92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,351–3,400 of 92,816 · page 68 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-92595 | CVE-2026-92595 CVSS 5.9 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message conte… |
| CVE-2026-92594 | CVE-2026-92594 CVSS 7.5 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-dat… |
| CVE-2026-92593 | CVE-2026-92593 CVSS 8.8 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() … |
| CVE-2026-92592 | CVE-2026-92592 CVSS 8.8 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used… |
| CVE-2026-92591 | CVE-2026-92591 CVSS 5.9 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — includin… |
| CVE-2026-92590 | CVE-2026-92590 CVSS 5.4 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescapin… |
| CVE-2026-9259 | CVE-2026-9259 CVSS 6.5canon | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-92589 | CVE-2026-92589 CVSS 4.3 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control… |
| CVE-2026-92588 | CVE-2026-92588 CVSS 4.4 | n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push f… |
| CVE-2026-92587 | CVE-2026-92587 CVSS 5.0 | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured rep… |
| CVE-2026-92586 | CVE-2026-92586 CVSS 4.3 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authen… |
| CVE-2026-92585 | CVE-2026-92585 CVSS 4.3 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in u… |
| CVE-2026-92584 | CVE-2026-92584 CVSS 6.1 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoA… |
| CVE-2026-92583 | CVE-2026-92583 CVSS 6.5 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to … |
| CVE-2026-92582 | CVE-2026-92582 CVSS 7.1 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF… |
| CVE-2026-92581 | CVE-2026-92581 CVSS 4.3 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchroni… |
| CVE-2026-92580 | CVE-2026-92580 CVSS 8.8 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH … |
| CVE-2026-9258 | CVE-2026-9258 CVSS 6.5canon | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-92579 | CVE-2026-92579 CVSS 5.4 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin file… |
| CVE-2026-92578 | CVE-2026-92578 CVSS 8.1 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two ind… |
| CVE-2026-92577 | CVE-2026-92577 CVSS 7.5 | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restric… |
| CVE-2026-92576 | CVE-2026-92576 CVSS 8.6 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block… |
| CVE-2026-92574 | CVE-2026-92574 CVSS 8.8 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes sec… |
| CVE-2026-92573 | CVE-2026-92573 CVSS 6.5apache | Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP ma… |
| CVE-2026-92571 | CVE-2026-92571 | Rejected reason: CVE ID reserved in error and not assigned to a vulnerability. The correct CVE ID is CVE-2026-92574. |
| CVE-2026-92570 | CVE-2026-92570 CVSS 6.5 | reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled rec… |
| CVE-2026-92569 | CVE-2026-92569 CVSS 4.3 | Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress param… |
| CVE-2026-92568 | CVE-2026-92568 CVSS 5.4 | MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API se… |
| CVE-2026-92567 | CVE-2026-92567 CVSS 6.5 | TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated user… |
| CVE-2026-92566 | CVE-2026-92566 CVSS 8.2 | DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to exec… |
| CVE-2026-92565 | CVE-2026-92565 CVSS 5.3 | Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addr… |
| CVE-2026-92564 | CVE-2026-92564 CVSS 7.5apache | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qp… |
| CVE-2026-92561 | CVE-2026-92561 CVSS 6.1 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.… |
| CVE-2026-92560 | CVE-2026-92560 CVSS 7.5apache | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects… |
| CVE-2026-9256 | CVE-2026-9256 CVSS 8.1f5 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pa… |
| CVE-2026-92555 | CVE-2026-92555 CVSS 9.8 | Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Pan… |
| CVE-2026-92554 | CVE-2026-92554 CVSS 6.1 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String… |
| CVE-2026-92551 | CVE-2026-92551 CVSS 6.1 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to… |
| CVE-2026-92550 | CVE-2026-92550 CVSS 7.5apache | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects… |
| CVE-2026-9255 | CVE-2026-9255 CVSS 7.8amazon | Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell … |
| CVE-2026-92548 | CVE-2026-92548 CVSS 5.3 | The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' paramet… |
| CVE-2026-92543 | CVE-2026-92543 | Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CID… |
| CVE-2026-92542 | CVE-2026-92542 | The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams se… |
| CVE-2026-92541 | CVE-2026-92541 CVSS 7.2 | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, al… |
| CVE-2026-92540 | CVE-2026-92540 CVSS 7.2 | The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a C… |
| CVE-2026-9254 | CVE-2026-9254 | An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper f… |
| CVE-2026-92538 | CVE-2026-92538 CVSS 6.1 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the… |
| CVE-2026-92537 | CVE-2026-92537 CVSS 5.3 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and inclu… |
| CVE-2026-92536 | CVE-2026-92536 CVSS 8.8 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to… |
| CVE-2026-92533 | CVE-2026-92533 | Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplie… |