87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,401–1,450 of 87,929 · page 29 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-96273 | CVE-2026-96273 CVSS 5.5 | Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain … |
| CVE-2026-96272 | CVE-2026-96272 CVSS 7.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into … |
| CVE-2026-96271 | CVE-2026-96271 CVSS 7.1 | Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links… |
| CVE-2026-96270 | CVE-2026-96270 CVSS 7.2 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored… |
| CVE-2026-9627 | CVE-2026-9627 CVSS 8.8 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web… |
| CVE-2026-96269 | CVE-2026-96269 | GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and un… |
| CVE-2026-96268 | CVE-2026-96268 CVSS 6.4 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in al… |
| CVE-2026-96267 | CVE-2026-96267 CVSS 7.5 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, an… |
| CVE-2026-96260 | CVE-2026-96260 CVSS 6.5 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation … |
| CVE-2026-9626 | CVE-2026-9626 CVSS 6.4 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up… |
| CVE-2026-96259 | CVE-2026-96259 CVSS 5.5 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint re… |
| CVE-2026-96258 | CVE-2026-96258 CVSS 4.3 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html … |
| CVE-2026-96257 | CVE-2026-96257 CVSS 10.0 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service… |
| CVE-2026-96256 | CVE-2026-96256 CVSS 6.4 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google … |
| CVE-2026-96255 | CVE-2026-96255 CVSS 7.5 | The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's… |
| CVE-2026-9625 | CVE-2026-9625 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic… |
| CVE-2026-9624 | CVE-2026-9624 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data … |
| CVE-2026-9622 | CVE-2026-9622 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic servic… |
| CVE-2026-9621 | CVE-2026-9621 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet c… |
| CVE-2026-96200 | CVE-2026-96200 CVSS 5.3 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provide… |
| CVE-2026-9620 | CVE-2026-9620 CVSS 6.4 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and i… |
| CVE-2026-9619 | CVE-2026-9619 CVSS 4.3 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the … |
| CVE-2026-96173 | CVE-2026-96173 CVSS 5.3 | The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-cal… |
| CVE-2026-9617 | CVE-2026-9617 CVSS 6.8dalibo | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column i… |
| CVE-2026-9616 | CVE-2026-9616 CVSS 4.3 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin no… |
| CVE-2026-9615 | CVE-2026-9615 CVSS 4.3 | The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_flex… |
| CVE-2026-9614 | CVE-2026-9614 CVSS 8.8 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative acces… |
| CVE-2026-9613 | CVE-2026-9613 CVSS 4.3 | The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is… |
| CVE-2026-9612 | CVE-2026-9612 CVSS 5.3 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.… |
| CVE-2026-9611 | CVE-2026-9611 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this cand… |
| CVE-2026-9610 | CVE-2026-9610 CVSS 2.3ibm | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is acc… |
| CVE-2026-9609 | CVE-2026-9609 CVSS 4.7 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password rec… |
| CVE-2026-9608 | CVE-2026-9608 CVSS 2.4 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator … |
| CVE-2026-9607 | CVE-2026-9607 CVSS 6.3 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a… |
| CVE-2026-9606 | CVE-2026-9606 CVSS 7.3 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation o… |
| CVE-2026-9605 | CVE-2026-9605 CVSS 7.3 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This m… |
| CVE-2026-9604 | CVE-2026-9604 CVSS 4.3 | A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the a… |
| CVE-2026-96039 | CVE-2026-96039 CVSS 7.2 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 … |
| CVE-2026-9603 | CVE-2026-9603 CVSS 6.5 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session… |
| CVE-2026-9602 | CVE-2026-9602 CVSS 6.5mattermost | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious ser… |
| CVE-2026-9599 | CVE-2026-9599 CVSS 4.3 | The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorre… |
| CVE-2026-95985 | CVE-2026-95985 CVSS 8.8 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's contex… |
| CVE-2026-9597 | CVE-2026-9597 CVSS 5.4mattermost | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token … |
| CVE-2026-95958 | CVE-2026-95958 CVSS 3.3 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component P… |
| CVE-2026-95957 | CVE-2026-95957 CVSS 4.3 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signu… |
| CVE-2026-9595 | CVE-2026-9595 CVSS 5.3webpack.js | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and… |
| CVE-2026-9594 | CVE-2026-9594 CVSS 4.4 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … |
| CVE-2026-95930 | CVE-2026-95930 CVSS 6.3 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the com… |
| CVE-2026-9593 | CVE-2026-9593 CVSS 6.7 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted fi… |
| CVE-2026-95929 | CVE-2026-95929 CVSS 6.3 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapp… |