87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,551–1,600 of 87,929 · page 32 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-95619 | CVE-2026-95619 CVSS 7.7 | A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability co… |
| CVE-2026-95616 | CVE-2026-95616 CVSS 7.5apache | An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X… |
| CVE-2026-9561 | CVE-2026-9561 CVSS 8.2eclipse | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log en… |
| CVE-2026-95604 | CVE-2026-95604 CVSS 7.5 | Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. |
| CVE-2026-95603 | CVE-2026-95603 CVSS 7.2 | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. |
| CVE-2026-95602 | CVE-2026-95602 CVSS 6.5 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control… |
| CVE-2026-95601 | CVE-2026-95601 CVSS 9.3 | Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. |
| CVE-2026-95600 | CVE-2026-95600 CVSS 5.3 | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. |
| CVE-2026-9560 | CVE-2026-9560 CVSS 7.8openvpn | Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privil… |
| CVE-2026-95594 | CVE-2026-95594 CVSS 8.1 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. |
| CVE-2026-95593 | CVE-2026-95593 CVSS 7.6 | Editor SQL Injection in Ultimeter <= 3.0.8 versions. |
| CVE-2026-95592 | CVE-2026-95592 CVSS 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. |
| CVE-2026-95590 | CVE-2026-95590 CVSS 7.1 | Subscriber SQL Injection in Tainacan <= 1.2.0 versions. |
| CVE-2026-9559 | CVE-2026-9559 CVSS 9.9 | A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the val… |
| CVE-2026-95588 | CVE-2026-95588 CVSS 8.6 | Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. |
| CVE-2026-95587 | CVE-2026-95587 CVSS 7.5 | Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. |
| CVE-2026-95586 | CVE-2026-95586 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. |
| CVE-2026-9558 | CVE-2026-9558 CVSS 9.9 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict… |
| CVE-2026-9557 | CVE-2026-9557 CVSS 6.4 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated u… |
| CVE-2026-95531 | CVE-2026-95531 CVSS 8.8 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. |
| CVE-2026-95530 | CVE-2026-95530 CVSS 6.5 | Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. |
| CVE-2026-95529 | CVE-2026-95529 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. |
| CVE-2026-95528 | CVE-2026-95528 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. |
| CVE-2026-95527 | CVE-2026-95527 CVSS 6.5 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. |
| CVE-2026-95526 | CVE-2026-95526 CVSS 7.3 | Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions. |
| CVE-2026-95525 | CVE-2026-95525 CVSS 6.5 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95524 | CVE-2026-95524 CVSS 5.3 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95523 | CVE-2026-95523 CVSS 6.5 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95522 | CVE-2026-95522 CVSS 7.6 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| CVE-2026-95521 | CVE-2026-95521 CVSS 7.8 | A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm t… |
| CVE-2026-95520 | CVE-2026-95520 CVSS 7.1 | A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFF… |
| CVE-2026-9552 | CVE-2026-9552 CVSS 7.3 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoin… |
| CVE-2026-95519 | CVE-2026-95519 CVSS 7.8 | A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-proc… |
| CVE-2026-95515 | CVE-2026-95515 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-95514 | CVE-2026-95514 CVSS 5.3 | Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. |
| CVE-2026-95513 | CVE-2026-95513 CVSS 7.5 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. |
| CVE-2026-95512 | CVE-2026-95512 CVSS 5.5 | A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening conte… |
| CVE-2026-95511 | CVE-2026-95511 | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in… |
| CVE-2026-9551 | CVE-2026-9551 CVSS 7.3 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRec… |
| CVE-2026-95509 | CVE-2026-95509 | Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bou… |
| CVE-2026-95508 | CVE-2026-95508 CVSS 7.4 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-su… |
| CVE-2026-95503 | CVE-2026-95503 CVSS 6.8 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication… |
| CVE-2026-95501 | CVE-2026-95501 CVSS 4.3 | A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.ph… |
| CVE-2026-95500 | CVE-2026-95500 CVSS 7.3 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.ph… |
| CVE-2026-9550 | CVE-2026-9550 CVSS 7.3 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown… |
| CVE-2026-95499 | CVE-2026-95499 CVSS 7.3 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.ph… |
| CVE-2026-9549 | CVE-2026-9549 CVSS 4.8checkmk | Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administra… |
| CVE-2026-9548 | CVE-2026-9548 CVSS 6.5 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22… |
| CVE-2026-9547 | CVE-2026-9547 CVSS 7.4haxx | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an un… |
| CVE-2026-9546 | CVE-2026-9546 CVSS 7.5haxx | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURL… |