92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,451–3,500 of 92,816 · page 70 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-92486 | CVE-2026-92486 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF subprograms use the bpf_callback_t ABI, b… |
| CVE-2026-92485 | CVE-2026-92485 CVSS 7.8 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the bli… |
| CVE-2026-92484 | CVE-2026-92484 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_ways() error path The error path releases … |
| CVE-2026-92483 | CVE-2026-92483 | In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeps track of successful retrieve attempt… |
| CVE-2026-92482 | CVE-2026-92482 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated … |
| CVE-2026-92481 | CVE-2026-92481 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain… |
| CVE-2026-92480 | CVE-2026-92480 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The string descriptor length includes a two-… |
| CVE-2026-9248 | CVE-2026-9248 CVSS 2.6devolutions | Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation a… |
| CVE-2026-92479 | CVE-2026-92479 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell com… |
| CVE-2026-92478 | CVE-2026-92478 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts The connected lane count is used by TX eq… |
| CVE-2026-92477 | CVE-2026-92477 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string terminator ufs_saved_err_write() copies us… |
| CVE-2026-92476 | CVE-2026-92476 | In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requesting IRQ kmb_ocs_aes_probe() request… |
| CVE-2026-92475 | CVE-2026-92475 CVSS 5.3 | A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of … |
| CVE-2026-92474 | CVE-2026-92474 CVSS 3.3 | A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the compo… |
| CVE-2026-92473 | CVE-2026-92473 CVSS 3.3 | A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component… |
| CVE-2026-92472 | CVE-2026-92472 CVSS 3.3 | A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of th… |
| CVE-2026-92470 | CVE-2026-92470 CVSS 7.7gitlab | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain condi… |
| CVE-2026-9247 | CVE-2026-9247 CVSS 2.4devolutions | Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without tr… |
| CVE-2026-92469 | CVE-2026-92469 CVSS 8.1 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs… |
| CVE-2026-92468 | CVE-2026-92468 CVSS 6.5 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to… |
| CVE-2026-92467 | CVE-2026-92467 CVSS 8.3 | zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated… |
| CVE-2026-92466 | CVE-2026-92466 CVSS 8.8 | zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to f… |
| CVE-2026-92465 | CVE-2026-92465 CVSS 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This is… |
| CVE-2026-92463 | CVE-2026-92463 CVSS 6.5 | yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, … |
| CVE-2026-92462 | CVE-2026-92462 CVSS 6.5 | yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to … |
| CVE-2026-92461 | CVE-2026-92461 CVSS 4.3 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office… |
| CVE-2026-92460 | CVE-2026-92460 CVSS 6.5 | yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to acces… |
| CVE-2026-9246 | CVE-2026-9246 CVSS 4.3devolutions | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retriev… |
| CVE-2026-92459 | CVE-2026-92459 CVSS 6.5 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office… |
| CVE-2026-92458 | CVE-2026-92458 CVSS 4.3 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users… |
| CVE-2026-92457 | CVE-2026-92457 CVSS 6.5 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office … |
| CVE-2026-92456 | CVE-2026-92456 CVSS 7.1 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-… |
| CVE-2026-92455 | CVE-2026-92455 CVSS 4.3 | yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office u… |
| CVE-2026-9245 | CVE-2026-9245 CVSS 5.0devolutions | Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to a… |
| CVE-2026-9244 | CVE-2026-9244 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-92438 | CVE-2026-92438 CVSS 8.8 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, whi… |
| CVE-2026-92437 | CVE-2026-92437 CVSS 5.3 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandon… |
| CVE-2026-92436 | CVE-2026-92436 CVSS 5.3 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-suppli… |
| CVE-2026-92435 | CVE-2026-92435 CVSS 5.3 | The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback f… |
| CVE-2026-92430 | CVE-2026-92430 CVSS 5.3 | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook be… |
| CVE-2026-9243 | CVE-2026-9243 CVSS 6.4 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything… |
| CVE-2026-92425 | CVE-2026-92425 CVSS 5.5 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of it… |
| CVE-2026-92424 | CVE-2026-92424 CVSS 6.8 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they se… |
| CVE-2026-92423 | CVE-2026-92423 CVSS 2.7 | The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returni… |
| CVE-2026-92422 | CVE-2026-92422 CVSS 6.5 | The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes … |
| CVE-2026-92421 | CVE-2026-92421 CVSS 4.7 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the … |
| CVE-2026-92420 | CVE-2026-92420 CVSS 3.8 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user befor… |
| CVE-2026-9242 | CVE-2026-9242 CVSS 5.3 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via I… |
| CVE-2026-92419 | CVE-2026-92419 | WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation c… |
| CVE-2026-92418 | CVE-2026-92418 CVSS 3.5 | A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/… |