87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,501–1,550 of 87,929 · page 31 of 1759

IDTitleSummary
CVE-2026-9579CVE-2026-9579
CVSS 6.3
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component Sys…
CVE-2026-9577CVE-2026-9577
CVSS 4.8
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page…
CVE-2026-9576CVE-2026-9576
CVSS 4.9
The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, a…
CVE-2026-95754CVE-2026-95754In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not inclu…
CVE-2026-9575CVE-2026-9575
CVSS 7.3
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/…
CVE-2026-9574CVE-2026-9574
CVSS 7.3
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/tran…
CVE-2026-9573CVE-2026-9573
CVSS 7.3
A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.ph…
CVE-2026-9572CVE-2026-9572
CVSS 3.3gpac
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the …
CVE-2026-9571CVE-2026-9571
CVSS 5.9mattermost
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allow…
CVE-2026-95703CVE-2026-95703In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, …
CVE-2026-95701CVE-2026-95701In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence…
CVE-2026-95699CVE-2026-95699
CVSS 9.6
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' d…
CVE-2026-95698CVE-2026-95698The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directo…
CVE-2026-95697CVE-2026-95697MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwri…
CVE-2026-95693CVE-2026-95693In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype…
CVE-2026-95687CVE-2026-95687
CVSS 8.8
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including…
CVE-2026-95685CVE-2026-95685MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content w…
CVE-2026-95683CVE-2026-95683In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using onl…
CVE-2026-95682CVE-2026-95682MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated …
CVE-2026-9568CVE-2026-9568
CVSS 5.0
A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/pro…
CVE-2026-95679CVE-2026-95679MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in it…
CVE-2026-95676CVE-2026-95676A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass …
CVE-2026-95675CVE-2026-95675
CVSS 9.8
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbit…
CVE-2026-95674CVE-2026-95674In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match. If …
CVE-2026-95671CVE-2026-95671In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method …
CVE-2026-95670CVE-2026-95670
CVSS 7.2
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and incl…
CVE-2026-9567CVE-2026-9567
CVSS 3.3
A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box.…
CVE-2026-95667CVE-2026-95667The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /va…
CVE-2026-95666CVE-2026-95666
CVSS 4.3
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bul…
CVE-2026-95665CVE-2026-95665MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/ev…
CVE-2026-95662CVE-2026-95662Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into execu…
CVE-2026-95661CVE-2026-95661MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL …
CVE-2026-95660CVE-2026-95660
CVSS 6.3
A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/…
CVE-2026-9566CVE-2026-9566
CVSS 4.3
A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.t…
CVE-2026-95659CVE-2026-95659MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type…
CVE-2026-95658CVE-2026-95658MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unloc…
CVE-2026-95657CVE-2026-95657
CVSS 3.5
A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectioni…
CVE-2026-95656CVE-2026-95656
CVSS 7.3
A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetect…
CVE-2026-95655CVE-2026-95655
CVSS 8.1
Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attack…
CVE-2026-95654CVE-2026-95654
CVSS 7.4
Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validi…
CVE-2026-95653CVE-2026-95653
CVSS 7.5
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predic…
CVE-2026-9565CVE-2026-9565
CVSS 6.3
A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/b…
CVE-2026-9564CVE-2026-9564
CVSS 2.4
A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file …
CVE-2026-9563CVE-2026-9563
CVSS 7.5
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consum…
CVE-2026-95627CVE-2026-95627
CVSS 7.7
When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recurs…
CVE-2026-95626CVE-2026-95626
CVSS 8.3
Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes dat…
CVE-2026-95625CVE-2026-95625
CVSS 5.9
The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which c…
CVE-2026-95624CVE-2026-95624
CVSS 6.8
The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replac…
CVE-2026-95623CVE-2026-95623
CVSS 5.6
The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server r…
CVE-2026-9562CVE-2026-9562
CVSS 7.3
A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown functi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.