91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,801–1,850 of 91,785 · page 37 of 1836

IDTitleSummary
CVE-2026-9509CVE-2026-9509An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of s…
CVE-2026-9508CVE-2026-9508Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when t…
CVE-2026-9507CVE-2026-9507A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the ini…
CVE-2026-9506CVE-2026-9506This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacke…
CVE-2026-9504CVE-2026-9504
CVSS 3.3
A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Util…
CVE-2026-9503CVE-2026-9503
CVSS 3.3
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Ha…
CVE-2026-9502CVE-2026-9502
CVSS 5.3
A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread…
CVE-2026-9501CVE-2026-9501
CVSS 3.3
A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the compon…
CVE-2026-9500CVE-2026-9500
CVSS 5.3
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the compone…
CVE-2026-9499CVE-2026-9499An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NU…
CVE-2026-9498CVE-2026-9498
CVSS 6.3
A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handl…
CVE-2026-9497CVE-2026-9497
CVSS 6.3
A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST…
CVE-2026-9496CVE-2026-9496
CVSS 7.5
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this…
CVE-2026-94954CVE-2026-94954
CVSS 8.8
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable throu…
CVE-2026-94953CVE-2026-94953
CVSS 8.8
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable throu…
CVE-2026-94952CVE-2026-94952
CVSS 9.8
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable throu…
CVE-2026-9495CVE-2026-9495
CVSS 7.3
Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the…
CVE-2026-9494CVE-2026-9494
CVSS 5.5
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credential…
CVE-2026-9493CVE-2026-9493
CVSS 6.5
Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modi…
CVE-2026-9492CVE-2026-9492
CVSS 7.8
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. …
CVE-2026-9491CVE-2026-9491
CVSS 4.3
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensiti…
CVE-2026-9490CVE-2026-9490
CVSS 5.5acer
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerabil…
CVE-2026-9489CVE-2026-9489NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to…
CVE-2026-9487CVE-2026-9487
CVSS 9.1xml\
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the Sign…
CVE-2026-9486CVE-2026-9486
CVSS 4.3
A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-sit…
CVE-2026-9485CVE-2026-9485
CVSS 3.5
A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file student…
CVE-2026-9484CVE-2026-9484
CVSS 6.3
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/remo…
CVE-2026-9483CVE-2026-9483
CVSS 6.3
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipula…
CVE-2026-9482CVE-2026-9482
CVSS 8.8
A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument …
CVE-2026-9481CVE-2026-9481
CVSS 8.8
A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-ur…
CVE-2026-9480CVE-2026-9480
CVSS 8.8
A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of t…
CVE-2026-9479CVE-2026-9479
CVSS 8.8
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manip…
CVE-2026-9478CVE-2026-9478
CVSS 9.8
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the compo…
CVE-2026-9477CVE-2026-9477
CVSS 9.8
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cg…
CVE-2026-9476CVE-2026-9476
CVSS 9.8
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi…
CVE-2026-9475CVE-2026-9475
CVSS 9.8
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the compone…
CVE-2026-9474CVE-2026-9474
CVSS 7.3
A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function co…
CVE-2026-9473CVE-2026-9473
CVSS 6.3
A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generat…
CVE-2026-9472CVE-2026-9472
CVSS 6.3
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_f…
CVE-2026-9471CVE-2026-9471
CVSS 3.5
A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file…
CVE-2026-9470CVE-2026-9470
CVSS 7.3
A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function conf…
CVE-2026-9469CVE-2026-9469
CVSS 7.3
A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown functio…
CVE-2026-94684CVE-2026-94684Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. False positive detection.
CVE-2026-94683CVE-2026-94683
CVSS 8.8
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
CVE-2026-94682CVE-2026-94682
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
CVE-2026-94681CVE-2026-94681
CVSS 5.9
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
CVE-2026-94680CVE-2026-94680
CVSS 6.5
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
CVE-2026-9468CVE-2026-9468
CVSS 6.3
A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the function handleI…
CVE-2026-94679CVE-2026-94679
CVSS 5.4
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
CVE-2026-94678CVE-2026-94678
CVSS 8.8
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.