92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,501–2,550 of 92,393 · page 51 of 1848

IDTitleSummary
CVE-2026-93710CVE-2026-93710
CVSS 7.5
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. A…
CVE-2026-9371CVE-2026-9371
CVSS 5.6
A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the c…
CVE-2026-93709CVE-2026-93709
CVSS 5.3
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler. The handler …
CVE-2026-9370CVE-2026-9370
CVSS 3.7
A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator …
CVE-2026-93699CVE-2026-93699Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
CVE-2026-93698CVE-2026-93698
CVSS 9.9
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
CVE-2026-93697CVE-2026-93697
CVSS 9.0
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
CVE-2026-93690CVE-2026-93690
CVSS 7.5
uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode…
CVE-2026-9369CVE-2026-9369
CVSS 5.3
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_ser…
CVE-2026-93689CVE-2026-93689
CVSS 5.5
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the vo…
CVE-2026-93688CVE-2026-93688
CVSS 7.5
SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded trans…
CVE-2026-93687CVE-2026-93687
CVSS 7.5
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patt…
CVE-2026-93685CVE-2026-93685
CVSS 5.4
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in th…
CVE-2026-93684CVE-2026-93684
CVSS 5.4
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's br…
CVE-2026-93682CVE-2026-93682
CVSS 5.8
When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end o…
CVE-2026-9368CVE-2026-9368
CVSS 7.3
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of…
CVE-2026-93679CVE-2026-93679
CVSS 4.3langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during …
CVE-2026-93678CVE-2026-93678
CVSS 7.6langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.
CVE-2026-93677CVE-2026-93677
CVSS 7.7langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to a…
CVE-2026-93676CVE-2026-93676
CVSS 3.2
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak app…
CVE-2026-93675CVE-2026-93675
CVSS 8.8langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.
CVE-2026-93674CVE-2026-93674
CVSS 9.8langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS …
CVE-2026-9367CVE-2026-9367
CVSS 7.3
A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command …
CVE-2026-93662CVE-2026-93662
CVSS 4.3
The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner va…
CVE-2026-93661CVE-2026-93661
CVSS 2.7
The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against,…
CVE-2026-93660CVE-2026-93660
CVSS 6.5
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify ot…
CVE-2026-9366CVE-2026-9366
CVSS 7.3
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.p…
CVE-2026-93659CVE-2026-93659
CVSS 8.1
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers c…
CVE-2026-93658CVE-2026-93658
CVSS 7.0
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to l…
CVE-2026-93657CVE-2026-93657
CVSS 7.5
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing inv…
CVE-2026-93656CVE-2026-93656
CVSS 6.4
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…
CVE-2026-93655CVE-2026-93655
CVSS 6.1
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and includi…
CVE-2026-93654CVE-2026-93654
CVSS 7.2
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parame…
CVE-2026-93653CVE-2026-93653
CVSS 5.5
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutpu…
CVE-2026-93652CVE-2026-93652
CVSS 7.5
Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
CVE-2026-93651CVE-2026-93651
CVSS 7.2
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93650CVE-2026-93650
CVSS 3.7
A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/accou…
CVE-2026-9365CVE-2026-9365
CVSS 5.6
A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component G…
CVE-2026-93647CVE-2026-93647
CVSS 9.3
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS…
CVE-2026-93643CVE-2026-93643
CVSS 9.8
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsi…
CVE-2026-93642CVE-2026-93642
CVSS 9.3
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the at…
CVE-2026-93641CVE-2026-93641
CVSS 9.3
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the a…
CVE-2026-9364CVE-2026-9364
CVSS 7.3
A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation …
CVE-2026-9363CVE-2026-9363
CVSS 6.3
A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the compone…
CVE-2026-93624CVE-2026-93624
CVSS 7.2
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-93623CVE-2026-93623
CVSS 5.3
Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
CVE-2026-93622CVE-2026-93622
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
CVE-2026-93621CVE-2026-93621
CVSS 8.2
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-93620CVE-2026-93620
CVSS 6.5
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
CVE-2026-9362CVE-2026-9362
CVSS 6.3
A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnectionSetting of the file /goform/formCon…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.