91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,901–1,950 of 91,785 · page 39 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-94604 | CVE-2026-94604 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-9460 | CVE-2026-9460 CVSS 8.8 | A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the … |
| CVE-2026-94594 | CVE-2026-94594 CVSS 4.0 | Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access … |
| CVE-2026-94593 | CVE-2026-94593 CVSS 7.8 | Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the ho… |
| CVE-2026-94592 | CVE-2026-94592 CVSS 8.4 | Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generat… |
| CVE-2026-94591 | CVE-2026-94591 CVSS 8.4 | Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled.… |
| CVE-2026-9459 | CVE-2026-9459 CVSS 8.8 | A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Perfo… |
| CVE-2026-94588 | CVE-2026-94588 CVSS 4.4 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-su… |
| CVE-2026-94587 | CVE-2026-94587 | A buffer overflow vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric O… |
| CVE-2026-94586 | CVE-2026-94586 | A command injection vulnerability exists in the WebTools administrative interface handling configuration download or file transfer operations of Brocade Fabric… |
| CVE-2026-94585 | CVE-2026-94585 | An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An un… |
| CVE-2026-94584 | CVE-2026-94584 | A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. When handling user authentica… |
| CVE-2026-94583 | CVE-2026-94583 | A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handli… |
| CVE-2026-94582 | CVE-2026-94582 | A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol c… |
| CVE-2026-94581 | CVE-2026-94581 | An OS command injection vulnerability exists in the REST API management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1 allow… |
| CVE-2026-94580 | CVE-2026-94580 | An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS version… |
| CVE-2026-9458 | CVE-2026-9458 CVSS 9.8 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the … |
| CVE-2026-94579 | CVE-2026-94579 | An OS command injection vulnerability exists in the PAM (Pluggable Authentication Module) session cleanup routines during SSH session termination on Brocade Fa… |
| CVE-2026-94578 | CVE-2026-94578 | Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration fr… |
| CVE-2026-94577 | CVE-2026-94577 | A privilege escalation vulnerability exists in the internal Command-Line Interface (CLI) authorization handling mechanism of Brocade Fabric OS versions before … |
| CVE-2026-94576 | CVE-2026-94576 | An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.… |
| CVE-2026-94575 | CVE-2026-94575 | A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Ba… |
| CVE-2026-94574 | CVE-2026-94574 CVSS 7.8 | A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys… |
| CVE-2026-94573 | CVE-2026-94573 CVSS 7.2 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and i… |
| CVE-2026-94572 | CVE-2026-94572 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is w… |
| CVE-2026-94571 | CVE-2026-94571 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The… |
| CVE-2026-94570 | CVE-2026-94570 CVSS 5.9 | SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthentica… |
| CVE-2026-9457 | CVE-2026-9457 CVSS 9.8 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cg… |
| CVE-2026-9456 | CVE-2026-9456 CVSS 9.8 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web… |
| CVE-2026-9455 | CVE-2026-9455 CVSS 9.8 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of t… |
| CVE-2026-94545 | CVE-2026-94545 | Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values befo… |
| CVE-2026-94544 | CVE-2026-94544 CVSS 4.2vercel | Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without se… |
| CVE-2026-94543 | CVE-2026-94543 CVSS 5.3vercel | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router wi… |
| CVE-2026-94541 | CVE-2026-94541 CVSS 9.8 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is d… |
| CVE-2026-94540 | CVE-2026-94540 CVSS 7.7 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persis… |
| CVE-2026-9454 | CVE-2026-9454 CVSS 9.8 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi… |
| CVE-2026-94539 | CVE-2026-94539 CVSS 6.5 | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' para… |
| CVE-2026-94536 | CVE-2026-94536 CVSS 4.3 | lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employe… |
| CVE-2026-94535 | CVE-2026-94535 CVSS 7.1 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' … |
| CVE-2026-94534 | CVE-2026-94534 CVSS 7.1 | lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify … |
| CVE-2026-94533 | CVE-2026-94533 CVSS 6.5 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachme… |
| CVE-2026-94532 | CVE-2026-94532 CVSS 6.5 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user… |
| CVE-2026-9453 | CVE-2026-9453 CVSS 7.3 | A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/applicati… |
| CVE-2026-9452 | CVE-2026-9452 CVSS 7.3 | A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecT… |
| CVE-2026-94510 | CVE-2026-94510 CVSS 9.9 | Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-9451 | CVE-2026-9451 CVSS 6.3 | A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process… |
| CVE-2026-94505 | CVE-2026-94505 CVSS 8.1 | The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ… |
| CVE-2026-94504 | CVE-2026-94504 CVSS 7.2 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break … |
| CVE-2026-94501 | CVE-2026-94501 CVSS 8.8 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or dele… |
| CVE-2026-94500 | CVE-2026-94500 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. |