87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,351–1,400 of 87,929 · page 28 of 1759

IDTitleSummary
CVE-2026-96419CVE-2026-96419
CVSS 5.5
Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
CVE-2026-96418CVE-2026-96418
CVSS 5.5
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96417CVE-2026-96417
CVSS 5.5
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96416CVE-2026-96416
CVSS 5.5
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96415CVE-2026-96415
CVSS 5.5
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-9641CVE-2026-9641
CVSS 5.3
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only …
CVE-2026-96404CVE-2026-96404When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the …
CVE-2026-96400CVE-2026-96400With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link…
CVE-2026-9640CVE-2026-9640
CVSS 7.2canonical
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restrict…
CVE-2026-96399CVE-2026-96399A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue re…
CVE-2026-9639CVE-2026-9639
CVSS 6.5canonical
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes…
CVE-2026-9638CVE-2026-9638
CVSS 7.5
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable…
CVE-2026-9637CVE-2026-9637A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input…
CVE-2026-9636CVE-2026-9636A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. T…
CVE-2026-96352CVE-2026-96352
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
CVE-2026-96351CVE-2026-96351
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
CVE-2026-96350CVE-2026-96350
CVSS 9.8
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
CVE-2026-9635CVE-2026-9635
CVSS 6.4
The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions …
CVE-2026-96349CVE-2026-96349
CVSS 10.0
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
CVE-2026-96348CVE-2026-96348
CVSS 7.5
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
CVE-2026-96347CVE-2026-96347
CVSS 6.5
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
CVE-2026-96346CVE-2026-96346
CVSS 7.6
Author SQL Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96345CVE-2026-96345
CVSS 7.6
Administrator SQL Injection in Estatik <= 4.3.5 versions.
CVE-2026-96344CVE-2026-96344
CVSS 7.2
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
CVE-2026-96343CVE-2026-96343
CVSS 7.2
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96342CVE-2026-96342Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a thro…
CVE-2026-9634CVE-2026-9634A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL…
CVE-2026-96338CVE-2026-96338
CVSS 6.5
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
CVE-2026-9633CVE-2026-9633A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DL…
CVE-2026-96326CVE-2026-96326
CVSS 7.2
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field i…
CVE-2026-9632CVE-2026-9632
CVSS 8.8
A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the c…
CVE-2026-9631CVE-2026-9631
CVSS 8.8
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfi…
CVE-2026-96294CVE-2026-96294Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.2…
CVE-2026-96292CVE-2026-96292Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift:…
CVE-2026-9629CVE-2026-9629
CVSS 6.4
The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insuffi…
CVE-2026-96289CVE-2026-96289Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to …
CVE-2026-96288CVE-2026-96288Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrif…
CVE-2026-96287CVE-2026-96287Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended t…
CVE-2026-96286CVE-2026-96286Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to ver…
CVE-2026-96284CVE-2026-96284
CVSS 2.5
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the …
CVE-2026-96283CVE-2026-96283
CVSS 3.3
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, makin…
CVE-2026-96282CVE-2026-96282
CVSS 3.1
A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can b…
CVE-2026-96281CVE-2026-96281
CVSS 6.2
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote re…
CVE-2026-96280CVE-2026-96280
CVSS 7.5
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing und…
CVE-2026-9628CVE-2026-9628
CVSS 8.8
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the componen…
CVE-2026-96279CVE-2026-96279
CVSS 6.5
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remo…
CVE-2026-96277CVE-2026-96277Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.…
CVE-2026-96276CVE-2026-96276
CVSS 6.5
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extensi…
CVE-2026-96275CVE-2026-96275
CVSS 8.8
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On …
CVE-2026-96274CVE-2026-96274
CVSS 7.4
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS pa…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.