92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,701–2,750 of 92,393 · page 55 of 1848

IDTitleSummary
CVE-2026-93378CVE-2026-93378
CVSS 3.1google
Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isol…
CVE-2026-93377CVE-2026-93377
CVSS 8.8google
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandb…
CVE-2026-93376CVE-2026-93376
CVSS 6.3google
Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sa…
CVE-2026-93375CVE-2026-93375
CVSS 8.1google
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code …
CVE-2026-93374CVE-2026-93374
CVSS 9.6google
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbo…
CVE-2026-93373CVE-2026-93373
CVSS 9.6google
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chro…
CVE-2026-93372CVE-2026-93372
CVSS 9.6google
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr…
CVE-2026-93371CVE-2026-93371
CVSS 8.3
A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/int…
CVE-2026-93368CVE-2026-93368
CVSS 7.5
The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up t…
CVE-2026-93367CVE-2026-93367
CVSS 7.2
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and incl…
CVE-2026-93366CVE-2026-93366
CVSS 5.4
Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media fil…
CVE-2026-93365CVE-2026-93365
CVSS 6.5
Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full con…
CVE-2026-93364CVE-2026-93364
CVSS 4.3
Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserv…
CVE-2026-93363CVE-2026-93363
CVSS 4.3
The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass col…
CVE-2026-9336CVE-2026-9336
CVSS 6.5ibm
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative end…
CVE-2026-93355CVE-2026-93355
CVSS 8.1
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any e…
CVE-2026-93354CVE-2026-93354
CVSS 8.1
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and …
CVE-2026-93353CVE-2026-93353
CVSS 3.1
copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitra…
CVE-2026-93352CVE-2026-93352
CVSS 9.8
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blockli…
CVE-2026-9335CVE-2026-9335
CVSS 6.5
A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The …
CVE-2026-93349CVE-2026-93349
CVSS 8.8
Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Pa…
CVE-2026-93348CVE-2026-93348
CVSS 8.1
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-load…
CVE-2026-93345CVE-2026-93345
CVSS 7.5
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an…
CVE-2026-93344CVE-2026-93344
CVSS 6.5
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authent…
CVE-2026-93343CVE-2026-93343
CVSS 6.5
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authe…
CVE-2026-93342CVE-2026-93342
CVSS 5.4
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authen…
CVE-2026-93341CVE-2026-93341
CVSS 4.3
MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticate…
CVE-2026-93340CVE-2026-93340
CVSS 6.8
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password rese…
CVE-2026-9334CVE-2026-9334
CVSS 7.3rurban
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses dupli…
CVE-2026-93339CVE-2026-93339
CVSS 5.4
Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-lev…
CVE-2026-93338CVE-2026-93338
CVSS 5.3
Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain…
CVE-2026-93337CVE-2026-93337
CVSS 7.8
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation p…
CVE-2026-93332CVE-2026-93332
CVSS 5.4
Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create,…
CVE-2026-93331CVE-2026-93331
CVSS 7.3
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the comp…
CVE-2026-93330CVE-2026-93330
CVSS 4.3
Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions…
CVE-2026-93326CVE-2026-93326A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look li…
CVE-2026-93323CVE-2026-93323The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversi…
CVE-2026-93322CVE-2026-93322A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
CVE-2026-93321CVE-2026-93321A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
CVE-2026-93320CVE-2026-93320BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootf…
CVE-2026-93319CVE-2026-93319A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon t…
CVE-2026-93318CVE-2026-93318A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised D…
CVE-2026-93317CVE-2026-93317An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting s…
CVE-2026-93316CVE-2026-93316If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
CVE-2026-93315CVE-2026-93315When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build…
CVE-2026-93314CVE-2026-93314
CVSS 6.3
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing…
CVE-2026-93313CVE-2026-93313
CVSS 6.3
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc…
CVE-2026-93312CVE-2026-93312
CVSS 4.3
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes…
CVE-2026-93311CVE-2026-93311
CVSS 4.3
A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc o…
CVE-2026-93310CVE-2026-93310
CVSS 5.3
A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocatio…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.