92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,601–2,650 of 92,393 · page 53 of 1848
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93558 | CVE-2026-93558 CVSS 7.5 | A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to … |
| CVE-2026-93556 | CVE-2026-93556 | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for t… |
| CVE-2026-9355 | CVE-2026-9355 CVSS 7.3 | A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Maste… |
| CVE-2026-93549 | CVE-2026-93549 CVSS 8.8 | The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce pr… |
| CVE-2026-93548 | CVE-2026-93548 CVSS 8.8 | The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenti… |
| CVE-2026-93547 | CVE-2026-93547 | A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace c… |
| CVE-2026-93546 | CVE-2026-93546 CVSS 8.8apache | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persi… |
| CVE-2026-93545 | CVE-2026-93545 CVSS 6.5 | An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. |
| CVE-2026-93544 | CVE-2026-93544 CVSS 6.5 | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client. |
| CVE-2026-93543 | CVE-2026-93543 CVSS 7.4 | An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client. |
| CVE-2026-93542 | CVE-2026-93542 CVSS 6.5 | An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X… |
| CVE-2026-93541 | CVE-2026-93541 CVSS 6.5 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a |
| CVE-2026-93540 | CVE-2026-93540 CVSS 6.5suse | A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, … |
| CVE-2026-9354 | CVE-2026-9354 CVSS 6.5 | A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost … |
| CVE-2026-93539 | CVE-2026-93539 CVSS 5.4suse | A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests… |
| CVE-2026-93538 | CVE-2026-93538 CVSS 7.1suse | A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registerin… |
| CVE-2026-93537 | CVE-2026-93537 CVSS 6.5suse | A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or … |
| CVE-2026-93534 | CVE-2026-93534 CVSS 6.3 | A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the compon… |
| CVE-2026-93533 | CVE-2026-93533 CVSS 6.3 | A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of t… |
| CVE-2026-93532 | CVE-2026-93532 CVSS 6.3 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function ap… |
| CVE-2026-93531 | CVE-2026-93531 CVSS 4.3 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This … |
| CVE-2026-9353 | CVE-2026-9353 CVSS 7.3 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of t… |
| CVE-2026-93529 | CVE-2026-93529 CVSS 6.5 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. |
| CVE-2026-93528 | CVE-2026-93528 CVSS 3.7 | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticat… |
| CVE-2026-93527 | CVE-2026-93527 CVSS 8.5 | Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. |
| CVE-2026-93526 | CVE-2026-93526 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. |
| CVE-2026-9352 | CVE-2026-9352 CVSS 5.3 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local… |
| CVE-2026-93514 | CVE-2026-93514 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. |
| CVE-2026-93513 | CVE-2026-93513 CVSS 4.3 | Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. |
| CVE-2026-93512 | CVE-2026-93512 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. |
| CVE-2026-93511 | CVE-2026-93511 CVSS 5.3 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowi… |
| CVE-2026-93510 | CVE-2026-93510 CVSS 4.3 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim … |
| CVE-2026-9351 | CVE-2026-9351 CVSS 6.5 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the file tools/… |
| CVE-2026-93509 | CVE-2026-93509 CVSS 6.5 | The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new bala… |
| CVE-2026-93508 | CVE-2026-93508 CVSS 8.1 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with S… |
| CVE-2026-93507 | CVE-2026-93507 CVSS 3.3 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-l… |
| CVE-2026-93506 | CVE-2026-93506 CVSS 6.3 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Uplo… |
| CVE-2026-93505 | CVE-2026-93505 CVSS 3.5 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG … |
| CVE-2026-93504 | CVE-2026-93504 CVSS 6.3 | A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute… |
| CVE-2026-9350 | CVE-2026-9350 CVSS 7.3 | A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py o… |
| CVE-2026-93495 | CVE-2026-93495 | Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted d… |
| CVE-2026-93494 | CVE-2026-93494 CVSS 7.5 | A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body wi… |
| CVE-2026-93493 | CVE-2026-93493 CVSS 5.9 | A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Prot… |
| CVE-2026-93492 | CVE-2026-93492 CVSS 5.3 | A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. … |
| CVE-2026-93491 | CVE-2026-93491 CVSS 7.5 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single conn… |
| CVE-2026-9349 | CVE-2026-9349 CVSS 5.3 | A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/v… |
| CVE-2026-93488 | CVE-2026-93488 CVSS 7.5 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Int… |
| CVE-2026-93485 | CVE-2026-93485 CVSS 7.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This is… |
| CVE-2026-9348 | CVE-2026-9348 CVSS 8.8 | A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component w… |
| CVE-2026-93477 | CVE-2026-93477 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private act… |