92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,151–3,200 of 92,816 · page 64 of 1857

IDTitleSummary
CVE-2026-9295CVE-2026-9295
CVSS 8.8
A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component PO…
CVE-2026-92949CVE-2026-92949
CVSS 4.0
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze…
CVE-2026-92948CVE-2026-92948
CVSS 9.9
vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder e…
CVE-2026-92947CVE-2026-92947
CVSS 10.0
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related alloc…
CVE-2026-92946CVE-2026-92946
CVSS 10.0
vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. …
CVE-2026-92945CVE-2026-92945
CVSS 4.2
vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored …
CVE-2026-92944CVE-2026-92944
CVSS 9.8
vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections du…
CVE-2026-92943CVE-2026-92943
CVSS 8.1
Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.…
CVE-2026-92942CVE-2026-92942
CVSS 7.5
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout…
CVE-2026-92941CVE-2026-92941
CVSS 10.0
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace…
CVE-2026-92940CVE-2026-92940
CVSS 10.0
vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('…
CVE-2026-9294CVE-2026-9294
CVSS 8.8
A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the co…
CVE-2026-92939CVE-2026-92939
CVSS 9.9
vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursiv…
CVE-2026-92938CVE-2026-92938
CVSS 9.9
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or thro…
CVE-2026-92937CVE-2026-92937
CVSS 10.0
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the b…
CVE-2026-92936CVE-2026-92936
CVSS 5.8
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the h…
CVE-2026-92935CVE-2026-92935
CVSS 9.0
vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof r…
CVE-2026-92934CVE-2026-92934
CVSS 9.0
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are cau…
CVE-2026-92933CVE-2026-92933
CVSS 5.8
vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy …
CVE-2026-92932CVE-2026-92932In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-bas…
CVE-2026-92931CVE-2026-92931
CVSS 8.8
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attack…
CVE-2026-92930CVE-2026-92930
CVSS 6.2
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other se…
CVE-2026-92929CVE-2026-92929
CVSS 5.3
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request sour…
CVE-2026-92928CVE-2026-92928
CVSS 6.5
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be change…
CVE-2026-92927CVE-2026-92927
CVSS 5.3
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Pe…
CVE-2026-92926CVE-2026-92926
CVSS 7.3
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preferen…
CVE-2026-92925CVE-2026-92925
CVSS 7.1
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-ca…
CVE-2026-92924CVE-2026-92924
CVSS 5.4
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it,…
CVE-2026-92923CVE-2026-92923
CVSS 6.3
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users…
CVE-2026-92921CVE-2026-92921
CVSS 4.9
admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database acc…
CVE-2026-92920CVE-2026-92920
CVSS 5.4
admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permi…
CVE-2026-9292CVE-2026-9292A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user…
CVE-2026-92919CVE-2026-92919
CVSS 8.1
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on…
CVE-2026-92918CVE-2026-92918
CVSS 8.8
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission ca…
CVE-2026-92917CVE-2026-92917
CVSS 7.5
Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, js…
CVE-2026-92916CVE-2026-92916
CVSS 7.5
Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the…
CVE-2026-92915CVE-2026-92915
CVSS 7.3
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables t…
CVE-2026-92914CVE-2026-92914
CVSS 8.1
AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equalit…
CVE-2026-92913CVE-2026-92913
CVSS 7.4
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / …
CVE-2026-92912CVE-2026-92912
CVSS 6.5
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entr…
CVE-2026-9291CVE-2026-9291
CVSS 7.1
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write acce…
CVE-2026-92905CVE-2026-92905
CVSS 5.3
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector …
CVE-2026-92904CVE-2026-92904
CVSS 4.3
A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocat…
CVE-2026-92903CVE-2026-92903
CVSS 8.2
Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are exe…
CVE-2026-9290CVE-2026-9290
CVSS 7.5
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17…
CVE-2026-92899CVE-2026-92899
CVSS 4.8apache
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentica…
CVE-2026-92894CVE-2026-92894
CVSS 4.3
A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying…
CVE-2026-92893CVE-2026-92893
CVSS 4.3
A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not en…
CVE-2026-9289CVE-2026-9289
CVSS 5.3
The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via t…
CVE-2026-92882CVE-2026-92882Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p38, <2.3.0p51 and 2.2.0 (EOL) …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.