91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,751–1,800 of 91,785 · page 36 of 1836

IDTitleSummary
CVE-2026-95282CVE-2026-95282
CVSS 8.8google
Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pa…
CVE-2026-95281CVE-2026-95281
CVSS 9.6google
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr…
CVE-2026-95280CVE-2026-95280
CVSS 7.5google
Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C…
CVE-2026-9528CVE-2026-9528
CVSS 7.3
A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipul…
CVE-2026-95279CVE-2026-95279
CVSS 5.4google
UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (…
CVE-2026-95278CVE-2026-95278
CVSS 8.4google
Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system a…
CVE-2026-95277CVE-2026-95277
CVSS 9.6google
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a craft…
CVE-2026-95276CVE-2026-95276
CVSS 8.3google
Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially e…
CVE-2026-95275CVE-2026-95275
CVSS 6.5google
Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged p…
CVE-2026-95274CVE-2026-95274
CVSS 8.3google
Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially …
CVE-2026-95273CVE-2026-95273
CVSS 4.3
A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py…
CVE-2026-95272CVE-2026-95272
CVSS 3.7
A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of t…
CVE-2026-95271CVE-2026-95271
CVSS 7.3
A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetecti…
CVE-2026-95270CVE-2026-95270
CVSS 3.7
A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.…
CVE-2026-9527CVE-2026-9527
CVSS 4.3
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This ma…
CVE-2026-95265CVE-2026-95265
CVSS 7.5
Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopba…
CVE-2026-95264CVE-2026-95264
CVSS 6.5
Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP…
CVE-2026-95263CVE-2026-95263
CVSS 7.2
Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password o…
CVE-2026-9526CVE-2026-9526
CVSS 7.3
A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipula…
CVE-2026-9525CVE-2026-9525
CVSS 7.3
A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation …
CVE-2026-9524CVE-2026-9524
CVSS 6.3
A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing…
CVE-2026-9523CVE-2026-9523
CVSS 7.3
A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an…
CVE-2026-9522CVE-2026-9522
CVSS 5.4devolutions
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative pr…
CVE-2026-95210CVE-2026-95210
CVSS 9.1
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
CVE-2026-9521CVE-2026-9521
CVSS 7.3
A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_…
CVE-2026-95209CVE-2026-95209
CVSS 7.5
An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).
CVE-2026-95208CVE-2026-95208
CVSS 7.5
An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via pr…
CVE-2026-9520CVE-2026-9520
CVSS 4.3
A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/a…
CVE-2026-9519CVE-2026-9519
CVSS 4.3
A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/…
CVE-2026-95184CVE-2026-95184
CVSS 7.5
Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS…
CVE-2026-9518CVE-2026-9518
CVSS 4.3
A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php…
CVE-2026-9517CVE-2026-9517
CVSS 7.3
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/a…
CVE-2026-95166CVE-2026-95166
CVSS 5.4
In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.
CVE-2026-95165CVE-2026-95165
CVSS 6.1
Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field.
CVE-2026-9516CVE-2026-9516
CVSS 7.5rurban
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-…
CVE-2026-95153CVE-2026-95153
CVSS 4.9
An issue in Bludit CMS 3.22.0 allows a remote attacker to obtain sensitive information via the /admin/ajax/clippy and /admin/ajax/save-as-draft endpoints
CVE-2026-9515CVE-2026-9515
CVSS 6.3
A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the com…
CVE-2026-95140CVE-2026-95140
CVSS 7.5
kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints acc…
CVE-2026-9514CVE-2026-9514
CVSS 6.3
A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the comp…
CVE-2026-95137CVE-2026-95137Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was …
CVE-2026-9513CVE-2026-9513
CVSS 6.3
A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the componen…
CVE-2026-95125CVE-2026-95125libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can ca…
CVE-2026-9512CVE-2026-9512
CVSS 6.3
A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of …
CVE-2026-95116CVE-2026-95116An issue in libming through 0.4.8 allows a remote attacker to cause a denial of service via the readtag_file() in src/blocks/fromswf.c.
CVE-2026-95112CVE-2026-95112
CVSS 6.5
When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, givin…
CVE-2026-9511CVE-2026-9511
CVSS 6.3
A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Settin…
CVE-2026-95106CVE-2026-95106
CVSS 9.1
Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to…
CVE-2026-95105CVE-2026-95105Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with wri…
CVE-2026-95104CVE-2026-95104
CVSS 7.5
Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condit…
CVE-2026-95102CVE-2026-95102
CVSS 9.4
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weaknes…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.