551
CVSS 4.3
A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/m…
CVE-2026-96550CVE-2026-96550
CVSS 3.7
A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_…
CVE-2026-9655CVE-2026-9655Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-96549CVE-2026-96549
CVSS 3.3
A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_p…
CVE-2026-96548CVE-2026-96548
CVSS 5.6
A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resource…
CVE-2026-96546CVE-2026-96546
CVSS 2.5
A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in pe…
CVE-2026-96545CVE-2026-96545
CVSS 4.4
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the fi…
CVE-2026-96541CVE-2026-96541
CVSS 7.5
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and re…
CVE-2026-96538CVE-2026-96538WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_writ…
CVE-2026-96533CVE-2026-96533
CVSS 5.8
The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a publi…
CVE-2026-96532CVE-2026-96532
CVSS 7.5
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form…
CVE-2026-96531CVE-2026-96531
CVSS 6.8
The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper e…
CVE-2026-9653CVE-2026-9653A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection pac…
CVE-2026-96526CVE-2026-96526
CVSS 2.7
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing u…
CVE-2026-96525CVE-2026-96525
CVSS 2.7
The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and del…
CVE-2026-96524CVE-2026-96524
CVSS 8.8
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a con…
CVE-2026-9652CVE-2026-9652Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-96515CVE-2026-96515This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import fun…
CVE-2026-96514CVE-2026-96514
CVSS 7.3
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. T…
CVE-2026-96513CVE-2026-96513
CVSS 7.3
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation …
CVE-2026-96512CVE-2026-96512
CVSS 7.8
A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indic…
CVE-2026-9651CVE-2026-9651
CVSS 4.4schneider-electric
CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account c…
CVE-2026-9650CVE-2026-9650
CVSS 7.5schneider-electric
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated atta…
CVE-2026-9648CVE-2026-9648
CVSS 9.1
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names…
CVE-2026-9646CVE-2026-9646
CVSS 6.1scadabr
A reflected cross-site scripting issue exists in URL handling.
CVE-2026-96456CVE-2026-96456
CVSS 6.3
The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an a…
CVE-2026-96455CVE-2026-96455
CVSS 8.8
The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps…
CVE-2026-96454CVE-2026-96454
CVSS 8.2
Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together t…
CVE-2026-96451CVE-2026-96451
CVSS 8.8
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affect…
CVE-2026-96450CVE-2026-96450
CVSS 5.4
Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
CVE-2026-9645CVE-2026-9645
CVSS 9.9scadabr
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complet…
CVE-2026-96448CVE-2026-96448
CVSS 6.6
A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the sys…
CVE-2026-96446CVE-2026-96446
CVSS 4.2
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, …
CVE-2026-96445CVE-2026-96445
CVSS 6.8
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates speci…
CVE-2026-96443CVE-2026-96443
CVSS 6.5
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.
CVE-2026-96442CVE-2026-96442
CVSS 7.8
A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary co…
CVE-2026-96440CVE-2026-96440Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 ve…
CVE-2026-96431CVE-2026-96431Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allo…
CVE-2026-96430CVE-2026-96430Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated u…
CVE-2026-9643CVE-2026-9643
CVSS 7.2
The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, an…
CVE-2026-96429CVE-2026-96429SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arb…
CVE-2026-96428CVE-2026-96428SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbi…
CVE-2026-96423CVE-2026-96423
CVSS 5.5wireshark
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96422CVE-2026-96422
CVSS 5.5wireshark
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96421CVE-2026-96421
CVSS 5.5wireshark
USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96420CVE-2026-96420
CVSS 4.7wireshark
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-9642CVE-2026-9642Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.