92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,451–2,500 of 92,393 · page 50 of 1848
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93790 | CVE-2026-93790 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was in… |
| CVE-2026-9379 | CVE-2026-9379 CVSS 6.3 | A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request … |
| CVE-2026-93789 | CVE-2026-93789 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: bound aligned TLV advance in FW parser Validate ALIGN(tlv_len, 4) against … |
| CVE-2026-93788 | CVE-2026-93788 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: acpi: validate WGDS table revision index Check tbl_rev bounds before BIT(t… |
| CVE-2026-93787 | CVE-2026-93787 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name against end of SMB response in cifs_filldir cifs_filldir()… |
| CVE-2026-93786 | CVE-2026-93786 CVSS 8.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from… |
| CVE-2026-93785 | CVE-2026-93785 | In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length… |
| CVE-2026-93784 | CVE-2026-93784 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() The KASAN allocation trace shows… |
| CVE-2026-93783 | CVE-2026-93783 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame rfcomm_recv_frame() casts skb… |
| CVE-2026-93782 | CVE-2026-93782 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descri… |
| CVE-2026-93781 | CVE-2026-93781 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Do not block on tag allocation in scsi_eh_lock_door() scsi_eh_lock_door() is … |
| CVE-2026-9378 | CVE-2026-9378 CVSS 6.3 | A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request H… |
| CVE-2026-93778 | CVE-2026-93778 CVSS 7.2 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all v… |
| CVE-2026-93774 | CVE-2026-93774 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. |
| CVE-2026-93773 | CVE-2026-93773 CVSS 8.5 | Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. |
| CVE-2026-93772 | CVE-2026-93772 CVSS 6.5 | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. |
| CVE-2026-93771 | CVE-2026-93771 CVSS 7.2 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. |
| CVE-2026-93770 | CVE-2026-93770 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. |
| CVE-2026-9377 | CVE-2026-9377 CVSS 2.4 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The m… |
| CVE-2026-93769 | CVE-2026-93769 | HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage User… |
| CVE-2026-93765 | CVE-2026-93765 CVSS 9.1mongodb | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from … |
| CVE-2026-93764 | CVE-2026-93764 CVSS 6.5mongodb | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enabl… |
| CVE-2026-93763 | CVE-2026-93763 CVSS 6.5mongodb | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-sid… |
| CVE-2026-93762 | CVE-2026-93762 CVSS 9.8mongodb | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to c… |
| CVE-2026-93761 | CVE-2026-93761 CVSS 7.5mongodb | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cau… |
| CVE-2026-93760 | CVE-2026-93760 CVSS 8.2mongodb | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In… |
| CVE-2026-9376 | CVE-2026-9376 CVSS 6.3 | A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCe… |
| CVE-2026-93759 | CVE-2026-93759 CVSS 8.6mongodb | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript exp… |
| CVE-2026-93758 | CVE-2026-93758 CVSS 8.1mongodb | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges … |
| CVE-2026-93756 | CVE-2026-93756 CVSS 7.2 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment M… |
| CVE-2026-93753 | CVE-2026-93753 CVSS 7.5 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target… |
| CVE-2026-93752 | CVE-2026-93752 CVSS 7.5 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers c… |
| CVE-2026-93751 | CVE-2026-93751 CVSS 6.5 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII … |
| CVE-2026-93750 | CVE-2026-93750 CVSS 5.9 | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcar… |
| CVE-2026-9375 | CVE-2026-9375 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-93749 | CVE-2026-93749 CVSS 7.5 | source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values.… |
| CVE-2026-93748 | CVE-2026-93748 CVSS 7.5 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticat… |
| CVE-2026-93747 | CVE-2026-93747 CVSS 6.4 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. Th… |
| CVE-2026-93742 | CVE-2026-93742 CVSS 9.9 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipula… |
| CVE-2026-93741 | CVE-2026-93741 CVSS 10.0 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlW… |
| CVE-2026-93740 | CVE-2026-93740 CVSS 10.0 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulatio… |
| CVE-2026-9374 | CVE-2026-9374 CVSS 6.3 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component C… |
| CVE-2026-93739 | CVE-2026-93739 CVSS 9.9 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation… |
| CVE-2026-93738 | CVE-2026-93738 CVSS 9.9 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipula… |
| CVE-2026-93737 | CVE-2026-93737 CVSS 6.5 | Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule … |
| CVE-2026-93736 | CVE-2026-93736 CVSS 4.3 | Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe rating… |
| CVE-2026-9373 | CVE-2026-9373 CVSS 3.7 | A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Suc… |
| CVE-2026-9372 | CVE-2026-9372 CVSS 7.3 | A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Mod… |
| CVE-2026-93712 | CVE-2026-93712 CVSS 7.5 | Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins … |
| CVE-2026-93711 | CVE-2026-93711 CVSS 6.5 | Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header v… |