92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,551–2,600 of 92,393 · page 52 of 1848

IDTitleSummary
CVE-2026-93618CVE-2026-93618
CVSS 6.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. T…
CVE-2026-93617CVE-2026-93617
CVSS 7.2
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Phot…
CVE-2026-93616Check Point Multiple Products Path Traversal Vulnerability
KEVCVSS 9.8Check Point
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal v…
CVE-2026-9361CVE-2026-9361
CVSS 6.3
A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Request Hand…
CVE-2026-93606CVE-2026-93606
CVSS 10.0
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the…
CVE-2026-93605CVE-2026-93605
CVSS 10.0
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-…
CVE-2026-93604CVE-2026-93604
CVSS 7.2
vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (…
CVE-2026-93603CVE-2026-93603
CVSS 10.0
vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code c…
CVE-2026-93602CVE-2026-93602
CVSS 4.4
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against e…
CVE-2026-93601CVE-2026-93601
CVSS 2.2
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS na…
CVE-2026-93600CVE-2026-93600
CVSS 2.2
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to U…
CVE-2026-9360CVE-2026-9360
CVSS 8.8
A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of…
CVE-2026-93599CVE-2026-93599
CVSS 7.5
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input gu…
CVE-2026-93598CVE-2026-93598ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyg…
CVE-2026-93597CVE-2026-93597
CVSS 7.7
ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attacke…
CVE-2026-93596CVE-2026-93596
CVSS 4.3
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker thread…
CVE-2026-93595CVE-2026-93595
CVSS 6.5
ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes quer…
CVE-2026-93594CVE-2026-93594
CVSS 8.1
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file …
CVE-2026-93593CVE-2026-93593
CVSS 8.1
ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but …
CVE-2026-93592CVE-2026-93592
CVSS 7.5vllm
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to c…
CVE-2026-93591CVE-2026-93591
CVSS 7.6
SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string l…
CVE-2026-93590CVE-2026-93590
CVSS 3.7
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image p…
CVE-2026-9359CVE-2026-9359
CVSS 6.3
A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the compon…
CVE-2026-93589CVE-2026-93589
CVSS 3.7
ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being enco…
CVE-2026-93588CVE-2026-93588
CVSS 3.1
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a sp…
CVE-2026-93587CVE-2026-93587
CVSS 3.3
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific com…
CVE-2026-93586CVE-2026-93586
CVSS 2.9
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated co…
CVE-2026-93580CVE-2026-93580
CVSS 5.3
The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and…
CVE-2026-9358CVE-2026-9358
CVSS 4.3
A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the co…
CVE-2026-93579CVE-2026-93579
CVSS 6.5
A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Ret…
CVE-2026-93578CVE-2026-93578
CVSS 5.9
A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OC…
CVE-2026-93577CVE-2026-93577
CVSS 9.9gitlab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain co…
CVE-2026-93576CVE-2026-93576
CVSS 7.5
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-nam…
CVE-2026-93575CVE-2026-93575
CVSS 7.5
A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. …
CVE-2026-93574CVE-2026-93574
CVSS 6.5
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size…
CVE-2026-93573CVE-2026-93573
CVSS 6.5
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Tra…
CVE-2026-93572CVE-2026-93572
CVSS 7.5
A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP)…
CVE-2026-9357CVE-2026-9357
CVSS 3.5
A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting.…
CVE-2026-93569CVE-2026-93569
CVSS 8.2
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request…
CVE-2026-93568CVE-2026-93568
CVSS 7.5
A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's …
CVE-2026-93567CVE-2026-93567
CVSS 7.5
A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONN…
CVE-2026-93566CVE-2026-93566
CVSS 6.5
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-s…
CVE-2026-93565CVE-2026-93565
CVSS 7.5
A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming…
CVE-2026-93564CVE-2026-93564
CVSS 7.5
A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted P…
CVE-2026-93563CVE-2026-93563
CVSS 7.5
A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit th…
CVE-2026-93562CVE-2026-93562
CVSS 6.5
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smugg…
CVE-2026-93561CVE-2026-93561
CVSS 6.5
A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types ins…
CVE-2026-93560CVE-2026-93560
CVSS 7.5
A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum inte…
CVE-2026-9356CVE-2026-9356
CVSS 7.3
A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/…
CVE-2026-93559CVE-2026-93559
CVSS 7.3
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file ba…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.