91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,051–2,100 of 91,785 · page 42 of 1836

IDTitleSummary
CVE-2026-94285CVE-2026-94285
CVSS 5.1
An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.
CVE-2026-94284CVE-2026-94284
CVSS 5.5
An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attac…
CVE-2026-94283CVE-2026-94283
CVSS 6.5
An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash att…
CVE-2026-94282CVE-2026-94282
CVSS 5.6
An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X clien…
CVE-2026-94281CVE-2026-94281
CVSS 6.5
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
CVE-2026-9428CVE-2026-9428
CVSS 8.8
A vulnerability has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromPPTPUserSetting of the file /goform/PPTPUserSetting. Such manipulatio…
CVE-2026-94278CVE-2026-94278
CVSS 5.5
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any use…
CVE-2026-94277CVE-2026-94277MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any H…
CVE-2026-94276CVE-2026-94276Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that …
CVE-2026-94275CVE-2026-94275
CVSS 5.3
The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenti…
CVE-2026-94274CVE-2026-94274
CVSS 5.3
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still…
CVE-2026-94271CVE-2026-94271
CVSS 5.3
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkou…
CVE-2026-94270CVE-2026-94270
CVSS 5.3
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verif…
CVE-2026-9427CVE-2026-9427
CVSS 8.8
A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component webs. This ma…
CVE-2026-94269CVE-2026-94269Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protec…
CVE-2026-9426CVE-2026-9426
CVSS 8.8
A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Ann…
CVE-2026-94258CVE-2026-94258
CVSS 2.7
The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored…
CVE-2026-94251CVE-2026-94251
CVSS 6.5apache
A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling …
CVE-2026-94250CVE-2026-94250Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway …
CVE-2026-9425CVE-2026-9425
CVSS 8.8
A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manip…
CVE-2026-94246CVE-2026-94246
CVSS 6.3
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user m…
CVE-2026-94245CVE-2026-94245
CVSS 6.5
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allo…
CVE-2026-94244CVE-2026-94244
CVSS 4.3
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain…
CVE-2026-94243CVE-2026-94243
CVSS 7.3apache
A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: bef…
CVE-2026-9424CVE-2026-9424
CVSS 6.3
A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Conte…
CVE-2026-94239CVE-2026-94239
CVSS 6.8
The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, al…
CVE-2026-94238CVE-2026-94238
CVSS 6.8
The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Tran…
CVE-2026-9423CVE-2026-9423
CVSS 4.7
A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the component POST Request Handler. Perform…
CVE-2026-94220CVE-2026-94220Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted…
CVE-2026-9422CVE-2026-9422
CVSS 7.3
A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler.…
CVE-2026-94218CVE-2026-94218
CVSS 3.1
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enfor…
CVE-2026-94217CVE-2026-94217
CVSS 3.5
A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission t…
CVE-2026-94216CVE-2026-94216
CVSS 4.3
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /autho…
CVE-2026-94215CVE-2026-94215
CVSS 5.5
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request…
CVE-2026-94214CVE-2026-94214
CVSS 4.3
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Lo…
CVE-2026-94213CVE-2026-94213
CVSS 4.9
A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy ev…
CVE-2026-94212CVE-2026-94212Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route prot…
CVE-2026-94211CVE-2026-94211
CVSS 2.4
A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/…
CVE-2026-94210CVE-2026-94210
CVSS 3.5
A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Ticke…
CVE-2026-9421CVE-2026-9421
CVSS 7.3
A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File …
CVE-2026-94206CVE-2026-94206Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds …
CVE-2026-94205CVE-2026-94205
CVSS 9.8
Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_…
CVE-2026-94204CVE-2026-94204
CVSS 7.5
The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored obj…
CVE-2026-94201CVE-2026-94201Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced th…
CVE-2026-9420CVE-2026-9420
CVSS 6.3
A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation re…
CVE-2026-94194CVE-2026-94194Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchr…
CVE-2026-9419CVE-2026-9419
CVSS 4.3
A vulnerability has been found in code-projects Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /empproject.ph…
CVE-2026-94185CVE-2026-94185
CVSS 5.5
nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto th…
CVE-2026-94184CVE-2026-94184
CVSS 5.3
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication …
CVE-2026-94183CVE-2026-94183
CVSS 7.4
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the bac…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.