92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,201–3,250 of 92,816 · page 65 of 1857

IDTitleSummary
CVE-2026-92881CVE-2026-92881
CVSS 4.3
A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the compo…
CVE-2026-92880CVE-2026-92880
CVSS 6.3
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component…
CVE-2026-92879CVE-2026-92879
CVSS 4.3
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation result…
CVE-2026-92874CVE-2026-92874
CVSS 5.4gitlab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain co…
CVE-2026-92873CVE-2026-92873
CVSS 7.3
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog nod…
CVE-2026-92872CVE-2026-92872
CVSS 4.3
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.
CVE-2026-92871CVE-2026-92871
CVSS 7.5
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.
CVE-2026-92870CVE-2026-92870
CVSS 7.5
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
CVE-2026-92869CVE-2026-92869
CVSS 6.5
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
CVE-2026-92868CVE-2026-92868
CVSS 6.5
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
CVE-2026-92867CVE-2026-92867
CVSS 8.8
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code ex…
CVE-2026-92862CVE-2026-92862
CVSS 3.3
The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website …
CVE-2026-92861CVE-2026-92861
CVSS 4.0
The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.
CVE-2026-92860CVE-2026-92860
CVSS 9.1
A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/qui…
CVE-2026-92842CVE-2026-92842
CVSS 5.9
The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is …
CVE-2026-9284CVE-2026-9284
CVSS 8.2
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization c…
CVE-2026-92839CVE-2026-92839
CVSS 4.3
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin conte…
CVE-2026-92838CVE-2026-92838
CVSS 7.8
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from…
CVE-2026-92834CVE-2026-92834Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.2…
CVE-2026-92829CVE-2026-92829
CVSS 4.3
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. Thi…
CVE-2026-92826CVE-2026-92826
CVSS 6.1
The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and includin…
CVE-2026-92821CVE-2026-92821
CVSS 6.8
A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protoc…
CVE-2026-92820CVE-2026-92820
CVSS 8.1
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (A…
CVE-2026-9282CVE-2026-9282
CVSS 7.5
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This ma…
CVE-2026-92816CVE-2026-92816
CVSS 7.8
ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output direct…
CVE-2026-92815CVE-2026-92815
CVSS 7.5
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Atta…
CVE-2026-92814CVE-2026-92814
CVSS 4.2
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malici…
CVE-2026-92813CVE-2026-92813
CVSS 4.9
Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopbac…
CVE-2026-92812CVE-2026-92812
CVSS 6.8
decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator valid…
CVE-2026-92811CVE-2026-92811
CVSS 6.5
browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders t…
CVE-2026-92810CVE-2026-92810
CVSS 4.3
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retriev…
CVE-2026-9281CVE-2026-9281
CVSS 6.4
The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scr…
CVE-2026-92809CVE-2026-92809
CVSS 4.3
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers c…
CVE-2026-92808CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can caus…
CVE-2026-92807CVE-2026-92807
CVSS 8.8
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf…
CVE-2026-92806CVE-2026-92806
CVSS 8.1
phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in a…
CVE-2026-92805CVE-2026-92805
CVSS 9.8
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unaut…
CVE-2026-92804CVE-2026-92804
CVSS 7.1
Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated …
CVE-2026-92803CVE-2026-92803
CVSS 5.3
LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can …
CVE-2026-92802CVE-2026-92802
CVSS 4.3
kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking…
CVE-2026-92801CVE-2026-92801
CVSS 8.8
cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatc…
CVE-2026-92800CVE-2026-92800
CVSS 6.8
Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can re…
CVE-2026-9280CVE-2026-9280
CVSS 6.1
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versio…
CVE-2026-92799CVE-2026-92799
CVSS 5.3
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions …
CVE-2026-92796CVE-2026-92796
CVSS 8.8
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to exe…
CVE-2026-92795CVE-2026-92795
CVSS 6.5
Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch inter…
CVE-2026-92794CVE-2026-92794
CVSS 7.5
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supp…
CVE-2026-92793CVE-2026-92793
CVSS 8.1
GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appen…
CVE-2026-92792CVE-2026-92792
CVSS 7.5
OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the Fallbac…
CVE-2026-92791CVE-2026-92791
CVSS 7.5
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configur…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.