87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,451–1,500 of 87,929 · page 30 of 1759

IDTitleSummary
CVE-2026-95928CVE-2026-95928
CVSS 5.5
A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsre…
CVE-2026-95927CVE-2026-95927
CVSS 7.3
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessm…
CVE-2026-95926CVE-2026-95926
CVSS 7.3
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/adm…
CVE-2026-95925CVE-2026-95925
CVSS 7.3
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/a…
CVE-2026-95924CVE-2026-95924
CVSS 7.3
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessme…
CVE-2026-9592CVE-2026-9592SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the sess…
CVE-2026-9591CVE-2026-9591Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or mod…
CVE-2026-9590CVE-2026-9590
CVSS 5.3devolutions
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privile…
CVE-2026-95897CVE-2026-95897
CVSS 5.5
A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loa…
CVE-2026-9588CVE-2026-9588A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality…
CVE-2026-9587CVE-2026-9587An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled i…
CVE-2026-95868CVE-2026-95868
CVSS 6.3
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the fun…
CVE-2026-95866CVE-2026-95866
CVSS 7.2
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…
CVE-2026-95865CVE-2026-95865
CVSS 6.5
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in al…
CVE-2026-95864CVE-2026-95864
CVSS 7.2
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all versions up to, and including, 7.8.1 du…
CVE-2026-95862CVE-2026-95862
CVSS 7.5
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of S…
CVE-2026-95861CVE-2026-95861
CVSS 7.5
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial o…
CVE-2026-9586Sangoma Switchvox SQL Injection Vulnerability
KEVCVSS 9.8Sangoma
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backen…
CVE-2026-9585CVE-2026-9585An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to pr…
CVE-2026-95848CVE-2026-95848
CVSS 9.1moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthentic…
CVE-2026-95847CVE-2026-95847
CVSS 7.5moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metada…
CVE-2026-95846CVE-2026-95846
CVSS 7.5moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite author…
CVE-2026-95845CVE-2026-95845
CVSS 7.5moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast p…
CVE-2026-95844CVE-2026-95844
CVSS 7.5moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through …
CVE-2026-95843CVE-2026-95843
CVSS 7.5moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractSh…
CVE-2026-95842CVE-2026-95842
CVSS 7.5moquette
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart…
CVE-2026-9584CVE-2026-9584
CVSS 7.3
A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component…
CVE-2026-95835CVE-2026-95835Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obta…
CVE-2026-95834CVE-2026-95834Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the t…
CVE-2026-95833CVE-2026-95833
CVSS 6.3
A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manip…
CVE-2026-95832CVE-2026-95832Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49…
CVE-2026-95831CVE-2026-95831
CVSS 7.8
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate r…
CVE-2026-95830CVE-2026-95830
CVSS 6.3
A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the f…
CVE-2026-9583CVE-2026-9583
CVSS 4.3
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /i…
CVE-2026-95829CVE-2026-95829
CVSS 6.3
A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the …
CVE-2026-95828CVE-2026-95828
CVSS 4.3
A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component…
CVE-2026-95820CVE-2026-95820
CVSS 6.3
A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functio…
CVE-2026-9582CVE-2026-9582
CVSS 4.3
A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performi…
CVE-2026-95819CVE-2026-95819
CVSS 7.3
A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unkn…
CVE-2026-95818CVE-2026-95818
CVSS 3.6
A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt…
CVE-2026-95817CVE-2026-95817
CVSS 7.2
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due…
CVE-2026-95815CVE-2026-95815
CVSS 6.3
OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obta…
CVE-2026-95814CVE-2026-95814
CVSS 8.1
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed…
CVE-2026-95813CVE-2026-95813
CVSS 6.1
e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing att…
CVE-2026-95812CVE-2026-95812
CVSS 6.1
ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, an…
CVE-2026-95811CVE-2026-95811
CVSS 6.5
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path…
CVE-2026-9581CVE-2026-9581
CVSS 6.3
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to i…
CVE-2026-95806CVE-2026-95806MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point.  The phar stream wrapper causes PHP to treat a p…
CVE-2026-95805CVE-2026-95805A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'them…
CVE-2026-9580CVE-2026-9580
CVSS 7.3
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.