92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,451–3,500 of 92,816 · page 70 of 1857

IDTitleSummary
CVE-2026-92486CVE-2026-92486In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF subprograms use the bpf_callback_t ABI, b…
CVE-2026-92485CVE-2026-92485
CVSS 7.8
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The trampoline could be corrupted by the bli…
CVE-2026-92484CVE-2026-92484In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_ways() error path The error path releases …
CVE-2026-92483CVE-2026-92483In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeps track of successful retrieve attempt…
CVE-2026-92482CVE-2026-92482In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated …
CVE-2026-92481CVE-2026-92481In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain…
CVE-2026-92480CVE-2026-92480In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The string descriptor length includes a two-…
CVE-2026-9248CVE-2026-9248
CVSS 2.6devolutions
Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation a…
CVE-2026-92479CVE-2026-92479In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell com…
CVE-2026-92478CVE-2026-92478In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts The connected lane count is used by TX eq…
CVE-2026-92477CVE-2026-92477In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string terminator ufs_saved_err_write() copies us…
CVE-2026-92476CVE-2026-92476In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requesting IRQ kmb_ocs_aes_probe() request…
CVE-2026-92475CVE-2026-92475
CVSS 5.3
A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of …
CVE-2026-92474CVE-2026-92474
CVSS 3.3
A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the compo…
CVE-2026-92473CVE-2026-92473
CVSS 3.3
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component…
CVE-2026-92472CVE-2026-92472
CVSS 3.3
A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/scenegraph/base_scenegraph.c of th…
CVE-2026-92470CVE-2026-92470
CVSS 7.7gitlab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain condi…
CVE-2026-9247CVE-2026-9247
CVSS 2.4devolutions
Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without tr…
CVE-2026-92469CVE-2026-92469
CVSS 8.1
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs…
CVE-2026-92468CVE-2026-92468
CVSS 6.5
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to…
CVE-2026-92467CVE-2026-92467
CVSS 8.3
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated…
CVE-2026-92466CVE-2026-92466
CVSS 8.8
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to f…
CVE-2026-92465CVE-2026-92465
CVSS 7.6
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This is…
CVE-2026-92463CVE-2026-92463
CVSS 6.5
yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, …
CVE-2026-92462CVE-2026-92462
CVSS 6.5
yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to …
CVE-2026-92461CVE-2026-92461
CVSS 4.3
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office…
CVE-2026-92460CVE-2026-92460
CVSS 6.5
yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to acces…
CVE-2026-9246CVE-2026-9246
CVSS 4.3devolutions
Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retriev…
CVE-2026-92459CVE-2026-92459
CVSS 6.5
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office…
CVE-2026-92458CVE-2026-92458
CVSS 4.3
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users…
CVE-2026-92457CVE-2026-92457
CVSS 6.5
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office …
CVE-2026-92456CVE-2026-92456
CVSS 7.1
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-…
CVE-2026-92455CVE-2026-92455
CVSS 4.3
yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office u…
CVE-2026-9245CVE-2026-9245
CVSS 5.0devolutions
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to a…
CVE-2026-9244CVE-2026-9244Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-92438CVE-2026-92438
CVSS 8.8
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, whi…
CVE-2026-92437CVE-2026-92437
CVSS 5.3
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandon…
CVE-2026-92436CVE-2026-92436
CVSS 5.3
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-suppli…
CVE-2026-92435CVE-2026-92435
CVSS 5.3
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback f…
CVE-2026-92430CVE-2026-92430
CVSS 5.3
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook be…
CVE-2026-9243CVE-2026-9243
CVSS 6.4
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything…
CVE-2026-92425CVE-2026-92425
CVSS 5.5
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of it…
CVE-2026-92424CVE-2026-92424
CVSS 6.8
The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they se…
CVE-2026-92423CVE-2026-92423
CVSS 2.7
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returni…
CVE-2026-92422CVE-2026-92422
CVSS 6.5
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes …
CVE-2026-92421CVE-2026-92421
CVSS 4.7
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the …
CVE-2026-92420CVE-2026-92420
CVSS 3.8
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user befor…
CVE-2026-9242CVE-2026-9242
CVSS 5.3
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via I…
CVE-2026-92419CVE-2026-92419WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation c…
CVE-2026-92418CVE-2026-92418
CVSS 3.5
A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.