91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,301–2,350 of 91,785 · page 47 of 1836

IDTitleSummary
CVE-2026-93882CVE-2026-93882
CVSS 7.5
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up …
CVE-2026-93880CVE-2026-93880
CVSS 6.1
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in a…
CVE-2026-9388CVE-2026-9388
CVSS 9.8
A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of…
CVE-2026-93875CVE-2026-93875
CVSS 7.2
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5…
CVE-2026-93873CVE-2026-93873
CVSS 4.3
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-sub…
CVE-2026-93872CVE-2026-93872
CVSS 7.5
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users w…
CVE-2026-93871CVE-2026-93871
CVSS 5.4
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit perm…
CVE-2026-93870CVE-2026-93870
CVSS 4.3
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated use…
CVE-2026-9387CVE-2026-9387
CVSS 9.8
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi…
CVE-2026-93869CVE-2026-93869
CVSS 6.1
Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression l…
CVE-2026-93868CVE-2026-93868
CVSS 8.1
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approxi…
CVE-2026-93861CVE-2026-93861In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a furthe…
CVE-2026-93860CVE-2026-93860In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any polic…
CVE-2026-9386CVE-2026-9386
CVSS 9.8
A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the compone…
CVE-2026-93858CVE-2026-93858In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH…
CVE-2026-93854CVE-2026-93854In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} …
CVE-2026-93853CVE-2026-93853Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots…
CVE-2026-93852CVE-2026-93852In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an adm…
CVE-2026-9385CVE-2026-9385
CVSS 9.8
A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of th…
CVE-2026-93841CVE-2026-93841
CVSS 3.7vllm
vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset w…
CVE-2026-93840CVE-2026-93840
CVSS 3.7vllm
vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). A…
CVE-2026-9384CVE-2026-9384
CVSS 9.8
A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of …
CVE-2026-93839CVE-2026-93839
CVSS 9.8
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register…
CVE-2026-93838CVE-2026-93838
CVSS 5.9
SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_R…
CVE-2026-93836CVE-2026-93836
CVSS 7.2
The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and in…
CVE-2026-93834CVE-2026-93834
CVSS 8.8
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcr…
CVE-2026-93832CVE-2026-93832
CVSS 4.4
A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.
CVE-2026-93830CVE-2026-93830
CVSS 7.5
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: xgmac2: disable RBUE in default RX interrupt mask Enabling the RX Buffer Una…
CVE-2026-9383CVE-2026-9383
CVSS 7.3
A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulati…
CVE-2026-93829CVE-2026-93829In the Linux kernel, the following vulnerability has been resolved: smb: client: fix races in cifsd thread creation The cifsd demultiplex thread can run and …
CVE-2026-93828CVE-2026-93828In the Linux kernel, the following vulnerability has been resolved: exfat: fix handling of damaged volume in exfat_create_upcase_table() When the size of the…
CVE-2026-93827CVE-2026-93827
CVSS 8.4
In the Linux kernel, the following vulnerability has been resolved: virtio-fs: avoid double-free on failed queue setup virtio_fs_setup_vqs() allocates fs->vq…
CVE-2026-93826CVE-2026-93826
CVSS 7.5
In the Linux kernel, the following vulnerability has been resolved: HID: hidpp: fix potential UAF in hidpp_connect_event() If input_register_device() fails, …
CVE-2026-93825CVE-2026-93825In the Linux kernel, the following vulnerability has been resolved: spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() Prevent NULL p…
CVE-2026-93824CVE-2026-93824In the Linux kernel, the following vulnerability has been resolved: tls: reject the combination of TLS and sockmap TLS and sockmap (BPF psock) integration hi…
CVE-2026-93823CVE-2026-93823In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl amdkfd driv…
CVE-2026-93822CVE-2026-93822In the Linux kernel, the following vulnerability has been resolved: PCI: iproc: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock loc…
CVE-2026-93821CVE-2026-93821In the Linux kernel, the following vulnerability has been resolved: PCI: altera: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lo…
CVE-2026-93820CVE-2026-93820In the Linux kernel, the following vulnerability has been resolved: PCI: rockchip: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock …
CVE-2026-9382CVE-2026-9382
CVSS 8.8
A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Re…
CVE-2026-93819CVE-2026-93819In the Linux kernel, the following vulnerability has been resolved: PCI: mediatek: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock …
CVE-2026-93818CVE-2026-93818In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock…
CVE-2026-93817CVE-2026-93817
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: perf: Fix addr_filter_ranges lifetime Lee Jia Jie reported that since event::addr_filter_…
CVE-2026-93816CVE-2026-93816
CVSS 7.1
In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry name lengths before conversion Inline dentry conversion copi…
CVE-2026-93815CVE-2026-93815In the Linux kernel, the following vulnerability has been resolved: net: au1000: move free_irq out of the close-time spinlocked section au1000_close() calls …
CVE-2026-93814CVE-2026-93814In the Linux kernel, the following vulnerability has been resolved: spi: core: Abort active target transfer on controller suspend When an SPI controller oper…
CVE-2026-93813CVE-2026-93813
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: btrfs: tree-checker: validate INODE_REF's namelen [BUG] A crafted btrfs image can trigger…
CVE-2026-93812CVE-2026-93812In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr ndr_encode_v4_ntacl() alloca…
CVE-2026-93811CVE-2026-93811In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling 1. When ndr_decode_v…
CVE-2026-93810CVE-2026-93810
CVSS 7.0
In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix double fput Fix a double fput() in error handling in cachefiles_create_tm…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.