87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,551–1,600 of 87,929 · page 32 of 1759

IDTitleSummary
CVE-2026-95619CVE-2026-95619
CVSS 7.7
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability co…
CVE-2026-95616CVE-2026-95616
CVSS 7.5apache
An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X…
CVE-2026-9561CVE-2026-9561
CVSS 8.2eclipse
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log en…
CVE-2026-95604CVE-2026-95604
CVSS 7.5
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
CVE-2026-95603CVE-2026-95603
CVSS 7.2
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
CVE-2026-95602CVE-2026-95602
CVSS 6.5
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control…
CVE-2026-95601CVE-2026-95601
CVSS 9.3
Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.
CVE-2026-95600CVE-2026-95600
CVSS 5.3
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
CVE-2026-9560CVE-2026-9560
CVSS 7.8openvpn
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privil…
CVE-2026-95594CVE-2026-95594
CVSS 8.1
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
CVE-2026-95593CVE-2026-95593
CVSS 7.6
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
CVE-2026-95592CVE-2026-95592
CVSS 5.3
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
CVE-2026-95590CVE-2026-95590
CVSS 7.1
Subscriber SQL Injection in Tainacan <= 1.2.0 versions.
CVE-2026-9559CVE-2026-9559
CVSS 9.9
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the val…
CVE-2026-95588CVE-2026-95588
CVSS 8.6
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
CVE-2026-95587CVE-2026-95587
CVSS 7.5
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
CVE-2026-95586CVE-2026-95586
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
CVE-2026-9558CVE-2026-9558
CVSS 9.9
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict…
CVE-2026-9557CVE-2026-9557
CVSS 6.4
A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated u…
CVE-2026-95531CVE-2026-95531
CVSS 8.8
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
CVE-2026-95530CVE-2026-95530
CVSS 6.5
Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
CVE-2026-95529CVE-2026-95529
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
CVE-2026-95528CVE-2026-95528
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
CVE-2026-95527CVE-2026-95527
CVSS 6.5
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
CVE-2026-95526CVE-2026-95526
CVSS 7.3
Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions.
CVE-2026-95525CVE-2026-95525
CVSS 6.5
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-95524CVE-2026-95524
CVSS 5.3
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95523CVE-2026-95523
CVSS 6.5
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95522CVE-2026-95522
CVSS 7.6
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
CVE-2026-95521CVE-2026-95521
CVSS 7.8
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm t…
CVE-2026-95520CVE-2026-95520
CVSS 7.1
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFF…
CVE-2026-9552CVE-2026-9552
CVSS 7.3
A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoin…
CVE-2026-95519CVE-2026-95519
CVSS 7.8
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-proc…
CVE-2026-95515CVE-2026-95515
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
CVE-2026-95514CVE-2026-95514
CVSS 5.3
Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
CVE-2026-95513CVE-2026-95513
CVSS 7.5
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
CVE-2026-95512CVE-2026-95512
CVSS 5.5
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening conte…
CVE-2026-95511CVE-2026-95511Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in…
CVE-2026-9551CVE-2026-9551
CVSS 7.3
A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRec…
CVE-2026-95509CVE-2026-95509Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bou…
CVE-2026-95508CVE-2026-95508
CVSS 7.4
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-su…
CVE-2026-95503CVE-2026-95503
CVSS 6.8
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication…
CVE-2026-95501CVE-2026-95501
CVSS 4.3
A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.ph…
CVE-2026-95500CVE-2026-95500
CVSS 7.3
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.ph…
CVE-2026-9550CVE-2026-9550
CVSS 7.3
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown…
CVE-2026-95499CVE-2026-95499
CVSS 7.3
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.ph…
CVE-2026-9549CVE-2026-9549
CVSS 4.8checkmk
Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administra…
CVE-2026-9548CVE-2026-9548
CVSS 6.5
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22…
CVE-2026-9547CVE-2026-9547
CVSS 7.4haxx
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an un…
CVE-2026-9546CVE-2026-9546
CVSS 7.5haxx
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURL…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.