92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,651–2,700 of 92,393 · page 54 of 1848
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93474 | CVE-2026-93474 CVSS 6.5 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-9347 | CVE-2026-9347 CVSS 6.3 | A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs.… |
| CVE-2026-93468 | CVE-2026-93468 CVSS 7.5 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrar… |
| CVE-2026-93467 | CVE-2026-93467 CVSS 9.8 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by send… |
| CVE-2026-93464 | CVE-2026-93464 CVSS 5.4 | A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be … |
| CVE-2026-93463 | CVE-2026-93463 CVSS 5.4 | A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed i… |
| CVE-2026-93462 | CVE-2026-93462 CVSS 5.3 | A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive inf… |
| CVE-2026-93460 | CVE-2026-93460 CVSS 5.4 | A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary scri… |
| CVE-2026-9346 | CVE-2026-9346 CVSS 8.8 | A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Exe… |
| CVE-2026-93456 | CVE-2026-93456 CVSS 8.2 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify… |
| CVE-2026-93455 | CVE-2026-93455 CVSS 6.5 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and… |
| CVE-2026-93454 | CVE-2026-93454 CVSS 5.4 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-t… |
| CVE-2026-93453 | CVE-2026-93453 CVSS 8.3 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect re… |
| CVE-2026-93452 | CVE-2026-93452 CVSS 7.5 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination bu… |
| CVE-2026-93451 | CVE-2026-93451 CVSS 6.5 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompre… |
| CVE-2026-93450 | CVE-2026-93450 CVSS 7.5 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no de… |
| CVE-2026-9345 | CVE-2026-9345 CVSS 8.8 | A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. … |
| CVE-2026-93449 | CVE-2026-93449 CVSS 8.5langflow | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation. |
| CVE-2026-93448 | CVE-2026-93448 CVSS 6.5langflow | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a… |
| CVE-2026-93447 | CVE-2026-93447 CVSS 7.5langflow | IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache va… |
| CVE-2026-93445 | CVE-2026-93445 CVSS 8.1langflow | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. |
| CVE-2026-93443 | CVE-2026-93443 CVSS 7.5langflow | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … |
| CVE-2026-9344 | CVE-2026-9344 CVSS 8.8 | A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the… |
| CVE-2026-93436 | CVE-2026-93436 CVSS 7.5vllm | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attacke… |
| CVE-2026-93435 | CVE-2026-93435 CVSS 7.5 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client pro… |
| CVE-2026-93433 | CVE-2026-93433 CVSS 5.5 | A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System… |
| CVE-2026-93432 | CVE-2026-93432 CVSS 6.1 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content … |
| CVE-2026-93430 | CVE-2026-93430 CVSS 7.2 | The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all vers… |
| CVE-2026-9343 | CVE-2026-9343 CVSS 6.3 | A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of the compo… |
| CVE-2026-93428 | CVE-2026-93428 CVSS 7.5 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to author… |
| CVE-2026-93426 | CVE-2026-93426 CVSS 8.5 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject … |
| CVE-2026-93425 | CVE-2026-93425 CVSS 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPa… |
| CVE-2026-93421 | CVE-2026-93421 | Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-control… |
| CVE-2026-9342 | CVE-2026-9342 CVSS 6.3 | A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patie… |
| CVE-2026-9341 | CVE-2026-9341 CVSS 4.3 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u… |
| CVE-2026-93405 | CVE-2026-93405 CVSS 6.1 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Sn… |
| CVE-2026-93399 | CVE-2026-93399 CVSS 9.1 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_… |
| CVE-2026-93395 | CVE-2026-93395 CVSS 5.3mongodb | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length pre… |
| CVE-2026-93394 | CVE-2026-93394 CVSS 3.7mongodb | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a … |
| CVE-2026-93393 | CVE-2026-93393 CVSS 8.1mongodb | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that… |
| CVE-2026-93387 | CVE-2026-93387 CVSS 4.3google | Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chrom… |
| CVE-2026-93386 | CVE-2026-93386 CVSS 5.4google | UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via… |
| CVE-2026-93385 | CVE-2026-93385 CVSS 6.5google | Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium … |
| CVE-2026-93384 | CVE-2026-93384 CVSS 3.7google | Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass … |
| CVE-2026-93383 | CVE-2026-93383 CVSS 4.3google | Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium … |
| CVE-2026-93382 | CVE-2026-93382 CVSS 8.8google | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page… |
| CVE-2026-93381 | CVE-2026-93381 CVSS 8.8google | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute … |
| CVE-2026-93380 | CVE-2026-93380 CVSS 3.1google | Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social en… |
| CVE-2026-9338 | CVE-2026-9338 CVSS 5.3ibm | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could expl… |
| CVE-2026-93379 | CVE-2026-93379 CVSS 4.3google | Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium se… |