91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,151–2,200 of 91,785 · page 44 of 1836

IDTitleSummary
CVE-2026-9411CVE-2026-9411
CVSS 6.3
A vulnerability was found in SourceCodester Indian Invoicing System 1.0. This issue affects some unknown processing of the file /Invoicing/IGST_Invoice.php of …
CVE-2026-94109CVE-2026-94109
CVSS 8.0
openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows…
CVE-2026-94108CVE-2026-94108
CVSS 6.5
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on…
CVE-2026-94107CVE-2026-94107
CVSS 8.1
NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(m…
CVE-2026-94106CVE-2026-94106
CVSS 8.8
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft…
CVE-2026-94105CVE-2026-94105
CVSS 5.3
NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to…
CVE-2026-94104CVE-2026-94104
CVSS 8.8
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new file…
CVE-2026-94103CVE-2026-94103
CVSS 4.7
A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend…
CVE-2026-94102CVE-2026-94102
CVSS 4.3
A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulati…
CVE-2026-94101CVE-2026-94101
CVSS 9.9
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/…
CVE-2026-94100CVE-2026-94100
CVSS 9.9
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the componen…
CVE-2026-9410CVE-2026-9410
CVSS 4.3
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file…
CVE-2026-94099CVE-2026-94099
CVSS 9.9
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component …
CVE-2026-94098CVE-2026-94098
CVSS 9.1
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component…
CVE-2026-94097CVE-2026-94097
CVSS 10.0
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI …
CVE-2026-94096CVE-2026-94096
CVSS 9.9
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the…
CVE-2026-94095CVE-2026-94095
CVSS 9.9
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_t…
CVE-2026-94094CVE-2026-94094
CVSS 4.3
A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the comp…
CVE-2026-94093CVE-2026-94093
CVSS 6.3
A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of …
CVE-2026-94092CVE-2026-94092
CVSS 5.5
A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of t…
CVE-2026-94091CVE-2026-94091
CVSS 5.5
A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Lo…
CVE-2026-94090CVE-2026-94090
CVSS 6.3
A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the compo…
CVE-2026-9409CVE-2026-9409
CVSS 4.3
A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the compon…
CVE-2026-94089CVE-2026-94089
CVSS 10.0
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authen…
CVE-2026-94084CVE-2026-94084
CVSS 9.4oisf
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a trans…
CVE-2026-94083CVE-2026-94083
CVSS 9.4oisf
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual sta…
CVE-2026-94082CVE-2026-94082
CVSS 7.6
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-94081CVE-2026-94081
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94080CVE-2026-94080
CVSS 5.3
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
CVE-2026-9408CVE-2026-9408
CVSS 9.8
A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cg…
CVE-2026-94079CVE-2026-94079
CVSS 5.3
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
CVE-2026-94078CVE-2026-94078
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94077CVE-2026-94077
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2026-94076CVE-2026-94076
CVSS 8.8
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
CVE-2026-94074CVE-2026-94074
CVSS 6.5
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-9407CVE-2026-9407
CVSS 9.8
A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of the file …
CVE-2026-9406CVE-2026-9406
CVSS 9.8
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component…
CVE-2026-94057CVE-2026-94057
CVSS 4.0exim
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejec…
CVE-2026-94056CVE-2026-94056
CVSS 7.5exim
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
CVE-2026-94055CVE-2026-94055
CVSS 3.7exim
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVE-2026-94054CVE-2026-94054
CVSS 7.0exim
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVE-2026-94053CVE-2026-94053
CVSS 9.1
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is …
CVE-2026-94052CVE-2026-94052
CVSS 9.1
A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authenticatio…
CVE-2026-94051CVE-2026-94051
CVSS 6.3
A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNod…
CVE-2026-94050CVE-2026-94050
CVSS 4.3
A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the compone…
CVE-2026-9405CVE-2026-9405
CVSS 9.8
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the …
CVE-2026-94049CVE-2026-94049
CVSS 4.3
A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of …
CVE-2026-94048CVE-2026-94048
CVSS 6.6
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.p…
CVE-2026-94047CVE-2026-94047
CVSS 6.3
A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function importTemplate of the file src/services/temp…
CVE-2026-94046CVE-2026-94046
CVSS 4.3
A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of t…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.