91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,951–2,000 of 91,785 · page 40 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9450 | CVE-2026-9450 CVSS 6.3 | A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation… |
| CVE-2026-94499 | CVE-2026-94499 CVSS 7.1 | Subscriber Broken Access Control in FormGent <= 1.12.2 versions. |
| CVE-2026-94498 | CVE-2026-94498 CVSS 6.5 | Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. |
| CVE-2026-94497 | CVE-2026-94497 CVSS 8.3 | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read,… |
| CVE-2026-94496 | CVE-2026-94496 CVSS 8.3 | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete ro… |
| CVE-2026-94495 | CVE-2026-94495 CVSS 7.1 | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system c… |
| CVE-2026-94494 | CVE-2026-94494 CVSS 5.0 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info end… |
| CVE-2026-94493 | CVE-2026-94493 CVSS 10.0 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebS… |
| CVE-2026-94492 | CVE-2026-94492 CVSS 6.3 | A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit o… |
| CVE-2026-94491 | CVE-2026-94491 CVSS 7.3 | A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument… |
| CVE-2026-94490 | CVE-2026-94490 CVSS 4.7 | A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system… |
| CVE-2026-9449 | CVE-2026-9449 CVSS 6.3 | A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulati… |
| CVE-2026-94489 | CVE-2026-94489 CVSS 4.3 | A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of th… |
| CVE-2026-94488 | CVE-2026-94488 CVSS 8.2 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_ht… |
| CVE-2026-94487 | CVE-2026-94487 CVSS 8.1 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. |
| CVE-2026-94486 | CVE-2026-94486 CVSS 5.4vercel | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protoc… |
| CVE-2026-94485 | CVE-2026-94485 CVSS 5.3vercel | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Prot… |
| CVE-2026-94484 | CVE-2026-94484 CVSS 4.8vercel | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and … |
| CVE-2026-94483 | CVE-2026-94483 CVSS 6.5vercel | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resoluti… |
| CVE-2026-9448 | CVE-2026-9448 CVSS 4.3 | A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the file /applyleave.php. Executing a manip… |
| CVE-2026-9447 | CVE-2026-9447 CVSS 7.3 | A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Perf… |
| CVE-2026-94462 | CVE-2026-94462 CVSS 7.1 | Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::… |
| CVE-2026-94461 | CVE-2026-94461 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. |
| CVE-2026-9446 | CVE-2026-9446 CVSS 4.7 | A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_custo… |
| CVE-2026-94457 | CVE-2026-94457 CVSS 4.8 | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. |
| CVE-2026-94456 | CVE-2026-94456 CVSS 9.1 | Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access to… |
| CVE-2026-94455 | CVE-2026-94455 CVSS 7.1 | An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only … |
| CVE-2026-94450 | CVE-2026-94450 CVSS 7.5 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of servic… |
| CVE-2026-9445 | CVE-2026-9445 CVSS 6.3 | A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component… |
| CVE-2026-94449 | CVE-2026-94449 CVSS 7.5 | A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. T… |
| CVE-2026-94448 | CVE-2026-94448 | When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now e… |
| CVE-2026-94447 | CVE-2026-94447 | Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the us… |
| CVE-2026-94445 | CVE-2026-94445 CVSS 8.8 | A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the… |
| CVE-2026-94444 | CVE-2026-94444 | Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to c… |
| CVE-2026-94440 | CVE-2026-94440 | Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 40… |
| CVE-2026-9444 | CVE-2026-9444 CVSS 4.7 | A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php… |
| CVE-2026-94439 | CVE-2026-94439 | When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to … |
| CVE-2026-94432 | CVE-2026-94432 CVSS 5.3 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in vers… |
| CVE-2026-9443 | CVE-2026-9443 CVSS 8.8 | A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of… |
| CVE-2026-94426 | CVE-2026-94426 CVSS 3.5 | A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of t… |
| CVE-2026-94425 | CVE-2026-94425 CVSS 8.8 | A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of … |
| CVE-2026-94424 | CVE-2026-94424 CVSS 8.8 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of t… |
| CVE-2026-94422 | CVE-2026-94422 CVSS 8.8 | An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-B… |
| CVE-2026-9442 | CVE-2026-9442 CVSS 8.8 | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component P… |
| CVE-2026-94419 | CVE-2026-94419 CVSS 5.4wolfssl | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} in… |
| CVE-2026-94418 | CVE-2026-94418 CVSS 7.5wolfssl | Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges th… |
| CVE-2026-94417 | CVE-2026-94417 CVSS 5.3wolfssl | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certifica… |
| CVE-2026-94416 | CVE-2026-94416 CVSS 6.8 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new servi… |
| CVE-2026-94414 | CVE-2026-94414 CVSS 5.4 | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-perm… |
| CVE-2026-94413 | CVE-2026-94413 CVSS 6.5 | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any u… |