87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,451–1,500 of 87,929 · page 30 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-95928 | CVE-2026-95928 CVSS 5.5 | A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsre… |
| CVE-2026-95927 | CVE-2026-95927 CVSS 7.3 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessm… |
| CVE-2026-95926 | CVE-2026-95926 CVSS 7.3 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/adm… |
| CVE-2026-95925 | CVE-2026-95925 CVSS 7.3 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/a… |
| CVE-2026-95924 | CVE-2026-95924 CVSS 7.3 | A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessme… |
| CVE-2026-9592 | CVE-2026-9592 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the sess… |
| CVE-2026-9591 | CVE-2026-9591 | Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or mod… |
| CVE-2026-9590 | CVE-2026-9590 CVSS 5.3devolutions | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privile… |
| CVE-2026-95897 | CVE-2026-95897 CVSS 5.5 | A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loa… |
| CVE-2026-9588 | CVE-2026-9588 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality… |
| CVE-2026-9587 | CVE-2026-9587 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled i… |
| CVE-2026-95868 | CVE-2026-95868 CVSS 6.3 | A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the fun… |
| CVE-2026-95866 | CVE-2026-95866 CVSS 7.2 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… |
| CVE-2026-95865 | CVE-2026-95865 CVSS 6.5 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in al… |
| CVE-2026-95864 | CVE-2026-95864 CVSS 7.2 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 du… |
| CVE-2026-95862 | CVE-2026-95862 CVSS 7.5 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of S… |
| CVE-2026-95861 | CVE-2026-95861 CVSS 7.5 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial o… |
| CVE-2026-9586 | Sangoma Switchvox SQL Injection Vulnerability KEVCVSS 9.8Sangoma | Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backen… |
| CVE-2026-9585 | CVE-2026-9585 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to pr… |
| CVE-2026-95848 | CVE-2026-95848 CVSS 9.1moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthentic… |
| CVE-2026-95847 | CVE-2026-95847 CVSS 7.5moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metada… |
| CVE-2026-95846 | CVE-2026-95846 CVSS 7.5moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite author… |
| CVE-2026-95845 | CVE-2026-95845 CVSS 7.5moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast p… |
| CVE-2026-95844 | CVE-2026-95844 CVSS 7.5moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through … |
| CVE-2026-95843 | CVE-2026-95843 CVSS 7.5moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractSh… |
| CVE-2026-95842 | CVE-2026-95842 CVSS 7.5moquette | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart… |
| CVE-2026-9584 | CVE-2026-9584 CVSS 7.3 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component… |
| CVE-2026-95835 | CVE-2026-95835 | Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obta… |
| CVE-2026-95834 | CVE-2026-95834 | Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the t… |
| CVE-2026-95833 | CVE-2026-95833 CVSS 6.3 | A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manip… |
| CVE-2026-95832 | CVE-2026-95832 | Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49… |
| CVE-2026-95831 | CVE-2026-95831 CVSS 7.8 | Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate r… |
| CVE-2026-95830 | CVE-2026-95830 CVSS 6.3 | A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the f… |
| CVE-2026-9583 | CVE-2026-9583 CVSS 4.3 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /i… |
| CVE-2026-95829 | CVE-2026-95829 CVSS 6.3 | A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the … |
| CVE-2026-95828 | CVE-2026-95828 CVSS 4.3 | A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component… |
| CVE-2026-95820 | CVE-2026-95820 CVSS 6.3 | A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functio… |
| CVE-2026-9582 | CVE-2026-9582 CVSS 4.3 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performi… |
| CVE-2026-95819 | CVE-2026-95819 CVSS 7.3 | A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unkn… |
| CVE-2026-95818 | CVE-2026-95818 CVSS 3.6 | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt… |
| CVE-2026-95817 | CVE-2026-95817 CVSS 7.2 | The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due… |
| CVE-2026-95815 | CVE-2026-95815 CVSS 6.3 | OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obta… |
| CVE-2026-95814 | CVE-2026-95814 CVSS 8.1 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed… |
| CVE-2026-95813 | CVE-2026-95813 CVSS 6.1 | e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing att… |
| CVE-2026-95812 | CVE-2026-95812 CVSS 6.1 | ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, an… |
| CVE-2026-95811 | CVE-2026-95811 CVSS 6.5 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path… |
| CVE-2026-9581 | CVE-2026-9581 CVSS 6.3 | A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to i… |
| CVE-2026-95806 | CVE-2026-95806 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a p… |
| CVE-2026-95805 | CVE-2026-95805 | A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'them… |
| CVE-2026-9580 | CVE-2026-9580 CVSS 7.3 | A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This … |