91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,601–1,650 of 91,785 · page 33 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-95525 | CVE-2026-95525 CVSS 6.5 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95524 | CVE-2026-95524 CVSS 5.3 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95523 | CVE-2026-95523 CVSS 6.5 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95522 | CVE-2026-95522 CVSS 7.6 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| CVE-2026-95521 | CVE-2026-95521 CVSS 7.8 | A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm t… |
| CVE-2026-95520 | CVE-2026-95520 CVSS 7.1 | A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFF… |
| CVE-2026-9552 | CVE-2026-9552 CVSS 7.3 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoin… |
| CVE-2026-95519 | CVE-2026-95519 CVSS 7.8 | A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-proc… |
| CVE-2026-95515 | CVE-2026-95515 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-95514 | CVE-2026-95514 CVSS 5.3 | Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. |
| CVE-2026-95513 | CVE-2026-95513 CVSS 7.5 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. |
| CVE-2026-95512 | CVE-2026-95512 CVSS 5.5 | A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening conte… |
| CVE-2026-95511 | CVE-2026-95511 | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in… |
| CVE-2026-9551 | CVE-2026-9551 CVSS 7.3 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRec… |
| CVE-2026-95509 | CVE-2026-95509 | Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bou… |
| CVE-2026-95508 | CVE-2026-95508 CVSS 7.4 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-su… |
| CVE-2026-95503 | CVE-2026-95503 CVSS 6.8 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication… |
| CVE-2026-95501 | CVE-2026-95501 CVSS 4.3 | A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.ph… |
| CVE-2026-95500 | CVE-2026-95500 CVSS 7.3 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.ph… |
| CVE-2026-9550 | CVE-2026-9550 CVSS 7.3 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown… |
| CVE-2026-95499 | CVE-2026-95499 CVSS 7.3 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.ph… |
| CVE-2026-9549 | CVE-2026-9549 CVSS 4.8checkmk | Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administra… |
| CVE-2026-9548 | CVE-2026-9548 CVSS 6.5 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22… |
| CVE-2026-9547 | CVE-2026-9547 CVSS 7.4haxx | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an un… |
| CVE-2026-9546 | CVE-2026-9546 CVSS 7.5haxx | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURL… |
| CVE-2026-9545 | CVE-2026-9545 CVSS 7.5haxx | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replace… |
| CVE-2026-9544 | CVE-2026-9544 CVSS 7.3 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functiona… |
| CVE-2026-9543 | CVE-2026-9543 CVSS 9.8 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the componen… |
| CVE-2026-9542 | CVE-2026-9542 CVSS 6.3 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executin… |
| CVE-2026-9541 | CVE-2026-9541 CVSS 5.3squirrel-lang | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Han… |
| CVE-2026-9540 | CVE-2026-9540 CVSS 5.3 | A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such ma… |
| CVE-2026-95396 | CVE-2026-95396 CVSS 4.3 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalContr… |
| CVE-2026-95395 | CVE-2026-95395 CVSS 5.5wireshark | IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95394 | CVE-2026-95394 CVSS 4.7wireshark | Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95393 | CVE-2026-95393 CVSS 4.7wireshark | CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95392 | CVE-2026-95392 CVSS 5.5wireshark | MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95391 | CVE-2026-95391 CVSS 5.5wireshark | ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service |
| CVE-2026-95390 | CVE-2026-95390 CVSS 5.5wireshark | PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service |
| CVE-2026-9539 | CVE-2026-9539 CVSS 6.5 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor ho… |
| CVE-2026-95389 | CVE-2026-95389 CVSS 8.1wireshark | SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95388 | CVE-2026-95388 CVSS 5.5wireshark | Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95387 | CVE-2026-95387 CVSS 8.1wireshark | SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-95386 | CVE-2026-95386 CVSS 5.5wireshark | TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service |
| CVE-2026-95385 | CVE-2026-95385 CVSS 6.5google | Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri… |
| CVE-2026-95384 | CVE-2026-95384 CVSS 5.3google | Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a craft… |
| CVE-2026-95382 | CVE-2026-95382 CVSS 6.5google | Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged soci… |
| CVE-2026-95381 | CVE-2026-95381 CVSS 8.3google | Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially… |
| CVE-2026-95380 | CVE-2026-95380 CVSS 8.8google | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code insi… |
| CVE-2026-9538 | CVE-2026-9538 CVSS 7.5archive\ | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payl… |
| CVE-2026-95376 | CVE-2026-95376 CVSS 8.0google | Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system… |