91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,101–2,150 of 91,785 · page 43 of 1836

IDTitleSummary
CVE-2026-94181CVE-2026-94181
CVSS 7.4
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers request…
CVE-2026-94180CVE-2026-94180
CVSS 4.3
Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanc…
CVE-2026-9418CVE-2026-9418
CVSS 4.3
A flaw has been found in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /changepassemp.ph…
CVE-2026-94179CVE-2026-94179
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.
CVE-2026-94178CVE-2026-94178
CVSS 7.5
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
CVE-2026-94177CVE-2026-94177
CVSS 8.5
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
CVE-2026-94176CVE-2026-94176
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
CVE-2026-94174CVE-2026-94174
CVSS 7.6
Administrator SQL Injection in Email Log <= 2.63 versions.
CVE-2026-94173CVE-2026-94173
CVSS 5.4
Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.
CVE-2026-94171CVE-2026-94171
CVSS 7.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY woo-multi-currency allows DOM-Based XSS.…
CVE-2026-9417CVE-2026-9417
CVSS 4.3
A vulnerability was detected in code-projects Employee Management System 1.0. Affected is an unknown function of the file /myprofileup.php. Performing a manipu…
CVE-2026-94168CVE-2026-94168
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
CVE-2026-9416CVE-2026-9416
CVSS 4.3
A security vulnerability has been detected in code-projects Employee Management System 1.0. This impacts an unknown function of the file /myprofile.php. Such m…
CVE-2026-94154CVE-2026-94154
CVSS 6.1
The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due to…
CVE-2026-94152CVE-2026-94152
CVSS 4.3
A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the compone…
CVE-2026-94151CVE-2026-94151
CVSS 5.3
A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the compone…
CVE-2026-94150CVE-2026-94150
CVSS 2.4
A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the compon…
CVE-2026-9415CVE-2026-9415
CVSS 4.3
A weakness has been identified in code-projects Employee Management System 1.0. This affects an unknown function of the file /eloginwel.php. This manipulation …
CVE-2026-94149CVE-2026-94149
CVSS 4.3
A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of …
CVE-2026-94148CVE-2026-94148
CVSS 5.3
A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the compone…
CVE-2026-94146CVE-2026-94146
CVSS 8.8
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL …
CVE-2026-94145CVE-2026-94145
CVSS 3.5
A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/jo…
CVE-2026-94144CVE-2026-94144
CVSS 7.3
A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component OR…
CVE-2026-94143CVE-2026-94143
CVSS 7.3
A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the comp…
CVE-2026-94142CVE-2026-94142
CVSS 8.8
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of th…
CVE-2026-9414CVE-2026-9414
CVSS 3.5
A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing…
CVE-2026-94139CVE-2026-94139
CVSS 7.4
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_ord…
CVE-2026-94138CVE-2026-94138
CVSS 6.6
A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /se…
CVE-2026-94137CVE-2026-94137
CVSS 3.3
A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the compon…
CVE-2026-94132CVE-2026-94132Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of i…
CVE-2026-94131CVE-2026-94131Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a …
CVE-2026-94130CVE-2026-94130Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functio…
CVE-2026-9413CVE-2026-9413
CVSS 4.3
A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. …
CVE-2026-94129CVE-2026-94129
CVSS 8.8
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the com…
CVE-2026-94128CVE-2026-94128
CVSS 8.8
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component…
CVE-2026-94127F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
KEVCVSS 9.8F5
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerabilit…
CVE-2026-94124CVE-2026-94124
CVSS 8.5
Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.
CVE-2026-94123CVE-2026-94123
CVSS 7.5
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
CVE-2026-94122CVE-2026-94122
CVSS 7.2
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
CVE-2026-94121CVE-2026-94121
CVSS 8.8
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
CVE-2026-94120CVE-2026-94120
CVSS 7.5
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-9412CVE-2026-9412
CVSS 6.3
A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a ma…
CVE-2026-94118CVE-2026-94118
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
CVE-2026-94117CVE-2026-94117
CVSS 7.6
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blin…
CVE-2026-94115CVE-2026-94115
CVSS 8.5
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
CVE-2026-94114CVE-2026-94114
CVSS 5.9
Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, a…
CVE-2026-94113CVE-2026-94113
CVSS 6.5
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to…
CVE-2026-94112CVE-2026-94112
CVSS 6.8
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Att…
CVE-2026-94111CVE-2026-94111
CVSS 6.6
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-exte…
CVE-2026-94110CVE-2026-94110
CVSS 7.3
A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the compo…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.