91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,601–1,650 of 91,785 · page 33 of 1836

IDTitleSummary
CVE-2026-95525CVE-2026-95525
CVSS 6.5
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-95524CVE-2026-95524
CVSS 5.3
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95523CVE-2026-95523
CVSS 6.5
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95522CVE-2026-95522
CVSS 7.6
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
CVE-2026-95521CVE-2026-95521
CVSS 7.8
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm t…
CVE-2026-95520CVE-2026-95520
CVSS 7.1
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFF…
CVE-2026-9552CVE-2026-9552
CVSS 7.3
A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoin…
CVE-2026-95519CVE-2026-95519
CVSS 7.8
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-proc…
CVE-2026-95515CVE-2026-95515
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
CVE-2026-95514CVE-2026-95514
CVSS 5.3
Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
CVE-2026-95513CVE-2026-95513
CVSS 7.5
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
CVE-2026-95512CVE-2026-95512
CVSS 5.5
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening conte…
CVE-2026-95511CVE-2026-95511Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in…
CVE-2026-9551CVE-2026-9551
CVSS 7.3
A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRec…
CVE-2026-95509CVE-2026-95509Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bou…
CVE-2026-95508CVE-2026-95508
CVSS 7.4
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-su…
CVE-2026-95503CVE-2026-95503
CVSS 6.8
A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication…
CVE-2026-95501CVE-2026-95501
CVSS 4.3
A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.ph…
CVE-2026-95500CVE-2026-95500
CVSS 7.3
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.ph…
CVE-2026-9550CVE-2026-9550
CVSS 7.3
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown…
CVE-2026-95499CVE-2026-95499
CVSS 7.3
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.ph…
CVE-2026-9549CVE-2026-9549
CVSS 4.8checkmk
Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administra…
CVE-2026-9548CVE-2026-9548
CVSS 6.5
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22…
CVE-2026-9547CVE-2026-9547
CVSS 7.4haxx
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an un…
CVE-2026-9546CVE-2026-9546
CVSS 7.5haxx
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURL…
CVE-2026-9545CVE-2026-9545
CVSS 7.5haxx
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replace…
CVE-2026-9544CVE-2026-9544
CVSS 7.3
A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functiona…
CVE-2026-9543CVE-2026-9543
CVSS 9.8
A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the componen…
CVE-2026-9542CVE-2026-9542
CVSS 6.3
A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executin…
CVE-2026-9541CVE-2026-9541
CVSS 5.3squirrel-lang
A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Han…
CVE-2026-9540CVE-2026-9540
CVSS 5.3
A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such ma…
CVE-2026-95396CVE-2026-95396
CVSS 4.3
A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalContr…
CVE-2026-95395CVE-2026-95395
CVSS 5.5wireshark
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95394CVE-2026-95394
CVSS 4.7wireshark
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95393CVE-2026-95393
CVSS 4.7wireshark
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95392CVE-2026-95392
CVSS 5.5wireshark
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95391CVE-2026-95391
CVSS 5.5wireshark
ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-95390CVE-2026-95390
CVSS 5.5wireshark
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-9539CVE-2026-9539
CVSS 6.5
An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor ho…
CVE-2026-95389CVE-2026-95389
CVSS 8.1wireshark
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95388CVE-2026-95388
CVSS 5.5wireshark
Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95387CVE-2026-95387
CVSS 8.1wireshark
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95386CVE-2026-95386
CVSS 5.5wireshark
TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-95385CVE-2026-95385
CVSS 6.5google
Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri…
CVE-2026-95384CVE-2026-95384
CVSS 5.3google
Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a craft…
CVE-2026-95382CVE-2026-95382
CVSS 6.5google
Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged soci…
CVE-2026-95381CVE-2026-95381
CVSS 8.3google
Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially…
CVE-2026-95380CVE-2026-95380
CVSS 8.8google
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code insi…
CVE-2026-9538CVE-2026-9538
CVSS 7.5archive\
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payl…
CVE-2026-95376CVE-2026-95376
CVSS 8.0google
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.