92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,301–3,350 of 92,816 · page 67 of 1857

IDTitleSummary
CVE-2026-92720CVE-2026-92720
CVSS 9.1
Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and se…
CVE-2026-9272CVE-2026-9272
CVSS 8.1progress
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the A…
CVE-2026-92719CVE-2026-92719
CVSS 7.5
Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests…
CVE-2026-92718CVE-2026-92718
CVSS 7.3
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verif…
CVE-2026-92717CVE-2026-92717
CVSS 9.1
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and re…
CVE-2026-92716CVE-2026-92716
CVSS 9.6
Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and re…
CVE-2026-92714CVE-2026-92714
CVSS 6.5
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() functi…
CVE-2026-92713CVE-2026-92713
CVSS 8.1
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in…
CVE-2026-92712CVE-2026-92712
CVSS 6.4
The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions…
CVE-2026-9271CVE-2026-9271
CVSS 5.9
Vulnerability Title
CVE-2026-92708CVE-2026-92708
CVSS 7.5
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, s…
CVE-2026-92706CVE-2026-92706
CVSS 3.4
Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversi…
CVE-2026-92705CVE-2026-92705
CVSS 7.8
Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` me…
CVE-2026-92702CVE-2026-92702
CVSS 9.1
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-ha…
CVE-2026-92701CVE-2026-92701
CVSS 9.1
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-ha…
CVE-2026-92700CVE-2026-92700Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() us…
CVE-2026-9270CVE-2026-9270
CVSS 9.1binary
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of …
CVE-2026-92692CVE-2026-92692Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines hav…
CVE-2026-9269CVE-2026-9269
CVSS 3.5
The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high …
CVE-2026-92680CVE-2026-92680
CVSS 5.5
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply suff…
CVE-2026-9267CVE-2026-9267Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function…
CVE-2026-9266CVE-2026-9266A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulner…
CVE-2026-9265CVE-2026-9265Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 a…
CVE-2026-9264CVE-2026-9264
CVSS 9.3
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through malic…
CVE-2026-9263CVE-2026-9263
CVSS 6.5zephyrproject
The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start s…
CVE-2026-92628CVE-2026-92628
CVSS 3.1gitlab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race con…
CVE-2026-92627CVE-2026-92627A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-p…
CVE-2026-92626CVE-2026-92626
CVSS 7.5
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint derefer…
CVE-2026-92625CVE-2026-92625
CVSS 7.5
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable wit…
CVE-2026-92622CVE-2026-92622
CVSS 6.4
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and i…
CVE-2026-9262CVE-2026-9262
CVSS 6.5canon
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-92619CVE-2026-92619
CVSS 7.2
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJ…
CVE-2026-92616CVE-2026-92616
CVSS 6.8
FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and wr…
CVE-2026-92615CVE-2026-92615
CVSS 6.6
A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include Insecu…
CVE-2026-92612CVE-2026-92612In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts tho…
CVE-2026-92611CVE-2026-92611In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single…
CVE-2026-9261CVE-2026-9261
CVSS 6.8canon
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-92609CVE-2026-92609
CVSS 9.8apache
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a se…
CVE-2026-92608CVE-2026-92608
CVSS 7.5apache
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQ…
CVE-2026-92605CVE-2026-92605
CVSS 6.5
IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers wi…
CVE-2026-92604CVE-2026-92604
CVSS 8.1
Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacke…
CVE-2026-92603CVE-2026-92603
CVSS 6.5
ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete o…
CVE-2026-92602CVE-2026-92602
CVSS 7.1
TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attac…
CVE-2026-92601CVE-2026-92601
CVSS 6.5
Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by…
CVE-2026-92600CVE-2026-92600
CVSS 6.5
Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermiss…
CVE-2026-9260CVE-2026-9260
CVSS 6.2canon
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-92599CVE-2026-92599
CVSS 7.5
joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().is…
CVE-2026-92598CVE-2026-92598
CVSS 6.5
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punyco…
CVE-2026-92597CVE-2026-92597
CVSS 6.5
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break…
CVE-2026-92596CVE-2026-92596
CVSS 7.5
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of servi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.