91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,151–2,200 of 91,785 · page 44 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9411 | CVE-2026-9411 CVSS 6.3 | A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of … |
| CVE-2026-94109 | CVE-2026-94109 CVSS 8.0 | openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows… |
| CVE-2026-94108 | CVE-2026-94108 CVSS 6.5 | getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on… |
| CVE-2026-94107 | CVE-2026-94107 CVSS 8.1 | NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(m… |
| CVE-2026-94106 | CVE-2026-94106 CVSS 8.8 | getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft… |
| CVE-2026-94105 | CVE-2026-94105 CVSS 5.3 | NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to… |
| CVE-2026-94104 | CVE-2026-94104 CVSS 8.8 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new file… |
| CVE-2026-94103 | CVE-2026-94103 CVSS 4.7 | A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend… |
| CVE-2026-94102 | CVE-2026-94102 CVSS 4.3 | A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulati… |
| CVE-2026-94101 | CVE-2026-94101 CVSS 9.9 | A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/… |
| CVE-2026-94100 | CVE-2026-94100 CVSS 9.9 | A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the componen… |
| CVE-2026-9410 | CVE-2026-9410 CVSS 4.3 | A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file… |
| CVE-2026-94099 | CVE-2026-94099 CVSS 9.9 | A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component … |
| CVE-2026-94098 | CVE-2026-94098 CVSS 9.1 | A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component… |
| CVE-2026-94097 | CVE-2026-94097 CVSS 10.0 | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI … |
| CVE-2026-94096 | CVE-2026-94096 CVSS 9.9 | A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the… |
| CVE-2026-94095 | CVE-2026-94095 CVSS 9.9 | A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_t… |
| CVE-2026-94094 | CVE-2026-94094 CVSS 4.3 | A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the comp… |
| CVE-2026-94093 | CVE-2026-94093 CVSS 6.3 | A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of … |
| CVE-2026-94092 | CVE-2026-94092 CVSS 5.5 | A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of t… |
| CVE-2026-94091 | CVE-2026-94091 CVSS 5.5 | A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Lo… |
| CVE-2026-94090 | CVE-2026-94090 CVSS 6.3 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the compo… |
| CVE-2026-9409 | CVE-2026-9409 CVSS 4.3 | A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the compon… |
| CVE-2026-94089 | CVE-2026-94089 CVSS 10.0 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authen… |
| CVE-2026-94084 | CVE-2026-94084 CVSS 9.4oisf | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a trans… |
| CVE-2026-94083 | CVE-2026-94083 CVSS 9.4oisf | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual sta… |
| CVE-2026-94082 | CVE-2026-94082 CVSS 7.6 | Author SQL Injection in Quiz Cat <= 3.1.1 versions. |
| CVE-2026-94081 | CVE-2026-94081 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions. |
| CVE-2026-94080 | CVE-2026-94080 CVSS 5.3 | Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions. |
| CVE-2026-9408 | CVE-2026-9408 CVSS 9.8 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cg… |
| CVE-2026-94079 | CVE-2026-94079 CVSS 5.3 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. |
| CVE-2026-94078 | CVE-2026-94078 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. |
| CVE-2026-94077 | CVE-2026-94077 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. |
| CVE-2026-94076 | CVE-2026-94076 CVSS 8.8 | Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. |
| CVE-2026-94074 | CVE-2026-94074 CVSS 6.5 | Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. |
| CVE-2026-9407 | CVE-2026-9407 CVSS 9.8 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of the file … |
| CVE-2026-9406 | CVE-2026-9406 CVSS 9.8 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component… |
| CVE-2026-94057 | CVE-2026-94057 CVSS 4.0exim | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejec… |
| CVE-2026-94056 | CVE-2026-94056 CVSS 7.5exim | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. |
| CVE-2026-94055 | CVE-2026-94055 CVSS 3.7exim | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. |
| CVE-2026-94054 | CVE-2026-94054 CVSS 7.0exim | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. |
| CVE-2026-94053 | CVE-2026-94053 CVSS 9.1 | Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is … |
| CVE-2026-94052 | CVE-2026-94052 CVSS 9.1 | A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authenticatio… |
| CVE-2026-94051 | CVE-2026-94051 CVSS 6.3 | A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNod… |
| CVE-2026-94050 | CVE-2026-94050 CVSS 4.3 | A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the compone… |
| CVE-2026-9405 | CVE-2026-9405 CVSS 9.8 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the … |
| CVE-2026-94049 | CVE-2026-94049 CVSS 4.3 | A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of … |
| CVE-2026-94048 | CVE-2026-94048 CVSS 6.6 | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.p… |
| CVE-2026-94047 | CVE-2026-94047 CVSS 6.3 | A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/temp… |
| CVE-2026-94046 | CVE-2026-94046 CVSS 4.3 | A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of t… |