92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,301–3,350 of 92,816 · page 67 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-92720 | CVE-2026-92720 CVSS 9.1 | Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and se… |
| CVE-2026-9272 | CVE-2026-9272 CVSS 8.1progress | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the A… |
| CVE-2026-92719 | CVE-2026-92719 CVSS 7.5 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests… |
| CVE-2026-92718 | CVE-2026-92718 CVSS 7.3 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verif… |
| CVE-2026-92717 | CVE-2026-92717 CVSS 9.1 | Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and re… |
| CVE-2026-92716 | CVE-2026-92716 CVSS 9.6 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and re… |
| CVE-2026-92714 | CVE-2026-92714 CVSS 6.5 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() functi… |
| CVE-2026-92713 | CVE-2026-92713 CVSS 8.1 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in… |
| CVE-2026-92712 | CVE-2026-92712 CVSS 6.4 | The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions… |
| CVE-2026-9271 | CVE-2026-9271 CVSS 5.9 | Vulnerability Title |
| CVE-2026-92708 | CVE-2026-92708 CVSS 7.5 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, s… |
| CVE-2026-92706 | CVE-2026-92706 CVSS 3.4 | Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversi… |
| CVE-2026-92705 | CVE-2026-92705 CVSS 7.8 | Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` me… |
| CVE-2026-92702 | CVE-2026-92702 CVSS 9.1 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-ha… |
| CVE-2026-92701 | CVE-2026-92701 CVSS 9.1 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-ha… |
| CVE-2026-92700 | CVE-2026-92700 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() us… |
| CVE-2026-9270 | CVE-2026-9270 CVSS 9.1binary | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of … |
| CVE-2026-92692 | CVE-2026-92692 | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines hav… |
| CVE-2026-9269 | CVE-2026-9269 CVSS 3.5 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high … |
| CVE-2026-92680 | CVE-2026-92680 CVSS 5.5 | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply suff… |
| CVE-2026-9267 | CVE-2026-9267 | Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function… |
| CVE-2026-9266 | CVE-2026-9266 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulner… |
| CVE-2026-9265 | CVE-2026-9265 | Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 a… |
| CVE-2026-9264 | CVE-2026-9264 CVSS 9.3 | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through malic… |
| CVE-2026-9263 | CVE-2026-9263 CVSS 6.5zephyrproject | The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start s… |
| CVE-2026-92628 | CVE-2026-92628 CVSS 3.1gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race con… |
| CVE-2026-92627 | CVE-2026-92627 | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-p… |
| CVE-2026-92626 | CVE-2026-92626 CVSS 7.5 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint derefer… |
| CVE-2026-92625 | CVE-2026-92625 CVSS 7.5 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable wit… |
| CVE-2026-92622 | CVE-2026-92622 CVSS 6.4 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and i… |
| CVE-2026-9262 | CVE-2026-9262 CVSS 6.5canon | Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-92619 | CVE-2026-92619 CVSS 7.2 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJ… |
| CVE-2026-92616 | CVE-2026-92616 CVSS 6.8 | FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and wr… |
| CVE-2026-92615 | CVE-2026-92615 CVSS 6.6 | A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include Insecu… |
| CVE-2026-92612 | CVE-2026-92612 | In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts tho… |
| CVE-2026-92611 | CVE-2026-92611 | In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single… |
| CVE-2026-9261 | CVE-2026-9261 CVSS 6.8canon | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-92609 | CVE-2026-92609 CVSS 9.8apache | Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a se… |
| CVE-2026-92608 | CVE-2026-92608 CVSS 7.5apache | Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQ… |
| CVE-2026-92605 | CVE-2026-92605 CVSS 6.5 | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers wi… |
| CVE-2026-92604 | CVE-2026-92604 CVSS 8.1 | Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacke… |
| CVE-2026-92603 | CVE-2026-92603 CVSS 6.5 | ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete o… |
| CVE-2026-92602 | CVE-2026-92602 CVSS 7.1 | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attac… |
| CVE-2026-92601 | CVE-2026-92601 CVSS 6.5 | Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by… |
| CVE-2026-92600 | CVE-2026-92600 CVSS 6.5 | Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermiss… |
| CVE-2026-9260 | CVE-2026-9260 CVSS 6.2canon | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-92599 | CVE-2026-92599 CVSS 7.5 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().is… |
| CVE-2026-92598 | CVE-2026-92598 CVSS 6.5 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punyco… |
| CVE-2026-92597 | CVE-2026-92597 CVSS 6.5 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break… |
| CVE-2026-92596 | CVE-2026-92596 CVSS 7.5 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of servi… |