91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,751–1,800 of 91,785 · page 36 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-95282 | CVE-2026-95282 CVSS 8.8google | Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pa… |
| CVE-2026-95281 | CVE-2026-95281 CVSS 9.6google | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr… |
| CVE-2026-95280 | CVE-2026-95280 CVSS 7.5google | Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
| CVE-2026-9528 | CVE-2026-9528 CVSS 7.3 | A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipul… |
| CVE-2026-95279 | CVE-2026-95279 CVSS 5.4google | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (… |
| CVE-2026-95278 | CVE-2026-95278 CVSS 8.4google | Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system a… |
| CVE-2026-95277 | CVE-2026-95277 CVSS 9.6google | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a craft… |
| CVE-2026-95276 | CVE-2026-95276 CVSS 8.3google | Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially e… |
| CVE-2026-95275 | CVE-2026-95275 CVSS 6.5google | Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged p… |
| CVE-2026-95274 | CVE-2026-95274 CVSS 8.3google | Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially … |
| CVE-2026-95273 | CVE-2026-95273 CVSS 4.3 | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py… |
| CVE-2026-95272 | CVE-2026-95272 CVSS 3.7 | A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of t… |
| CVE-2026-95271 | CVE-2026-95271 CVSS 7.3 | A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetecti… |
| CVE-2026-95270 | CVE-2026-95270 CVSS 3.7 | A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.… |
| CVE-2026-9527 | CVE-2026-9527 CVSS 4.3 | A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This ma… |
| CVE-2026-95265 | CVE-2026-95265 CVSS 7.5 | Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopba… |
| CVE-2026-95264 | CVE-2026-95264 CVSS 6.5 | Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP… |
| CVE-2026-95263 | CVE-2026-95263 CVSS 7.2 | Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password o… |
| CVE-2026-9526 | CVE-2026-9526 CVSS 7.3 | A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipula… |
| CVE-2026-9525 | CVE-2026-9525 CVSS 7.3 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation … |
| CVE-2026-9524 | CVE-2026-9524 CVSS 6.3 | A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing… |
| CVE-2026-9523 | CVE-2026-9523 CVSS 7.3 | A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an… |
| CVE-2026-9522 | CVE-2026-9522 CVSS 5.4devolutions | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative pr… |
| CVE-2026-95210 | CVE-2026-95210 CVSS 9.1 | Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions. |
| CVE-2026-9521 | CVE-2026-9521 CVSS 7.3 | A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_… |
| CVE-2026-95209 | CVE-2026-95209 CVSS 7.5 | An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS). |
| CVE-2026-95208 | CVE-2026-95208 CVSS 7.5 | An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via pr… |
| CVE-2026-9520 | CVE-2026-9520 CVSS 4.3 | A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/a… |
| CVE-2026-9519 | CVE-2026-9519 CVSS 4.3 | A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/… |
| CVE-2026-95184 | CVE-2026-95184 CVSS 7.5 | Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS… |
| CVE-2026-9518 | CVE-2026-9518 CVSS 4.3 | A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php… |
| CVE-2026-9517 | CVE-2026-9517 CVSS 7.3 | A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/a… |
| CVE-2026-95166 | CVE-2026-95166 CVSS 5.4 | In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload. |
| CVE-2026-95165 | CVE-2026-95165 CVSS 6.1 | Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field. |
| CVE-2026-9516 | CVE-2026-9516 CVSS 7.5rurban | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-… |
| CVE-2026-95153 | CVE-2026-95153 CVSS 4.9 | An issue in Bludit CMS 3.22.0 allows a remote attacker to obtain sensitive information via the /admin/ajax/clippy and /admin/ajax/save-as-draft endpoints |
| CVE-2026-9515 | CVE-2026-9515 CVSS 6.3 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the com… |
| CVE-2026-95140 | CVE-2026-95140 CVSS 7.5 | kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints acc… |
| CVE-2026-9514 | CVE-2026-9514 CVSS 6.3 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the comp… |
| CVE-2026-95137 | CVE-2026-95137 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was … |
| CVE-2026-9513 | CVE-2026-9513 CVSS 6.3 | A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the componen… |
| CVE-2026-95125 | CVE-2026-95125 | libming through 0.4.8 contains a heap buffer overflow in r_readc() in src/blocks/fromswf.c. A crafted SWF file with a malformed or truncated RECT header can ca… |
| CVE-2026-9512 | CVE-2026-9512 CVSS 6.3 | A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of … |
| CVE-2026-95116 | CVE-2026-95116 | An issue in libming through 0.4.8 allows a remote attacker to cause a denial of service via the readtag_file() in src/blocks/fromswf.c. |
| CVE-2026-95112 | CVE-2026-95112 CVSS 6.5 | When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, givin… |
| CVE-2026-9511 | CVE-2026-9511 CVSS 6.3 | A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Settin… |
| CVE-2026-95106 | CVE-2026-95106 CVSS 9.1 | Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject. Gitea's web views resolved such a path to… |
| CVE-2026-95105 | CVE-2026-95105 | Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with wri… |
| CVE-2026-95104 | CVE-2026-95104 CVSS 7.5 | Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condit… |
| CVE-2026-95102 | CVE-2026-95102 CVSS 9.4 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weaknes… |