91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,851–1,900 of 91,785 · page 38 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-94677 | CVE-2026-94677 CVSS 7.2 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. |
| CVE-2026-94675 | CVE-2026-94675 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. |
| CVE-2026-94674 | CVE-2026-94674 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. |
| CVE-2026-94673 | CVE-2026-94673 CVSS 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. |
| CVE-2026-94672 | CVE-2026-94672 CVSS 4.3 | Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions. |
| CVE-2026-94671 | CVE-2026-94671 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| CVE-2026-94670 | CVE-2026-94670 CVSS 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects E… |
| CVE-2026-9467 | CVE-2026-9467 CVSS 4.3 | A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulati… |
| CVE-2026-94669 | CVE-2026-94669 CVSS 5.3 | Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Se… |
| CVE-2026-94662 | CVE-2026-94662 CVSS 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free… |
| CVE-2026-9466 | CVE-2026-9466 CVSS 5.3 | A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateU… |
| CVE-2026-94658 | CVE-2026-94658 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to… |
| CVE-2026-94657 | CVE-2026-94657 | Allocation of resources without limits or throttling vulnerability in Apache Thrift JavaME bindings. This issue affects Apache Thrift: before 0.25.0. Use… |
| CVE-2026-94656 | CVE-2026-94656 | Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users… |
| CVE-2026-94655 | CVE-2026-94655 | Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apa… |
| CVE-2026-94654 | CVE-2026-94654 | Loop with unreachable exit condition ('infinite loop') vulnerability in Apache Thrift python bindings. This issue affects Apache Thrift: before 0.25.0. U… |
| CVE-2026-94653 | CVE-2026-94653 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to… |
| CVE-2026-94652 | CVE-2026-94652 | Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users ar… |
| CVE-2026-94651 | CVE-2026-94651 CVSS 7.5 | improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue a… |
| CVE-2026-94650 | CVE-2026-94650 | Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … |
| CVE-2026-9465 | CVE-2026-9465 CVSS 7.3 | A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/Get… |
| CVE-2026-94648 | CVE-2026-94648 | Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users… |
| CVE-2026-94646 | CVE-2026-94646 | Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution… |
| CVE-2026-94645 | CVE-2026-94645 | Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. Thi… |
| CVE-2026-94644 | CVE-2026-94644 | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users … |
| CVE-2026-94642 | CVE-2026-94642 | Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to vers… |
| CVE-2026-94640 | CVE-2026-94640 CVSS 7.5 | A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of uniqu… |
| CVE-2026-9464 | CVE-2026-9464 CVSS 4.7 | A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of th… |
| CVE-2026-94639 | CVE-2026-94639 | improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindi… |
| CVE-2026-94638 | CVE-2026-94638 | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users … |
| CVE-2026-94637 | CVE-2026-94637 | Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache Thrift: before 0.25.0… |
| CVE-2026-94636 | CVE-2026-94636 | Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity… |
| CVE-2026-94635 | CVE-2026-94635 | Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This … |
| CVE-2026-94634 | CVE-2026-94634 | Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings. … |
| CVE-2026-94633 | CVE-2026-94633 | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue af… |
| CVE-2026-9463 | CVE-2026-9463 CVSS 8.8 | A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the a… |
| CVE-2026-94627 | CVE-2026-94627 CVSS 7.5vllm | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefi… |
| CVE-2026-94626 | CVE-2026-94626 CVSS 7.5vllm | vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unb… |
| CVE-2026-94625 | CVE-2026-94625 CVSS 5.3vllm | vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders th… |
| CVE-2026-94624 | CVE-2026-94624 CVSS 7.5vllm | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a pee… |
| CVE-2026-94623 | CVE-2026-94623 CVSS 7.5vllm | vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block coun… |
| CVE-2026-94622 | CVE-2026-94622 CVSS 7.5vllm | vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. … |
| CVE-2026-94620 | CVE-2026-94620 | Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones … |
| CVE-2026-9462 | CVE-2026-9462 CVSS 8.8 | A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnabl… |
| CVE-2026-94613 | CVE-2026-94613 CVSS 7.5 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an… |
| CVE-2026-94612 | CVE-2026-94612 CVSS 7.4 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validi… |
| CVE-2026-94611 | CVE-2026-94611 CVSS 8.1 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account h… |
| CVE-2026-9461 | CVE-2026-9461 CVSS 8.8 | A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of t… |
| CVE-2026-94609 | CVE-2026-94609 CVSS 8.8 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group members… |
| CVE-2026-94606 | CVE-2026-94606 CVSS 8.9 | authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or … |