92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,501–3,550 of 92,816 · page 71 of 1857

IDTitleSummary
CVE-2026-92417CVE-2026-92417
CVSS 6.5
A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component …
CVE-2026-92416CVE-2026-92416
CVSS 4.3
A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handl…
CVE-2026-92415CVE-2026-92415— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or a…
CVE-2026-92414CVE-2026-92414: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any …
CVE-2026-92413CVE-2026-92413
CVSS 4.3
A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the fi…
CVE-2026-92412CVE-2026-92412
CVSS 7.1
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing …
CVE-2026-92411CVE-2026-92411
CVSS 6.8
The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it o…
CVE-2026-92410CVE-2026-92410
CVSS 4.3
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to del…
CVE-2026-92406CVE-2026-92406
CVSS 7.3
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments…
CVE-2026-92405CVE-2026-92405
CVSS 7.3
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /inde…
CVE-2026-92404CVE-2026-92404
CVSS 7.5
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve th…
CVE-2026-92403CVE-2026-92403
CVSS 3.7
The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to t…
CVE-2026-92402CVE-2026-92402
CVSS 6.3
A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserCo…
CVE-2026-92401CVE-2026-92401
CVSS 7.3
A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils…
CVE-2026-92400CVE-2026-92400
CVSS 5.3
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's …
CVE-2026-9240CVE-2026-9240
CVSS 4.3
The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi…
CVE-2026-92399CVE-2026-92399
CVSS 7.3
A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket …
CVE-2026-92398CVE-2026-92398
CVSS 9.1
A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the …
CVE-2026-92397CVE-2026-92397
CVSS 9.1
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of …
CVE-2026-92395CVE-2026-92395
CVSS 9.1
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.…
CVE-2026-92393CVE-2026-92393Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn ar…
CVE-2026-92385CVE-2026-92385
CVSS 2.4
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_categor…
CVE-2026-92383CVE-2026-92383
CVSS 4.3
A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the fil…
CVE-2026-92382CVE-2026-92382
CVSS 4.1
An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer per…
CVE-2026-92381CVE-2026-92381
CVSS 3.5
A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.ph…
CVE-2026-92380CVE-2026-92380
CVSS 7.3
A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the c…
CVE-2026-92378CVE-2026-92378A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Se…
CVE-2026-92371CVE-2026-92371
CVSS 7.0
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functiona…
CVE-2026-92370CVE-2026-92370
CVSS 8.8
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated rem…
CVE-2026-9237CVE-2026-9237
CVSS 4.3
The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin…
CVE-2026-92369CVE-2026-92369
CVSS 7.3
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged a…
CVE-2026-92368CVE-2026-92368
CVSS 7.8
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session re…
CVE-2026-92366CVE-2026-92366
CVSS 7.3
A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. T…
CVE-2026-92365CVE-2026-92365
CVSS 4.3
A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_st…
CVE-2026-92364CVE-2026-92364
CVSS 6.3
A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/empl…
CVE-2026-92363CVE-2026-92363
CVSS 4.3
A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executin…
CVE-2026-92362CVE-2026-92362
CVSS 7.3
A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Fram…
CVE-2026-92361CVE-2026-92361
CVSS 4.3
A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go…
CVE-2026-92360CVE-2026-92360
CVSS 6.3
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the compone…
CVE-2026-9236CVE-2026-9236
CVSS 4.3
The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …
CVE-2026-92359CVE-2026-92359
CVSS 3.1
A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands…
CVE-2026-92358CVE-2026-92358
CVSS 6.4
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is cre…
CVE-2026-92357CVE-2026-92357
CVSS 4.3
A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processo…
CVE-2026-92356CVE-2026-92356
CVSS 4.3
A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component…
CVE-2026-92355CVE-2026-92355In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary…
CVE-2026-9235CVE-2026-9235
CVSS 4.3
The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check …
CVE-2026-9234CVE-2026-9234
CVSS 4.3
The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing c…
CVE-2026-9233CVE-2026-9233
CVSS 4.3
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …
CVE-2026-9232CVE-2026-9232
CVSS 6.5
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_custome…
CVE-2026-9231CVE-2026-9231
CVSS 7.5
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.