91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,351–2,400 of 91,785 · page 48 of 1836

IDTitleSummary
CVE-2026-9381CVE-2026-9381
CVSS 8.8
A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the …
CVE-2026-93809CVE-2026-93809In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: flush pending RCU callbacks on module unload Call rcu_barrier() in module exi…
CVE-2026-93808CVE-2026-93808In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: caiaq: validate EP1 reply lengths usb_ep1_command_reply_dispatch() uses …
CVE-2026-93807CVE-2026-93807In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers rsi_hal_load_key() copies tx_…
CVE-2026-93806CVE-2026-93806
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate assoc response length before status and IE access cfg80211_rx_as…
CVE-2026-93805CVE-2026-93805In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate rx/tx MLME callback frame lengths before access cfg80211_rx_mlme…
CVE-2026-93804CVE-2026-93804In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ibss: wait for in-flight TX on disconnect While leaving an IBSS in ieee80…
CVE-2026-93803CVE-2026-93803In the Linux kernel, the following vulnerability has been resolved: wifi: libipw: fix key index receive bound checks libipw_rx() reads skb->data[hdrlen + 3] …
CVE-2026-93802CVE-2026-93802In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: validate beacon length before fixed buffer copy rsi_prepare_beacon() copies th…
CVE-2026-93801CVE-2026-93801
CVSS 7.0
In the Linux kernel, the following vulnerability has been resolved: smb/client: zero-initialize stack-allocated cifs_open_info_data Stack-allocated cifs_open…
CVE-2026-93800CVE-2026-93800In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() If during re…
CVE-2026-9380CVE-2026-9380
CVSS 8.8
A security vulnerability has been detected in Edimax BR-6675nD 1.12. Affected is the function formL2TPSetup of the file /goform/formL2TPSetup of the component …
CVE-2026-93799CVE-2026-93799
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate sta_id in BA window status notif BA_WINDOW_STATUS_NOTIFICATI…
CVE-2026-93798CVE-2026-93798
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reloc root cleanup in merge_reloc_roots() If the root we got has zero root ref…
CVE-2026-93797CVE-2026-93797In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix an off-by-1 boundary check Before looking at the 11th byte, check…
CVE-2026-93796CVE-2026-93796
CVSS 7.0
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: pcie: null RX pointers after free When iwl_pcie_tx_init() fails after RX i…
CVE-2026-93795CVE-2026-93795In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix leaks and online flag on radix_tree_insert failure When radix_tree_insert…
CVE-2026-93794CVE-2026-93794In the Linux kernel, the following vulnerability has been resolved: smb/client: flush dirty data before punching a hole Punching a hole after a large buffere…
CVE-2026-93793CVE-2026-93793
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: validate TX_CMD response layout TX_CMD parsing uses frame_count to wa…
CVE-2026-93792CVE-2026-93792In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix a possible underflow We shouldn't trust the firmware about the le…
CVE-2026-93791CVE-2026-93791In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: add a check on the tid coming from the firmware ba_notif->tid is a fi…
CVE-2026-93790CVE-2026-93790
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was in…
CVE-2026-9379CVE-2026-9379
CVSS 6.3
A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request …
CVE-2026-93789CVE-2026-93789In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: bound aligned TLV advance in FW parser Validate ALIGN(tlv_len, 4) against …
CVE-2026-93788CVE-2026-93788In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: acpi: validate WGDS table revision index Check tbl_rev bounds before BIT(t…
CVE-2026-93787CVE-2026-93787
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name against end of SMB response in cifs_filldir cifs_filldir()…
CVE-2026-93786CVE-2026-93786
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from…
CVE-2026-93785CVE-2026-93785In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length…
CVE-2026-93784CVE-2026-93784In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() The KASAN allocation trace shows…
CVE-2026-93783CVE-2026-93783In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame rfcomm_recv_frame() casts skb…
CVE-2026-93782CVE-2026-93782
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descri…
CVE-2026-93781CVE-2026-93781In the Linux kernel, the following vulnerability has been resolved: scsi: core: Do not block on tag allocation in scsi_eh_lock_door() scsi_eh_lock_door() is …
CVE-2026-9378CVE-2026-9378
CVSS 6.3
A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request H…
CVE-2026-93778CVE-2026-93778
CVSS 7.2
The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all v…
CVE-2026-93774CVE-2026-93774
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
CVE-2026-93773CVE-2026-93773
CVSS 8.5
Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
CVE-2026-93772CVE-2026-93772
CVSS 6.5
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
CVE-2026-93771CVE-2026-93771
CVSS 7.2
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93770CVE-2026-93770
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-9377CVE-2026-9377
CVSS 2.4
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The m…
CVE-2026-93769CVE-2026-93769HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage User…
CVE-2026-93765CVE-2026-93765
CVSS 9.1mongodb
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from …
CVE-2026-93764CVE-2026-93764
CVSS 6.5mongodb
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enabl…
CVE-2026-93763CVE-2026-93763
CVSS 6.5mongodb
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-sid…
CVE-2026-93762CVE-2026-93762
CVSS 9.8mongodb
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to c…
CVE-2026-93761CVE-2026-93761
CVSS 7.5mongodb
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cau…
CVE-2026-93760CVE-2026-93760
CVSS 8.2mongodb
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In…
CVE-2026-9376CVE-2026-9376
CVSS 6.3
A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCe…
CVE-2026-93759CVE-2026-93759
CVSS 8.6mongodb
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript exp…
CVE-2026-93758CVE-2026-93758
CVSS 8.1mongodb
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.