92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,551–2,600 of 92,393 · page 52 of 1848
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93618 | CVE-2026-93618 CVSS 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. T… |
| CVE-2026-93617 | CVE-2026-93617 CVSS 7.2 | Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Phot… |
| CVE-2026-93616 | Check Point Multiple Products Path Traversal Vulnerability KEVCVSS 9.8Check Point | Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal v… |
| CVE-2026-9361 | CVE-2026-9361 CVSS 6.3 | A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Request Hand… |
| CVE-2026-93606 | CVE-2026-93606 CVSS 10.0 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the… |
| CVE-2026-93605 | CVE-2026-93605 CVSS 10.0 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-… |
| CVE-2026-93604 | CVE-2026-93604 CVSS 7.2 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (… |
| CVE-2026-93603 | CVE-2026-93603 CVSS 10.0 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code c… |
| CVE-2026-93602 | CVE-2026-93602 CVSS 4.4 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against e… |
| CVE-2026-93601 | CVE-2026-93601 CVSS 2.2 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS na… |
| CVE-2026-93600 | CVE-2026-93600 CVSS 2.2 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to U… |
| CVE-2026-9360 | CVE-2026-9360 CVSS 8.8 | A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of… |
| CVE-2026-93599 | CVE-2026-93599 CVSS 7.5 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input gu… |
| CVE-2026-93598 | CVE-2026-93598 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyg… |
| CVE-2026-93597 | CVE-2026-93597 CVSS 7.7 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attacke… |
| CVE-2026-93596 | CVE-2026-93596 CVSS 4.3 | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker thread… |
| CVE-2026-93595 | CVE-2026-93595 CVSS 6.5 | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes quer… |
| CVE-2026-93594 | CVE-2026-93594 CVSS 8.1 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file … |
| CVE-2026-93593 | CVE-2026-93593 CVSS 8.1 | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but … |
| CVE-2026-93592 | CVE-2026-93592 CVSS 7.5vllm | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to c… |
| CVE-2026-93591 | CVE-2026-93591 CVSS 7.6 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string l… |
| CVE-2026-93590 | CVE-2026-93590 CVSS 3.7 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image p… |
| CVE-2026-9359 | CVE-2026-9359 CVSS 6.3 | A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the compon… |
| CVE-2026-93589 | CVE-2026-93589 CVSS 3.7 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being enco… |
| CVE-2026-93588 | CVE-2026-93588 CVSS 3.1 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a sp… |
| CVE-2026-93587 | CVE-2026-93587 CVSS 3.3 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific com… |
| CVE-2026-93586 | CVE-2026-93586 CVSS 2.9 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated co… |
| CVE-2026-93580 | CVE-2026-93580 CVSS 5.3 | The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and… |
| CVE-2026-9358 | CVE-2026-9358 CVSS 4.3 | A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the co… |
| CVE-2026-93579 | CVE-2026-93579 CVSS 6.5 | A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Ret… |
| CVE-2026-93578 | CVE-2026-93578 CVSS 5.9 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OC… |
| CVE-2026-93577 | CVE-2026-93577 CVSS 9.9gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain co… |
| CVE-2026-93576 | CVE-2026-93576 CVSS 7.5 | A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-nam… |
| CVE-2026-93575 | CVE-2026-93575 CVSS 7.5 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. … |
| CVE-2026-93574 | CVE-2026-93574 CVSS 6.5 | A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size… |
| CVE-2026-93573 | CVE-2026-93573 CVSS 6.5 | A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Tra… |
| CVE-2026-93572 | CVE-2026-93572 CVSS 7.5 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP)… |
| CVE-2026-9357 | CVE-2026-9357 CVSS 3.5 | A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting.… |
| CVE-2026-93569 | CVE-2026-93569 CVSS 8.2 | A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request… |
| CVE-2026-93568 | CVE-2026-93568 CVSS 7.5 | A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's … |
| CVE-2026-93567 | CVE-2026-93567 CVSS 7.5 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONN… |
| CVE-2026-93566 | CVE-2026-93566 CVSS 6.5 | A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-s… |
| CVE-2026-93565 | CVE-2026-93565 CVSS 7.5 | A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming… |
| CVE-2026-93564 | CVE-2026-93564 CVSS 7.5 | A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted P… |
| CVE-2026-93563 | CVE-2026-93563 CVSS 7.5 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit th… |
| CVE-2026-93562 | CVE-2026-93562 CVSS 6.5 | A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smugg… |
| CVE-2026-93561 | CVE-2026-93561 CVSS 6.5 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types ins… |
| CVE-2026-93560 | CVE-2026-93560 CVSS 7.5 | A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum inte… |
| CVE-2026-9356 | CVE-2026-9356 CVSS 7.3 | A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/… |
| CVE-2026-93559 | CVE-2026-93559 CVSS 7.3 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file ba… |