91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,251–2,300 of 91,785 · page 46 of 1836

IDTitleSummary
CVE-2026-9398CVE-2026-9398
CVSS 3.1
A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown part of the component BLE/WiFi. Such manip…
CVE-2026-93979CVE-2026-93979
CVSS 7.3
A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing…
CVE-2026-93978CVE-2026-93978
CVSS 7.3
A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. …
CVE-2026-93977CVE-2026-93977
CVSS 3.5
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-…
CVE-2026-93976CVE-2026-93976
CVSS 2.4
A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the a…
CVE-2026-93975CVE-2026-93975
CVSS 2.4
A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component Us…
CVE-2026-93974CVE-2026-93974
CVSS 7.3
A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/data…
CVE-2026-93973CVE-2026-93973
CVSS 7.3
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admin…
CVE-2026-93972CVE-2026-93972
CVSS 7.3
A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /re…
CVE-2026-93971CVE-2026-93971
CVSS 5.3
A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation cause…
CVE-2026-93970CVE-2026-93970
CVSS 7.3
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the c…
CVE-2026-9397CVE-2026-9397
CVSS 8.1
A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Upda…
CVE-2026-93969CVE-2026-93969
CVSS 7.3
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. Th…
CVE-2026-93968CVE-2026-93968
CVSS 3.8
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSer…
CVE-2026-93967CVE-2026-93967
CVSS 5.5
A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the…
CVE-2026-93966CVE-2026-93966
CVSS 4.7
A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backen…
CVE-2026-93965CVE-2026-93965
CVSS 6.6
A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO…
CVE-2026-93964CVE-2026-93964
CVSS 5.3
A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/…
CVE-2026-93963CVE-2026-93963
CVSS 6.3
A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/control…
CVE-2026-93962CVE-2026-93962
CVSS 8.3
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/rece…
CVE-2026-93961CVE-2026-93961
CVSS 5.3
A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/u…
CVE-2026-93960CVE-2026-93960
CVSS 4.3
A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of th…
CVE-2026-9396CVE-2026-9396
CVSS 3.7
A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is an unknown functionality of the compone…
CVE-2026-93959CVE-2026-93959
CVSS 7.3
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admi…
CVE-2026-93958CVE-2026-93958
CVSS 9.1
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipu…
CVE-2026-93957CVE-2026-93957
CVSS 4.3
A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php …
CVE-2026-93956CVE-2026-93956
CVSS 3.5
A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php …
CVE-2026-93955CVE-2026-93955
CVSS 4.3
A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file back…
CVE-2026-93954CVE-2026-93954
CVSS 4.3
A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the fi…
CVE-2026-93952Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
KEVCVSS 10.0Arista
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal …
CVE-2026-9395CVE-2026-9395
CVSS 3.5
A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation lea…
CVE-2026-9394CVE-2026-9394
CVSS 3.1
A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler…
CVE-2026-9393CVE-2026-9393
CVSS 8.8
A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a manipulation of …
CVE-2026-93928CVE-2026-93928
CVSS 7.3
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. T…
CVE-2026-93926CVE-2026-93926Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. Th…
CVE-2026-93925CVE-2026-93925Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before…
CVE-2026-93923CVE-2026-93923
CVSS 8.8
SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers ca…
CVE-2026-93922CVE-2026-93922
CVSS 8.8
SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron …
CVE-2026-93921CVE-2026-93921
CVSS 4.3
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metada…
CVE-2026-93908CVE-2026-93908
CVSS 6.4
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' p…
CVE-2026-93903CVE-2026-93903LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
CVE-2026-93901CVE-2026-93901
CVSS 7.3
The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlo…
CVE-2026-9390CVE-2026-9390
CVSS 9.1xml\
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concate…
CVE-2026-93899CVE-2026-93899
CVSS 6.5
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Messag…
CVE-2026-93897CVE-2026-93897
CVSS 6.4
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-ty…
CVE-2026-93896CVE-2026-93896
CVSS 6.1
The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the d…
CVE-2026-93894CVE-2026-93894In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a r…
CVE-2026-9389CVE-2026-9389
CVSS 8.8
A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argum…
CVE-2026-93889CVE-2026-93889
CVSS 7.2
The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versio…
CVE-2026-93884CVE-2026-93884Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this cand…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.