91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,001–2,050 of 91,785 · page 41 of 1836

IDTitleSummary
CVE-2026-94412CVE-2026-94412
CVSS 8.8
jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's…
CVE-2026-94411CVE-2026-94411
CVSS 8.8
jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbit…
CVE-2026-9441CVE-2026-9441
CVSS 6.3
A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the com…
CVE-2026-94408CVE-2026-94408
CVSS 4.9elastic
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94405CVE-2026-94405
CVSS 5.3
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Downlo…
CVE-2026-94404CVE-2026-94404MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving t…
CVE-2026-94403CVE-2026-94403
CVSS 8.8
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. …
CVE-2026-94401CVE-2026-94401MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importi…
CVE-2026-94400CVE-2026-94400
CVSS 6.5elastic
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-9440CVE-2026-9440
CVSS 6.3
A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the compon…
CVE-2026-94399CVE-2026-94399
CVSS 6.5elastic
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94398CVE-2026-94398
CVSS 6.5elastic
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94397CVE-2026-94397
CVSS 6.5elastic
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94396CVE-2026-94396
CVSS 6.5elastic
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94394CVE-2026-94394When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whe…
CVE-2026-94393CVE-2026-94393When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actual…
CVE-2026-94391CVE-2026-94391
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
CVE-2026-94390CVE-2026-94390
CVSS 7.2
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
CVE-2026-9439CVE-2026-9439
CVSS 6.3
A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interf…
CVE-2026-94389CVE-2026-94389
CVSS 9.0
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
CVE-2026-94387CVE-2026-94387
CVSS 5.4
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered…
CVE-2026-94384CVE-2026-94384
CVSS 8.1
Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected fun…
CVE-2026-94383CVE-2026-94383The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied w…
CVE-2026-94382CVE-2026-94382
CVSS 4.2
Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authent…
CVE-2026-94381CVE-2026-94381MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view infor…
CVE-2026-9438CVE-2026-9438
CVSS 5.4
A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file co…
CVE-2026-94379CVE-2026-94379The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code us…
CVE-2026-94378CVE-2026-94378
CVSS 6.4
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' para…
CVE-2026-94376CVE-2026-94376
CVSS 6.4
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via U…
CVE-2026-94374CVE-2026-94374MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the …
CVE-2026-94373CVE-2026-94373MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option…
CVE-2026-94372CVE-2026-94372MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or defa…
CVE-2026-9437CVE-2026-9437
CVSS 6.3
A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlTe…
CVE-2026-94368CVE-2026-94368
CVSS 7.1
A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the serv…
CVE-2026-94367CVE-2026-94367
CVSS 7.2
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can su…
CVE-2026-9436CVE-2026-9436
CVSS 9.8
A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the co…
CVE-2026-9435CVE-2026-9435
CVSS 9.8
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the co…
CVE-2026-9434CVE-2026-9434
CVSS 9.8
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsCfg of the file /cgi-bin/cstecgi.cgi of …
CVE-2026-9433CVE-2026-9433
CVSS 9.8
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of t…
CVE-2026-9432CVE-2026-9432
CVSS 9.8
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cs…
CVE-2026-9431CVE-2026-9431
CVSS 8.8
A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the function fromPptpUserAdd of the file /goform/PptpUserAdd. The manipulation of the…
CVE-2026-94301CVE-2026-94301
CVSS 9.8
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 an…
CVE-2026-9430CVE-2026-9430
CVSS 8.8
A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the function formGstDhcpSetSer of the file /goform/GstDhcpSetSerof. Exec…
CVE-2026-94299CVE-2026-94299
CVSS 6.5
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification reques…
CVE-2026-94298CVE-2026-94298
CVSS 6.2
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using …
CVE-2026-94297CVE-2026-94297
CVSS 2.7
The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before cr…
CVE-2026-94293CVE-2026-94293
CVSS 9.8
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
CVE-2026-9429CVE-2026-9429
CVSS 8.8
A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. Perform…
CVE-2026-94287CVE-2026-94287
CVSS 5.5
A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and mem…
CVE-2026-94286CVE-2026-94286
CVSS 7.1
An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.