92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,601–2,650 of 92,393 · page 53 of 1848

IDTitleSummary
CVE-2026-93558CVE-2026-93558
CVSS 7.5
A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to …
CVE-2026-93556CVE-2026-93556The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for t…
CVE-2026-9355CVE-2026-9355
CVSS 7.3
A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Maste…
CVE-2026-93549CVE-2026-93549
CVSS 8.8
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce pr…
CVE-2026-93548CVE-2026-93548
CVSS 8.8
The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenti…
CVE-2026-93547CVE-2026-93547A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace c…
CVE-2026-93546CVE-2026-93546
CVSS 8.8apache
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persi…
CVE-2026-93545CVE-2026-93545
CVSS 6.5
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
CVE-2026-93544CVE-2026-93544
CVSS 6.5
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
CVE-2026-93543CVE-2026-93543
CVSS 7.4
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
CVE-2026-93542CVE-2026-93542
CVSS 6.5
An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X…
CVE-2026-93541CVE-2026-93541
CVSS 6.5
An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
CVE-2026-93540CVE-2026-93540
CVSS 6.5suse
A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, …
CVE-2026-9354CVE-2026-9354
CVSS 6.5
A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost …
CVE-2026-93539CVE-2026-93539
CVSS 5.4suse
A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests…
CVE-2026-93538CVE-2026-93538
CVSS 7.1suse
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registerin…
CVE-2026-93537CVE-2026-93537
CVSS 6.5suse
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or …
CVE-2026-93534CVE-2026-93534
CVSS 6.3
A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the compon…
CVE-2026-93533CVE-2026-93533
CVSS 6.3
A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of t…
CVE-2026-93532CVE-2026-93532
CVSS 6.3
A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function ap…
CVE-2026-93531CVE-2026-93531
CVSS 4.3
A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This …
CVE-2026-9353CVE-2026-9353
CVSS 7.3
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of t…
CVE-2026-93529CVE-2026-93529
CVSS 6.5
Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.
CVE-2026-93528CVE-2026-93528
CVSS 3.7
The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticat…
CVE-2026-93527CVE-2026-93527
CVSS 8.5
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
CVE-2026-93526CVE-2026-93526
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
CVE-2026-9352CVE-2026-9352
CVSS 5.3
A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local…
CVE-2026-93514CVE-2026-93514
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93513CVE-2026-93513
CVSS 4.3
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
CVE-2026-93512CVE-2026-93512
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-93511CVE-2026-93511
CVSS 5.3
The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowi…
CVE-2026-93510CVE-2026-93510
CVSS 4.3
The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim …
CVE-2026-9351CVE-2026-9351
CVSS 6.5
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/…
CVE-2026-93509CVE-2026-93509
CVSS 6.5
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new bala…
CVE-2026-93508CVE-2026-93508
CVSS 8.1
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with S…
CVE-2026-93507CVE-2026-93507
CVSS 3.3
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-l…
CVE-2026-93506CVE-2026-93506
CVSS 6.3
A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Uplo…
CVE-2026-93505CVE-2026-93505
CVSS 3.5
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG …
CVE-2026-93504CVE-2026-93504
CVSS 6.3
A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute…
CVE-2026-9350CVE-2026-9350
CVSS 7.3
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py o…
CVE-2026-93495CVE-2026-93495Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted d…
CVE-2026-93494CVE-2026-93494
CVSS 7.5
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body wi…
CVE-2026-93493CVE-2026-93493
CVSS 5.9
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Prot…
CVE-2026-93492CVE-2026-93492
CVSS 5.3
A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. …
CVE-2026-93491CVE-2026-93491
CVSS 7.5
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single conn…
CVE-2026-9349CVE-2026-9349
CVSS 5.3
A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/v…
CVE-2026-93488CVE-2026-93488
CVSS 7.5
A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Int…
CVE-2026-93485CVE-2026-93485
CVSS 7.1
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This is…
CVE-2026-9348CVE-2026-9348
CVSS 8.8
A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component w…
CVE-2026-93477CVE-2026-93477Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private act…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.