91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,851–1,900 of 91,785 · page 38 of 1836

IDTitleSummary
CVE-2026-94677CVE-2026-94677
CVSS 7.2
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
CVE-2026-94675CVE-2026-94675
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions.
CVE-2026-94674CVE-2026-94674
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.
CVE-2026-94673CVE-2026-94673
CVSS 5.3
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
CVE-2026-94672CVE-2026-94672
CVSS 4.3
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
CVE-2026-94671CVE-2026-94671
CVSS 6.5
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
CVE-2026-94670CVE-2026-94670
CVSS 7.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects E…
CVE-2026-9467CVE-2026-9467
CVSS 4.3
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulati…
CVE-2026-94669CVE-2026-94669
CVSS 5.3
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Se…
CVE-2026-94662CVE-2026-94662
CVSS 7.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free…
CVE-2026-9466CVE-2026-9466
CVSS 5.3
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateU…
CVE-2026-94658CVE-2026-94658Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to…
CVE-2026-94657CVE-2026-94657Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Use…
CVE-2026-94656CVE-2026-94656Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users…
CVE-2026-94655CVE-2026-94655Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apa…
CVE-2026-94654CVE-2026-94654Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. U…
CVE-2026-94653CVE-2026-94653Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to…
CVE-2026-94652CVE-2026-94652Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users ar…
CVE-2026-94651CVE-2026-94651
CVSS 7.5
improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue a…
CVE-2026-94650CVE-2026-94650Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade …
CVE-2026-9465CVE-2026-9465
CVSS 7.3
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/Get…
CVE-2026-94648CVE-2026-94648Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users…
CVE-2026-94646CVE-2026-94646Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution…
CVE-2026-94645CVE-2026-94645Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. Thi…
CVE-2026-94644CVE-2026-94644Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users …
CVE-2026-94642CVE-2026-94642Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to vers…
CVE-2026-94640CVE-2026-94640
CVSS 7.5
A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of uniqu…
CVE-2026-9464CVE-2026-9464
CVSS 4.7
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of th…
CVE-2026-94639CVE-2026-94639improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindi…
CVE-2026-94638CVE-2026-94638Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users …
CVE-2026-94637CVE-2026-94637Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0…
CVE-2026-94636CVE-2026-94636Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity…
CVE-2026-94635CVE-2026-94635Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This …
CVE-2026-94634CVE-2026-94634Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. …
CVE-2026-94633CVE-2026-94633Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue af…
CVE-2026-9463CVE-2026-9463
CVSS 8.8
A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the a…
CVE-2026-94627CVE-2026-94627
CVSS 7.5vllm
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefi…
CVE-2026-94626CVE-2026-94626
CVSS 7.5vllm
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unb…
CVE-2026-94625CVE-2026-94625
CVSS 5.3vllm
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders th…
CVE-2026-94624CVE-2026-94624
CVSS 7.5vllm
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a pee…
CVE-2026-94623CVE-2026-94623
CVSS 7.5vllm
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block coun…
CVE-2026-94622CVE-2026-94622
CVSS 7.5vllm
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. …
CVE-2026-94620CVE-2026-94620Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones …
CVE-2026-9462CVE-2026-9462
CVSS 8.8
A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnabl…
CVE-2026-94613CVE-2026-94613
CVSS 7.5
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an…
CVE-2026-94612CVE-2026-94612
CVSS 7.4
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validi…
CVE-2026-94611CVE-2026-94611
CVSS 8.1
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account h…
CVE-2026-9461CVE-2026-9461
CVSS 8.8
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of t…
CVE-2026-94609CVE-2026-94609
CVSS 8.8
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group members…
CVE-2026-94606CVE-2026-94606
CVSS 8.9
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.