91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,001–2,050 of 91,785 · page 41 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-94412 | CVE-2026-94412 CVSS 8.8 | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's… |
| CVE-2026-94411 | CVE-2026-94411 CVSS 8.8 | jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbit… |
| CVE-2026-9441 | CVE-2026-9441 CVSS 6.3 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the com… |
| CVE-2026-94408 | CVE-2026-94408 CVSS 4.9elastic | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94405 | CVE-2026-94405 CVSS 5.3 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Downlo… |
| CVE-2026-94404 | CVE-2026-94404 | MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving t… |
| CVE-2026-94403 | CVE-2026-94403 CVSS 8.8 | A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. … |
| CVE-2026-94401 | CVE-2026-94401 | MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importi… |
| CVE-2026-94400 | CVE-2026-94400 CVSS 6.5elastic | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-9440 | CVE-2026-9440 CVSS 6.3 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the compon… |
| CVE-2026-94399 | CVE-2026-94399 CVSS 6.5elastic | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94398 | CVE-2026-94398 CVSS 6.5elastic | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94397 | CVE-2026-94397 CVSS 6.5elastic | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94396 | CVE-2026-94396 CVSS 6.5elastic | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94394 | CVE-2026-94394 | When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whe… |
| CVE-2026-94393 | CVE-2026-94393 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actual… |
| CVE-2026-94391 | CVE-2026-94391 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. |
| CVE-2026-94390 | CVE-2026-94390 CVSS 7.2 | Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. |
| CVE-2026-9439 | CVE-2026-9439 CVSS 6.3 | A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interf… |
| CVE-2026-94389 | CVE-2026-94389 CVSS 9.0 | Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. |
| CVE-2026-94387 | CVE-2026-94387 CVSS 5.4 | Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered… |
| CVE-2026-94384 | CVE-2026-94384 CVSS 8.1 | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected fun… |
| CVE-2026-94383 | CVE-2026-94383 | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied w… |
| CVE-2026-94382 | CVE-2026-94382 CVSS 4.2 | Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authent… |
| CVE-2026-94381 | CVE-2026-94381 | MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view infor… |
| CVE-2026-9438 | CVE-2026-9438 CVSS 5.4 | A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file co… |
| CVE-2026-94379 | CVE-2026-94379 | The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code us… |
| CVE-2026-94378 | CVE-2026-94378 CVSS 6.4 | The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' para… |
| CVE-2026-94376 | CVE-2026-94376 CVSS 6.4 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via U… |
| CVE-2026-94374 | CVE-2026-94374 | MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the … |
| CVE-2026-94373 | CVE-2026-94373 | MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option… |
| CVE-2026-94372 | CVE-2026-94372 | MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or defa… |
| CVE-2026-9437 | CVE-2026-9437 CVSS 6.3 | A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlTe… |
| CVE-2026-94368 | CVE-2026-94368 CVSS 7.1 | A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the serv… |
| CVE-2026-94367 | CVE-2026-94367 CVSS 7.2 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can su… |
| CVE-2026-9436 | CVE-2026-9436 CVSS 9.8 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the co… |
| CVE-2026-9435 | CVE-2026-9435 CVSS 9.8 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the co… |
| CVE-2026-9434 | CVE-2026-9434 CVSS 9.8 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsCfg of the file /cgi-bin/cstecgi.cgi of … |
| CVE-2026-9433 | CVE-2026-9433 CVSS 9.8 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of t… |
| CVE-2026-9432 | CVE-2026-9432 CVSS 9.8 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cs… |
| CVE-2026-9431 | CVE-2026-9431 CVSS 8.8 | A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the function fromPptpUserAdd of the file /goform/PptpUserAdd. The manipulation of the… |
| CVE-2026-94301 | CVE-2026-94301 CVSS 9.8 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 an… |
| CVE-2026-9430 | CVE-2026-9430 CVSS 8.8 | A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the function formGstDhcpSetSer of the file /goform/GstDhcpSetSerof. Exec… |
| CVE-2026-94299 | CVE-2026-94299 CVSS 6.5 | The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification reques… |
| CVE-2026-94298 | CVE-2026-94298 CVSS 6.2 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using … |
| CVE-2026-94297 | CVE-2026-94297 CVSS 2.7 | The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before cr… |
| CVE-2026-94293 | CVE-2026-94293 CVSS 9.8 | An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. |
| CVE-2026-9429 | CVE-2026-9429 CVSS 8.8 | A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. Perform… |
| CVE-2026-94287 | CVE-2026-94287 CVSS 5.5 | A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and mem… |
| CVE-2026-94286 | CVE-2026-94286 CVSS 7.1 | An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients. |