91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,101–2,150 of 91,785 · page 43 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-94181 | CVE-2026-94181 CVSS 7.4 | An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers request… |
| CVE-2026-94180 | CVE-2026-94180 CVSS 4.3 | Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanc… |
| CVE-2026-9418 | CVE-2026-9418 CVSS 4.3 | A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /changepassemp.ph… |
| CVE-2026-94179 | CVE-2026-94179 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. |
| CVE-2026-94178 | CVE-2026-94178 CVSS 7.5 | Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions. |
| CVE-2026-94177 | CVE-2026-94177 CVSS 8.5 | Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. |
| CVE-2026-94176 | CVE-2026-94176 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. |
| CVE-2026-94174 | CVE-2026-94174 CVSS 7.6 | Administrator SQL Injection in Email Log <= 2.63 versions. |
| CVE-2026-94173 | CVE-2026-94173 CVSS 5.4 | Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions. |
| CVE-2026-94171 | CVE-2026-94171 CVSS 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY woo-multi-currency allows DOM-Based XSS.… |
| CVE-2026-9417 | CVE-2026-9417 CVSS 4.3 | A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the file /myprofileup.php. Performing a manipu… |
| CVE-2026-94168 | CVE-2026-94168 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. |
| CVE-2026-9416 | CVE-2026-9416 CVSS 4.3 | A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown function of the file /myprofile.php. Such m… |
| CVE-2026-94154 | CVE-2026-94154 CVSS 6.1 | The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due to… |
| CVE-2026-94152 | CVE-2026-94152 CVSS 4.3 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the compone… |
| CVE-2026-94151 | CVE-2026-94151 CVSS 5.3 | A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the compone… |
| CVE-2026-94150 | CVE-2026-94150 CVSS 2.4 | A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the compon… |
| CVE-2026-9415 | CVE-2026-9415 CVSS 4.3 | A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the file /eloginwel.php. This manipulation … |
| CVE-2026-94149 | CVE-2026-94149 CVSS 4.3 | A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of … |
| CVE-2026-94148 | CVE-2026-94148 CVSS 5.3 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the compone… |
| CVE-2026-94146 | CVE-2026-94146 CVSS 8.8 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL … |
| CVE-2026-94145 | CVE-2026-94145 CVSS 3.5 | A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/jo… |
| CVE-2026-94144 | CVE-2026-94144 CVSS 7.3 | A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component OR… |
| CVE-2026-94143 | CVE-2026-94143 CVSS 7.3 | A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the comp… |
| CVE-2026-94142 | CVE-2026-94142 CVSS 8.8 | A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of th… |
| CVE-2026-9414 | CVE-2026-9414 CVSS 3.5 | A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing… |
| CVE-2026-94139 | CVE-2026-94139 CVSS 7.4 | A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_ord… |
| CVE-2026-94138 | CVE-2026-94138 CVSS 6.6 | A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /se… |
| CVE-2026-94137 | CVE-2026-94137 CVSS 3.3 | A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the compon… |
| CVE-2026-94132 | CVE-2026-94132 | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of i… |
| CVE-2026-94131 | CVE-2026-94131 | Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a … |
| CVE-2026-94130 | CVE-2026-94130 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functio… |
| CVE-2026-9413 | CVE-2026-9413 CVSS 4.3 | A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. … |
| CVE-2026-94129 | CVE-2026-94129 CVSS 8.8 | A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the com… |
| CVE-2026-94128 | CVE-2026-94128 CVSS 8.8 | A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component… |
| CVE-2026-94127 | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability KEVCVSS 9.8F5 | F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerabilit… |
| CVE-2026-94124 | CVE-2026-94124 CVSS 8.5 | Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. |
| CVE-2026-94123 | CVE-2026-94123 CVSS 7.5 | Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions. |
| CVE-2026-94122 | CVE-2026-94122 CVSS 7.2 | Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. |
| CVE-2026-94121 | CVE-2026-94121 CVSS 8.8 | Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. |
| CVE-2026-94120 | CVE-2026-94120 CVSS 7.5 | Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| CVE-2026-9412 | CVE-2026-9412 CVSS 6.3 | A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a ma… |
| CVE-2026-94118 | CVE-2026-94118 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. |
| CVE-2026-94117 | CVE-2026-94117 CVSS 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blin… |
| CVE-2026-94115 | CVE-2026-94115 CVSS 8.5 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. |
| CVE-2026-94114 | CVE-2026-94114 CVSS 5.9 | Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, a… |
| CVE-2026-94113 | CVE-2026-94113 CVSS 6.5 | Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to… |
| CVE-2026-94112 | CVE-2026-94112 CVSS 6.8 | mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Att… |
| CVE-2026-94111 | CVE-2026-94111 CVSS 6.6 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-exte… |
| CVE-2026-94110 | CVE-2026-94110 CVSS 7.3 | A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the compo… |