91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,201–2,250 of 91,785 · page 45 of 1836

IDTitleSummary
CVE-2026-94045CVE-2026-94045
CVSS 3.5
A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java …
CVE-2026-94044CVE-2026-94044
CVSS 7.3
A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file…
CVE-2026-94043CVE-2026-94043
CVSS 5.3
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handle…
CVE-2026-94042CVE-2026-94042
CVSS 6.3
A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query…
CVE-2026-94041CVE-2026-94041
CVSS 6.3
A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some un…
CVE-2026-94040CVE-2026-94040
CVSS 5.3
A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderAction of the file app/(app)/apps/settings/…
CVE-2026-9404CVE-2026-9404
CVSS 9.8
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component …
CVE-2026-94039CVE-2026-94039
CVSS 7.3
A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component…
CVE-2026-94038CVE-2026-94038
CVSS 7.3
A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component D…
CVE-2026-94037CVE-2026-94037
CVSS 4.3
A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the…
CVE-2026-94036CVE-2026-94036
CVSS 8.8
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus…
CVE-2026-94035CVE-2026-94035
CVSS 4.3
A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Execu…
CVE-2026-94034CVE-2026-94034
CVSS 3.5
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/chan…
CVE-2026-94033CVE-2026-94033
CVSS 3.5
A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/ad…
CVE-2026-94032CVE-2026-94032
CVSS 6.3
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of …
CVE-2026-94031CVE-2026-94031
CVSS 6.3
A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the…
CVE-2026-94030CVE-2026-94030
CVSS 3.1
A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_…
CVE-2026-9403CVE-2026-9403
CVSS 8.8
A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the comp…
CVE-2026-94029CVE-2026-94029
CVSS 6.5
Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-hand…
CVE-2026-94028CVE-2026-94028
CVSS 4.3
A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controll…
CVE-2026-9402CVE-2026-9402
CVSS 6.3
A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Reques…
CVE-2026-94016CVE-2026-94016
CVSS 2.4
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_…
CVE-2026-94015CVE-2026-94015
CVSS 7.3
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user…
CVE-2026-9401CVE-2026-9401
CVSS 8.8
A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST…
CVE-2026-94004CVE-2026-94004
CVSS 7.3
A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument…
CVE-2026-94003CVE-2026-94003
CVSS 10.0
A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web…
CVE-2026-94002CVE-2026-94002
CVSS 7.5
Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. …
CVE-2026-94001CVE-2026-94001
CVSS 6.5
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials doe…
CVE-2026-94000CVE-2026-94000
CVSS 6.6
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints …
CVE-2026-9400CVE-2026-9400
CVSS 6.3
A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request…
CVE-2026-93999CVE-2026-93999
CVSS 4.2
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token ref…
CVE-2026-93997CVE-2026-93997
CVSS 7.3
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_s…
CVE-2026-93996CVE-2026-93996
CVSS 6.5
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library fo…
CVE-2026-93995CVE-2026-93995
CVSS 6.5
Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side …
CVE-2026-93994CVE-2026-93994
CVSS 8.1
Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two…
CVE-2026-93993CVE-2026-93993
CVSS 8.8
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Att…
CVE-2026-93992CVE-2026-93992
CVSS 8.1
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction…
CVE-2026-93991CVE-2026-93991
CVSS 7.7
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access re…
CVE-2026-93990CVE-2026-93990
CVSS 7.5
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. …
CVE-2026-9399CVE-2026-9399
CVSS 8.8
A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file /goform/formsetPPPoE of the component P…
CVE-2026-93989CVE-2026-93989
CVSS 3.1vllm
vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). A…
CVE-2026-93988CVE-2026-93988
CVSS 6.5
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read …
CVE-2026-93987CVE-2026-93987
CVSS 3.4
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume…
CVE-2026-93986CVE-2026-93986
CVSS 3.1
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object …
CVE-2026-93985CVE-2026-93985
CVSS 9.9
OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member acc…
CVE-2026-93984CVE-2026-93984
CVSS 5.3
OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only …
CVE-2026-93983CVE-2026-93983
CVSS 5.0
OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply…
CVE-2026-93982CVE-2026-93982
CVSS 3.3
OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attacker…
CVE-2026-93981CVE-2026-93981
CVSS 4.7
hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an …
CVE-2026-93980CVE-2026-93980
CVSS 7.3
A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the c…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.