92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,251–3,300 of 92,816 · page 66 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-92790 | CVE-2026-92790 CVSS 6.5 | Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action … |
| CVE-2026-9279 | CVE-2026-9279 | Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, `pandoc`, … |
| CVE-2026-92789 | CVE-2026-92789 CVSS 6.5 | Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers wi… |
| CVE-2026-92788 | CVE-2026-92788 CVSS 8.8 | Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can … |
| CVE-2026-92787 | CVE-2026-92787 CVSS 9.8 | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by pres… |
| CVE-2026-92786 | CVE-2026-92786 CVSS 7.8 | LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP pr… |
| CVE-2026-92785 | CVE-2026-92785 CVSS 8.1 | Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attack… |
| CVE-2026-92784 | CVE-2026-92784 CVSS 7.5 | @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data prov… |
| CVE-2026-92783 | CVE-2026-92783 CVSS 8.1 | Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control rel… |
| CVE-2026-92782 | CVE-2026-92782 CVSS 8.1 | Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from oth… |
| CVE-2026-92781 | CVE-2026-92781 CVSS 6.3 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttribu… |
| CVE-2026-92780 | CVE-2026-92780 CVSS 8.8 | KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality… |
| CVE-2026-9278 | CVE-2026-9278 CVSS 5.4 | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-sid… |
| CVE-2026-92779 | CVE-2026-92779 CVSS 7.6 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content blo… |
| CVE-2026-92778 | CVE-2026-92778 CVSS 5.4 | CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers … |
| CVE-2026-92776 | CVE-2026-92776 CVSS 8.1 | Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with autho… |
| CVE-2026-92775 | CVE-2026-92775 CVSS 6.5 | Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host,… |
| CVE-2026-92774 | CVE-2026-92774 CVSS 4.3 | Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attacke… |
| CVE-2026-92773 | CVE-2026-92773 CVSS 7.1 | Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can c… |
| CVE-2026-92772 | CVE-2026-92772 CVSS 7.1 | Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users … |
| CVE-2026-92771 | CVE-2026-92771 CVSS 6.5 | Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permissio… |
| CVE-2026-92770 | CVE-2026-92770 CVSS 6.5 | Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit… |
| CVE-2026-9277 | CVE-2026-9277 CVSS 8.1 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped chara… |
| CVE-2026-92768 | CVE-2026-92768 CVSS 5.5 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext pass… |
| CVE-2026-92767 | CVE-2026-92767 CVSS 6.4 | The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and i… |
| CVE-2026-92765 | CVE-2026-92765 CVSS 6.5 | ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings … |
| CVE-2026-92764 | CVE-2026-92764 CVSS 4.3 | OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's m… |
| CVE-2026-92763 | CVE-2026-92763 CVSS 8.1 | Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with onl… |
| CVE-2026-92762 | CVE-2026-92762 CVSS 8.8 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. … |
| CVE-2026-92761 | CVE-2026-92761 CVSS 8.8 | WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-on… |
| CVE-2026-92760 | CVE-2026-92760 CVSS 6.5 | Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. … |
| CVE-2026-92759 | CVE-2026-92759 CVSS 6.5 | SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password… |
| CVE-2026-92758 | CVE-2026-92758 CVSS 5.5mongodb | If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwo… |
| CVE-2026-92757 | CVE-2026-92757 CVSS 5.5mongodb | Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encrypt… |
| CVE-2026-92756 | CVE-2026-92756 CVSS 5.5mongodb | Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently… |
| CVE-2026-92754 | CVE-2026-92754 CVSS 4.3 | PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented … |
| CVE-2026-92753 | CVE-2026-92753 CVSS 7.1 | PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated… |
| CVE-2026-92752 | CVE-2026-92752 CVSS 8.3 | metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissi… |
| CVE-2026-92751 | CVE-2026-92751 CVSS 8.1 | CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated oper… |
| CVE-2026-92750 | CVE-2026-92750 CVSS 6.5 | Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configura… |
| CVE-2026-92749 | CVE-2026-92749 CVSS 8.1 | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key … |
| CVE-2026-92748 | CVE-2026-92748 CVSS 8.8 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbi… |
| CVE-2026-92747 | CVE-2026-92747 CVSS 5.0 | A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virt… |
| CVE-2026-92746 | CVE-2026-92746 CVSS 6.4 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixM… |
| CVE-2026-92745 | CVE-2026-92745 CVSS 5.0 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat S… |
| CVE-2026-9274 | CVE-2026-9274 | This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could… |
| CVE-2026-92730 | CVE-2026-92730 | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey-participant CSV import result page. |
| CVE-2026-9273 | CVE-2026-9273 CVSS 9.3 | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account … |
| CVE-2026-92729 | CVE-2026-92729 CVSS 8.2 | SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers … |
| CVE-2026-92727 | CVE-2026-92727 CVSS 6.4 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross… |