87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,401–1,450 of 87,929 · page 29 of 1759

IDTitleSummary
CVE-2026-96273CVE-2026-96273
CVSS 5.5
Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain …
CVE-2026-96272CVE-2026-96272
CVSS 7.5
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into …
CVE-2026-96271CVE-2026-96271
CVSS 7.1
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links…
CVE-2026-96270CVE-2026-96270
CVSS 7.2
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored…
CVE-2026-9627CVE-2026-9627
CVSS 8.8
A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web…
CVE-2026-96269CVE-2026-96269GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and un…
CVE-2026-96268CVE-2026-96268
CVSS 6.4
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in al…
CVE-2026-96267CVE-2026-96267
CVSS 7.5
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, an…
CVE-2026-96260CVE-2026-96260
CVSS 6.5
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation …
CVE-2026-9626CVE-2026-9626
CVSS 6.4
The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up…
CVE-2026-96259CVE-2026-96259
CVSS 5.5
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint re…
CVE-2026-96258CVE-2026-96258
CVSS 4.3
A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html …
CVE-2026-96257CVE-2026-96257
CVSS 10.0
A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service…
CVE-2026-96256CVE-2026-96256
CVSS 6.4
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google …
CVE-2026-96255CVE-2026-96255
CVSS 7.5
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's…
CVE-2026-9625CVE-2026-9625A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic…
CVE-2026-9624CVE-2026-9624A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data …
CVE-2026-9622CVE-2026-9622A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic servic…
CVE-2026-9621CVE-2026-9621A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet c…
CVE-2026-96200CVE-2026-96200
CVSS 5.3
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provide…
CVE-2026-9620CVE-2026-9620
CVSS 6.4
The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and i…
CVE-2026-9619CVE-2026-9619
CVSS 4.3
The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the …
CVE-2026-96173CVE-2026-96173
CVSS 5.3
The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-cal…
CVE-2026-9617CVE-2026-9617
CVSS 6.8dalibo
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column i…
CVE-2026-9616CVE-2026-9616
CVSS 4.3
The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin no…
CVE-2026-9615CVE-2026-9615
CVSS 4.3
The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_flex…
CVE-2026-9614CVE-2026-9614
CVSS 8.8
An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative acces…
CVE-2026-9613CVE-2026-9613
CVSS 4.3
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is…
CVE-2026-9612CVE-2026-9612
CVSS 5.3
The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.…
CVE-2026-9611CVE-2026-9611Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this cand…
CVE-2026-9610CVE-2026-9610
CVSS 2.3ibm
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is acc…
CVE-2026-9609CVE-2026-9609
CVSS 4.7
A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password rec…
CVE-2026-9608CVE-2026-9608
CVSS 2.4
A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator …
CVE-2026-9607CVE-2026-9607
CVSS 6.3
A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a…
CVE-2026-9606CVE-2026-9606
CVSS 7.3
A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation o…
CVE-2026-9605CVE-2026-9605
CVSS 7.3
A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This m…
CVE-2026-9604CVE-2026-9604
CVSS 4.3
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the a…
CVE-2026-96039CVE-2026-96039
CVSS 7.2
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 …
CVE-2026-9603CVE-2026-9603
CVSS 6.5
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session…
CVE-2026-9602CVE-2026-9602
CVSS 6.5mattermost
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious ser…
CVE-2026-9599CVE-2026-9599
CVSS 4.3
The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorre…
CVE-2026-95985CVE-2026-95985
CVSS 8.8
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's contex…
CVE-2026-9597CVE-2026-9597
CVSS 5.4mattermost
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token …
CVE-2026-95958CVE-2026-95958
CVSS 3.3
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component P…
CVE-2026-95957CVE-2026-95957
CVSS 4.3
A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signu…
CVE-2026-9595CVE-2026-9595
CVSS 5.3webpack.js
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and…
CVE-2026-9594CVE-2026-9594
CVSS 4.4
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …
CVE-2026-95930CVE-2026-95930
CVSS 6.3
A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the com…
CVE-2026-9593CVE-2026-9593
CVSS 6.7
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted fi…
CVE-2026-95929CVE-2026-95929
CVSS 6.3
A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapp…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.