92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,651–2,700 of 92,393 · page 54 of 1848

IDTitleSummary
CVE-2026-93474CVE-2026-93474
CVSS 6.5
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-9347CVE-2026-9347
CVSS 6.3
A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs.…
CVE-2026-93468CVE-2026-93468
CVSS 7.5
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrar…
CVE-2026-93467CVE-2026-93467
CVSS 9.8
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by send…
CVE-2026-93464CVE-2026-93464
CVSS 5.4
A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be …
CVE-2026-93463CVE-2026-93463
CVSS 5.4
A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed i…
CVE-2026-93462CVE-2026-93462
CVSS 5.3
A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive inf…
CVE-2026-93460CVE-2026-93460
CVSS 5.4
A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary scri…
CVE-2026-9346CVE-2026-9346
CVSS 8.8
A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Exe…
CVE-2026-93456CVE-2026-93456
CVSS 8.2
django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify…
CVE-2026-93455CVE-2026-93455
CVSS 6.5
django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and…
CVE-2026-93454CVE-2026-93454
CVSS 5.4
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-t…
CVE-2026-93453CVE-2026-93453
CVSS 8.3
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect re…
CVE-2026-93452CVE-2026-93452
CVSS 7.5
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination bu…
CVE-2026-93451CVE-2026-93451
CVSS 6.5
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompre…
CVE-2026-93450CVE-2026-93450
CVSS 7.5
go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no de…
CVE-2026-9345CVE-2026-9345
CVSS 8.8
A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. …
CVE-2026-93449CVE-2026-93449
CVSS 8.5langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-93448CVE-2026-93448
CVSS 6.5langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a…
CVE-2026-93447CVE-2026-93447
CVSS 7.5langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache va…
CVE-2026-93445CVE-2026-93445
CVSS 8.1langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVE-2026-93443CVE-2026-93443
CVSS 7.5langflow
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements …
CVE-2026-9344CVE-2026-9344
CVSS 8.8
A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the…
CVE-2026-93436CVE-2026-93436
CVSS 7.5vllm
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attacke…
CVE-2026-93435CVE-2026-93435
CVSS 7.5
redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client pro…
CVE-2026-93433CVE-2026-93433
CVSS 5.5
A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System…
CVE-2026-93432CVE-2026-93432
CVSS 6.1
A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content …
CVE-2026-93430CVE-2026-93430
CVSS 7.2
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all vers…
CVE-2026-9343CVE-2026-9343
CVSS 6.3
A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of the compo…
CVE-2026-93428CVE-2026-93428
CVSS 7.5
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to author…
CVE-2026-93426CVE-2026-93426
CVSS 8.5
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject …
CVE-2026-93425CVE-2026-93425
CVSS 9.9
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPa…
CVE-2026-93421CVE-2026-93421Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-control…
CVE-2026-9342CVE-2026-9342
CVSS 6.3
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patie…
CVE-2026-9341CVE-2026-9341
CVSS 4.3
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u…
CVE-2026-93405CVE-2026-93405
CVSS 6.1
Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Sn…
CVE-2026-93399CVE-2026-93399
CVSS 9.1
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_…
CVE-2026-93395CVE-2026-93395
CVSS 5.3mongodb
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length pre…
CVE-2026-93394CVE-2026-93394
CVSS 3.7mongodb
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a …
CVE-2026-93393CVE-2026-93393
CVSS 8.1mongodb
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that…
CVE-2026-93387CVE-2026-93387
CVSS 4.3google
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chrom…
CVE-2026-93386CVE-2026-93386
CVSS 5.4google
UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via…
CVE-2026-93385CVE-2026-93385
CVSS 6.5google
Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium …
CVE-2026-93384CVE-2026-93384
CVSS 3.7google
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass …
CVE-2026-93383CVE-2026-93383
CVSS 4.3google
Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …
CVE-2026-93382CVE-2026-93382
CVSS 8.8google
Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page…
CVE-2026-93381CVE-2026-93381
CVSS 8.8google
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute …
CVE-2026-93380CVE-2026-93380
CVSS 3.1google
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social en…
CVE-2026-9338CVE-2026-9338
CVSS 5.3ibm
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could expl…
CVE-2026-93379CVE-2026-93379
CVSS 4.3google
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium se…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.