92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 2,701–2,750 of 92,393 · page 55 of 1848
| ID | Title | Summary |
|---|---|---|
| CVE-2026-93378 | CVE-2026-93378 CVSS 3.1google | Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isol… |
| CVE-2026-93377 | CVE-2026-93377 CVSS 8.8google | Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandb… |
| CVE-2026-93376 | CVE-2026-93376 CVSS 6.3google | Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sa… |
| CVE-2026-93375 | CVE-2026-93375 CVSS 8.1google | Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code … |
| CVE-2026-93374 | CVE-2026-93374 CVSS 9.6google | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbo… |
| CVE-2026-93373 | CVE-2026-93373 CVSS 9.6google | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chro… |
| CVE-2026-93372 | CVE-2026-93372 CVSS 9.6google | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a cr… |
| CVE-2026-93371 | CVE-2026-93371 CVSS 8.3 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/int… |
| CVE-2026-93368 | CVE-2026-93368 CVSS 7.5 | The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up t… |
| CVE-2026-93367 | CVE-2026-93367 CVSS 7.2 | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and incl… |
| CVE-2026-93366 | CVE-2026-93366 CVSS 5.4 | Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media fil… |
| CVE-2026-93365 | CVE-2026-93365 CVSS 6.5 | Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full con… |
| CVE-2026-93364 | CVE-2026-93364 CVSS 4.3 | Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserv… |
| CVE-2026-93363 | CVE-2026-93363 CVSS 4.3 | The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass col… |
| CVE-2026-9336 | CVE-2026-9336 CVSS 6.5ibm | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative end… |
| CVE-2026-93355 | CVE-2026-93355 CVSS 8.1 | LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any e… |
| CVE-2026-93354 | CVE-2026-93354 CVSS 8.1 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and … |
| CVE-2026-93353 | CVE-2026-93353 CVSS 3.1 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitra… |
| CVE-2026-93352 | CVE-2026-93352 CVSS 9.8 | Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blockli… |
| CVE-2026-9335 | CVE-2026-9335 CVSS 6.5 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The … |
| CVE-2026-93349 | CVE-2026-93349 CVSS 8.8 | Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Pa… |
| CVE-2026-93348 | CVE-2026-93348 CVSS 8.1 | Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-load… |
| CVE-2026-93345 | CVE-2026-93345 CVSS 7.5 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an… |
| CVE-2026-93344 | CVE-2026-93344 CVSS 6.5 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authent… |
| CVE-2026-93343 | CVE-2026-93343 CVSS 6.5 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authe… |
| CVE-2026-93342 | CVE-2026-93342 CVSS 5.4 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authen… |
| CVE-2026-93341 | CVE-2026-93341 CVSS 4.3 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticate… |
| CVE-2026-93340 | CVE-2026-93340 CVSS 6.8 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password rese… |
| CVE-2026-9334 | CVE-2026-9334 CVSS 7.3rurban | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses dupli… |
| CVE-2026-93339 | CVE-2026-93339 CVSS 5.4 | Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-lev… |
| CVE-2026-93338 | CVE-2026-93338 CVSS 5.3 | Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain… |
| CVE-2026-93337 | CVE-2026-93337 CVSS 7.8 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation p… |
| CVE-2026-93332 | CVE-2026-93332 CVSS 5.4 | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create,… |
| CVE-2026-93331 | CVE-2026-93331 CVSS 7.3 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the comp… |
| CVE-2026-93330 | CVE-2026-93330 CVSS 4.3 | Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions… |
| CVE-2026-93326 | CVE-2026-93326 | A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look li… |
| CVE-2026-93323 | CVE-2026-93323 | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversi… |
| CVE-2026-93322 | CVE-2026-93322 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. |
| CVE-2026-93321 | CVE-2026-93321 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. |
| CVE-2026-93320 | CVE-2026-93320 | BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootf… |
| CVE-2026-93319 | CVE-2026-93319 | A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon t… |
| CVE-2026-93318 | CVE-2026-93318 | A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised D… |
| CVE-2026-93317 | CVE-2026-93317 | An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting s… |
| CVE-2026-93316 | CVE-2026-93316 | If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident. |
| CVE-2026-93315 | CVE-2026-93315 | When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build… |
| CVE-2026-93314 | CVE-2026-93314 CVSS 6.3 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing… |
| CVE-2026-93313 | CVE-2026-93313 CVSS 6.3 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc… |
| CVE-2026-93312 | CVE-2026-93312 CVSS 4.3 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes… |
| CVE-2026-93311 | CVE-2026-93311 CVSS 4.3 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc o… |
| CVE-2026-93310 | CVE-2026-93310 CVSS 5.3 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocatio… |