91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,901–1,950 of 91,785 · page 39 of 1836

IDTitleSummary
CVE-2026-94604CVE-2026-94604Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-9460CVE-2026-9460
CVSS 8.8
A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the …
CVE-2026-94594CVE-2026-94594
CVSS 4.0
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access …
CVE-2026-94593CVE-2026-94593
CVSS 7.8
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the ho…
CVE-2026-94592CVE-2026-94592
CVSS 8.4
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generat…
CVE-2026-94591CVE-2026-94591
CVSS 8.4
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled.…
CVE-2026-9459CVE-2026-9459
CVSS 8.8
A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Perfo…
CVE-2026-94588CVE-2026-94588
CVSS 4.4
In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-su…
CVE-2026-94587CVE-2026-94587A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric O…
CVE-2026-94586CVE-2026-94586A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric…
CVE-2026-94585CVE-2026-94585An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An un…
CVE-2026-94584CVE-2026-94584A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. When handling user authentica…
CVE-2026-94583CVE-2026-94583A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handli…
CVE-2026-94582CVE-2026-94582A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol c…
CVE-2026-94581CVE-2026-94581An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allow…
CVE-2026-94580CVE-2026-94580An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS version…
CVE-2026-9458CVE-2026-9458
CVSS 9.8
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the …
CVE-2026-94579CVE-2026-94579An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fa…
CVE-2026-94578CVE-2026-94578Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration fr…
CVE-2026-94577CVE-2026-94577A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before …
CVE-2026-94576CVE-2026-94576An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.…
CVE-2026-94575CVE-2026-94575A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Ba…
CVE-2026-94574CVE-2026-94574
CVSS 7.8
A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys…
CVE-2026-94573CVE-2026-94573
CVSS 7.2
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and i…
CVE-2026-94572CVE-2026-94572In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is w…
CVE-2026-94571CVE-2026-94571In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The…
CVE-2026-94570CVE-2026-94570
CVSS 5.9
SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthentica…
CVE-2026-9457CVE-2026-9457
CVSS 9.8
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cg…
CVE-2026-9456CVE-2026-9456
CVSS 9.8
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web…
CVE-2026-9455CVE-2026-9455
CVSS 9.8
A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of t…
CVE-2026-94545CVE-2026-94545Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values befo…
CVE-2026-94544CVE-2026-94544
CVSS 4.2vercel
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without se…
CVE-2026-94543CVE-2026-94543
CVSS 5.3vercel
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router wi…
CVE-2026-94541CVE-2026-94541
CVSS 9.8
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is d…
CVE-2026-94540CVE-2026-94540
CVSS 7.7
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persis…
CVE-2026-9454CVE-2026-9454
CVSS 9.8
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi…
CVE-2026-94539CVE-2026-94539
CVSS 6.5
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' para…
CVE-2026-94536CVE-2026-94536
CVSS 4.3
lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employe…
CVE-2026-94535CVE-2026-94535
CVSS 7.1
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' …
CVE-2026-94534CVE-2026-94534
CVSS 7.1
lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify …
CVE-2026-94533CVE-2026-94533
CVSS 6.5
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachme…
CVE-2026-94532CVE-2026-94532
CVSS 6.5
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user…
CVE-2026-9453CVE-2026-9453
CVSS 7.3
A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/applicati…
CVE-2026-9452CVE-2026-9452
CVSS 7.3
A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecT…
CVE-2026-94510CVE-2026-94510
CVSS 9.9
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-9451CVE-2026-9451
CVSS 6.3
A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process…
CVE-2026-94505CVE-2026-94505
CVSS 8.1
The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ…
CVE-2026-94504CVE-2026-94504
CVSS 7.2
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break …
CVE-2026-94501CVE-2026-94501
CVSS 8.8
jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or dele…
CVE-2026-94500CVE-2026-94500
CVSS 6.5
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.