92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,451–2,500 of 92,393 · page 50 of 1848

IDTitleSummary
CVE-2026-93790CVE-2026-93790
CVSS 8.8
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was in…
CVE-2026-9379CVE-2026-9379
CVSS 6.3
A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request …
CVE-2026-93789CVE-2026-93789In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: bound aligned TLV advance in FW parser Validate ALIGN(tlv_len, 4) against …
CVE-2026-93788CVE-2026-93788In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: acpi: validate WGDS table revision index Check tbl_rev bounds before BIT(t…
CVE-2026-93787CVE-2026-93787
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: smb: client: bound dirent name against end of SMB response in cifs_filldir cifs_filldir()…
CVE-2026-93786CVE-2026-93786
CVSS 8.1
In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from…
CVE-2026-93785CVE-2026-93785In the Linux kernel, the following vulnerability has been resolved: cifs: validate idmap key payload length The cifs.idmap key type stores its payload length…
CVE-2026-93784CVE-2026-93784In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie() The KASAN allocation trace shows…
CVE-2026-93783CVE-2026-93783In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame rfcomm_recv_frame() casts skb…
CVE-2026-93782CVE-2026-93782
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descri…
CVE-2026-93781CVE-2026-93781In the Linux kernel, the following vulnerability has been resolved: scsi: core: Do not block on tag allocation in scsi_eh_lock_door() scsi_eh_lock_door() is …
CVE-2026-9378CVE-2026-9378
CVSS 6.3
A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request H…
CVE-2026-93778CVE-2026-93778
CVSS 7.2
The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all v…
CVE-2026-93774CVE-2026-93774
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
CVE-2026-93773CVE-2026-93773
CVSS 8.5
Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
CVE-2026-93772CVE-2026-93772
CVSS 6.5
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
CVE-2026-93771CVE-2026-93771
CVSS 7.2
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93770CVE-2026-93770
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-9377CVE-2026-9377
CVSS 2.4
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The m…
CVE-2026-93769CVE-2026-93769HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage User…
CVE-2026-93765CVE-2026-93765
CVSS 9.1mongodb
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from …
CVE-2026-93764CVE-2026-93764
CVSS 6.5mongodb
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enabl…
CVE-2026-93763CVE-2026-93763
CVSS 6.5mongodb
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-sid…
CVE-2026-93762CVE-2026-93762
CVSS 9.8mongodb
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to c…
CVE-2026-93761CVE-2026-93761
CVSS 7.5mongodb
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cau…
CVE-2026-93760CVE-2026-93760
CVSS 8.2mongodb
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In…
CVE-2026-9376CVE-2026-9376
CVSS 6.3
A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCe…
CVE-2026-93759CVE-2026-93759
CVSS 8.6mongodb
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript exp…
CVE-2026-93758CVE-2026-93758
CVSS 8.1mongodb
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges …
CVE-2026-93756CVE-2026-93756
CVSS 7.2
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment M…
CVE-2026-93753CVE-2026-93753
CVSS 7.5
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target…
CVE-2026-93752CVE-2026-93752
CVSS 7.5
CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers c…
CVE-2026-93751CVE-2026-93751
CVSS 6.5
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII …
CVE-2026-93750CVE-2026-93750
CVSS 5.9
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcar…
CVE-2026-9375CVE-2026-9375Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-93749CVE-2026-93749
CVSS 7.5
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values.…
CVE-2026-93748CVE-2026-93748
CVSS 7.5
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticat…
CVE-2026-93747CVE-2026-93747
CVSS 6.4
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. Th…
CVE-2026-93742CVE-2026-93742
CVSS 9.9
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipula…
CVE-2026-93741CVE-2026-93741
CVSS 10.0
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlW…
CVE-2026-93740CVE-2026-93740
CVSS 10.0
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulatio…
CVE-2026-9374CVE-2026-9374
CVSS 6.3
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component C…
CVE-2026-93739CVE-2026-93739
CVSS 9.9
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation…
CVE-2026-93738CVE-2026-93738
CVSS 9.9
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipula…
CVE-2026-93737CVE-2026-93737
CVSS 6.5
Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule …
CVE-2026-93736CVE-2026-93736
CVSS 4.3
Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe rating…
CVE-2026-9373CVE-2026-9373
CVSS 3.7
A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Suc…
CVE-2026-9372CVE-2026-9372
CVSS 7.3
A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Mod…
CVE-2026-93712CVE-2026-93712
CVSS 7.5
Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins …
CVE-2026-93711CVE-2026-93711
CVSS 6.5
Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header v…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.