91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,301–2,350 of 91,785 · page 47 of 1836
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93882 | CVE-2026-93882 CVSS 7.5 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … |
| CVE-2026-93880 | CVE-2026-93880 CVSS 6.1 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in a… |
| CVE-2026-9388 | CVE-2026-9388 CVSS 9.8 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of… |
| CVE-2026-93875 | CVE-2026-93875 CVSS 7.2 | The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5… |
| CVE-2026-93873 | CVE-2026-93873 CVSS 4.3 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-sub… |
| CVE-2026-93872 | CVE-2026-93872 CVSS 7.5 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users w… |
| CVE-2026-93871 | CVE-2026-93871 CVSS 5.4 | Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit perm… |
| CVE-2026-93870 | CVE-2026-93870 CVSS 4.3 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated use… |
| CVE-2026-9387 | CVE-2026-9387 CVSS 9.8 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi… |
| CVE-2026-93869 | CVE-2026-93869 CVSS 6.1 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression l… |
| CVE-2026-93868 | CVE-2026-93868 CVSS 8.1 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approxi… |
| CVE-2026-93861 | CVE-2026-93861 | In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a furthe… |
| CVE-2026-93860 | CVE-2026-93860 | In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any polic… |
| CVE-2026-9386 | CVE-2026-9386 CVSS 9.8 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the compone… |
| CVE-2026-93858 | CVE-2026-93858 | In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH… |
| CVE-2026-93854 | CVE-2026-93854 | In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} … |
| CVE-2026-93853 | CVE-2026-93853 | Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots… |
| CVE-2026-93852 | CVE-2026-93852 | In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an adm… |
| CVE-2026-9385 | CVE-2026-9385 CVSS 9.8 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of th… |
| CVE-2026-93841 | CVE-2026-93841 CVSS 3.7vllm | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset w… |
| CVE-2026-93840 | CVE-2026-93840 CVSS 3.7vllm | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). A… |
| CVE-2026-9384 | CVE-2026-9384 CVSS 9.8 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of … |
| CVE-2026-93839 | CVE-2026-93839 CVSS 9.8 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register… |
| CVE-2026-93838 | CVE-2026-93838 CVSS 5.9 | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_R… |
| CVE-2026-93836 | CVE-2026-93836 CVSS 7.2 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and in… |
| CVE-2026-93834 | CVE-2026-93834 CVSS 8.8 | A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcr… |
| CVE-2026-93832 | CVE-2026-93832 CVSS 4.4 | A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps. |
| CVE-2026-93830 | CVE-2026-93830 CVSS 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: xgmac2: disable RBUE in default RX interrupt mask Enabling the RX Buffer Una… |
| CVE-2026-9383 | CVE-2026-9383 CVSS 7.3 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulati… |
| CVE-2026-93829 | CVE-2026-93829 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix races in cifsd thread creation The cifsd demultiplex thread can run and … |
| CVE-2026-93828 | CVE-2026-93828 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix handling of damaged volume in exfat_create_upcase_table() When the size of the… |
| CVE-2026-93827 | CVE-2026-93827 CVSS 8.4 | In the Linux kernel, the following vulnerability has been resolved: virtio-fs: avoid double-free on failed queue setup virtio_fs_setup_vqs() allocates fs->vq… |
| CVE-2026-93826 | CVE-2026-93826 CVSS 7.5 | In the Linux kernel, the following vulnerability has been resolved: HID: hidpp: fix potential UAF in hidpp_connect_event() If input_register_device() fails, … |
| CVE-2026-93825 | CVE-2026-93825 | In the Linux kernel, the following vulnerability has been resolved: spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() Prevent NULL p… |
| CVE-2026-93824 | CVE-2026-93824 | In the Linux kernel, the following vulnerability has been resolved: tls: reject the combination of TLS and sockmap TLS and sockmap (BPF psock) integration hi… |
| CVE-2026-93823 | CVE-2026-93823 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl amdkfd driv… |
| CVE-2026-93822 | CVE-2026-93822 | In the Linux kernel, the following vulnerability has been resolved: PCI: iproc: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock loc… |
| CVE-2026-93821 | CVE-2026-93821 | In the Linux kernel, the following vulnerability has been resolved: PCI: altera: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lo… |
| CVE-2026-93820 | CVE-2026-93820 | In the Linux kernel, the following vulnerability has been resolved: PCI: rockchip: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock … |
| CVE-2026-9382 | CVE-2026-9382 CVSS 8.8 | A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Re… |
| CVE-2026-93819 | CVE-2026-93819 | In the Linux kernel, the following vulnerability has been resolved: PCI: mediatek: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock … |
| CVE-2026-93818 | CVE-2026-93818 | In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock… |
| CVE-2026-93817 | CVE-2026-93817 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix addr_filter_ranges lifetime Lee Jia Jie reported that since event::addr_filter_… |
| CVE-2026-93816 | CVE-2026-93816 CVSS 7.1 | In the Linux kernel, the following vulnerability has been resolved: f2fs: validate inline dentry name lengths before conversion Inline dentry conversion copi… |
| CVE-2026-93815 | CVE-2026-93815 | In the Linux kernel, the following vulnerability has been resolved: net: au1000: move free_irq out of the close-time spinlocked section au1000_close() calls … |
| CVE-2026-93814 | CVE-2026-93814 | In the Linux kernel, the following vulnerability has been resolved: spi: core: Abort active target transfer on controller suspend When an SPI controller oper… |
| CVE-2026-93813 | CVE-2026-93813 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: btrfs: tree-checker: validate INODE_REF's namelen [BUG] A crafted btrfs image can trigger… |
| CVE-2026-93812 | CVE-2026-93812 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr ndr_encode_v4_ntacl() alloca… |
| CVE-2026-93811 | CVE-2026-93811 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling 1. When ndr_decode_v… |
| CVE-2026-93810 | CVE-2026-93810 CVSS 7.0 | In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix double fput Fix a double fput() in error handling in cachefiles_create_tm… |