87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,351–1,400 of 87,929 · page 28 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-96419 | CVE-2026-96419 CVSS 5.5 | Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution |
| CVE-2026-96418 | CVE-2026-96418 CVSS 5.5 | TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96417 | CVE-2026-96417 CVSS 5.5 | RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96416 | CVE-2026-96416 CVSS 5.5 | IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-96415 | CVE-2026-96415 CVSS 5.5 | Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-9641 | CVE-2026-9641 CVSS 5.3 | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only … |
| CVE-2026-96404 | CVE-2026-96404 | When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the … |
| CVE-2026-96400 | CVE-2026-96400 | With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and link… |
| CVE-2026-9640 | CVE-2026-9640 CVSS 7.2canonical | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restrict… |
| CVE-2026-96399 | CVE-2026-96399 | A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue re… |
| CVE-2026-9639 | CVE-2026-9639 CVSS 6.5canonical | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes… |
| CVE-2026-9638 | CVE-2026-9638 CVSS 7.5 | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable… |
| CVE-2026-9637 | CVE-2026-9637 | A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input… |
| CVE-2026-9636 | CVE-2026-9636 | A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. T… |
| CVE-2026-96352 | CVE-2026-96352 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. |
| CVE-2026-96351 | CVE-2026-96351 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. |
| CVE-2026-96350 | CVE-2026-96350 CVSS 9.8 | Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. |
| CVE-2026-9635 | CVE-2026-9635 CVSS 6.4 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions … |
| CVE-2026-96349 | CVE-2026-96349 CVSS 10.0 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. |
| CVE-2026-96348 | CVE-2026-96348 CVSS 7.5 | Unauthenticated Broken Access Control in Bookly <= 28.2 versions. |
| CVE-2026-96347 | CVE-2026-96347 CVSS 6.5 | Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. |
| CVE-2026-96346 | CVE-2026-96346 CVSS 7.6 | Author SQL Injection in WP ERP <= 1.17.9 versions. |
| CVE-2026-96345 | CVE-2026-96345 CVSS 7.6 | Administrator SQL Injection in Estatik <= 4.3.5 versions. |
| CVE-2026-96344 | CVE-2026-96344 CVSS 7.2 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. |
| CVE-2026-96343 | CVE-2026-96343 CVSS 7.2 | Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. |
| CVE-2026-96342 | CVE-2026-96342 | Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a thro… |
| CVE-2026-9634 | CVE-2026-9634 | A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL… |
| CVE-2026-96338 | CVE-2026-96338 CVSS 6.5 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. |
| CVE-2026-9633 | CVE-2026-9633 | A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DL… |
| CVE-2026-96326 | CVE-2026-96326 CVSS 7.2 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field i… |
| CVE-2026-9632 | CVE-2026-9632 CVSS 8.8 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the c… |
| CVE-2026-9631 | CVE-2026-9631 CVSS 8.8 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfi… |
| CVE-2026-96294 | CVE-2026-96294 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.2… |
| CVE-2026-96292 | CVE-2026-96292 | Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift:… |
| CVE-2026-9629 | CVE-2026-9629 CVSS 6.4 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insuffi… |
| CVE-2026-96289 | CVE-2026-96289 | Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to … |
| CVE-2026-96288 | CVE-2026-96288 | Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrif… |
| CVE-2026-96287 | CVE-2026-96287 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended t… |
| CVE-2026-96286 | CVE-2026-96286 | Uncaught exception vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to ver… |
| CVE-2026-96284 | CVE-2026-96284 CVSS 2.5 | A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the … |
| CVE-2026-96283 | CVE-2026-96283 CVSS 3.3 | By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, makin… |
| CVE-2026-96282 | CVE-2026-96282 CVSS 3.1 | A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can b… |
| CVE-2026-96281 | CVE-2026-96281 CVSS 6.2 | On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote re… |
| CVE-2026-96280 | CVE-2026-96280 CVSS 7.5 | The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing und… |
| CVE-2026-9628 | CVE-2026-9628 CVSS 8.8 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the componen… |
| CVE-2026-96279 | CVE-2026-96279 CVSS 6.5 | A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remo… |
| CVE-2026-96277 | CVE-2026-96277 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.… |
| CVE-2026-96276 | CVE-2026-96276 CVSS 6.5 | If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extensi… |
| CVE-2026-96275 | CVE-2026-96275 CVSS 8.8 | A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On … |
| CVE-2026-96274 | CVE-2026-96274 CVSS 7.4 | In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS pa… |