92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,551–3,600 of 92,816 · page 72 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9230 | CVE-2026-9230 CVSS 4.3 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … |
| CVE-2026-92299 | CVE-2026-92299 CVSS 7.4 | @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in th… |
| CVE-2026-92298 | CVE-2026-92298 CVSS 4.8 | EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographicall… |
| CVE-2026-92289 | CVE-2026-92289 CVSS 9.1 | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPoint… |
| CVE-2026-92288 | CVE-2026-92288 CVSS 9.1 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndP… |
| CVE-2026-92284 | CVE-2026-92284 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body r… |
| CVE-2026-9226 | CVE-2026-9226 CVSS 6.8 | Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account v… |
| CVE-2026-92259 | CVE-2026-92259 CVSS 5.5 | Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-… |
| CVE-2026-92257 | CVE-2026-92257 CVSS 5.4 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the cal… |
| CVE-2026-92256 | CVE-2026-92256 CVSS 6.5 | NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json… |
| CVE-2026-92255 | CVE-2026-92255 CVSS 5.4 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Att… |
| CVE-2026-92254 | CVE-2026-92254 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Mic… |
| CVE-2026-92253 | CVE-2026-92253 | Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attack… |
| CVE-2026-92252 | CVE-2026-92252 | Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete a… |
| CVE-2026-9225 | CVE-2026-9225 CVSS 6.5langflow | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access … |
| CVE-2026-92249 | CVE-2026-92249 CVSS 6.1 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.… |
| CVE-2026-92248 | CVE-2026-92248 CVSS 7.8 | A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer ov… |
| CVE-2026-92247 | CVE-2026-92247 CVSS 4.7 | A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of th… |
| CVE-2026-92245 | CVE-2026-92245 CVSS 7.5 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the '… |
| CVE-2026-92244 | CVE-2026-92244 CVSS 7.2 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company… |
| CVE-2026-92243 | CVE-2026-92243 CVSS 6.1 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, an… |
| CVE-2026-92240 | CVE-2026-92240 CVSS 9.1mozilla | A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbi… |
| CVE-2026-9224 | CVE-2026-9224 CVSS 4.3devolutions | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attrib… |
| CVE-2026-92239 | CVE-2026-92239 CVSS 8.1mozilla | A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderb… |
| CVE-2026-92238 | CVE-2026-92238 CVSS 9.8mozilla | A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in… |
| CVE-2026-92237 | CVE-2026-92237 CVSS 6.5 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authentic… |
| CVE-2026-92235 | CVE-2026-92235 CVSS 8.1 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the … |
| CVE-2026-92234 | CVE-2026-92234 CVSS 5.4 | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page… |
| CVE-2026-92232 | CVE-2026-92232 CVSS 6.5joomla | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanA… |
| CVE-2026-92231 | CVE-2026-92231 CVSS 6.7joomla | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute me… |
| CVE-2026-92230 | CVE-2026-92230 CVSS 7.5 | Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outli… |
| CVE-2026-9223 | CVE-2026-9223 CVSS 4.3devolutions | Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vault… |
| CVE-2026-92229 | CVE-2026-92229 CVSS 9.1 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions… |
| CVE-2026-92227 | CVE-2026-92227 CVSS 7.5joomla | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an remem… |
| CVE-2026-92226 | CVE-2026-92226 CVSS 6.0joomla | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows un… |
| CVE-2026-92225 | CVE-2026-92225 CVSS 6.7joomla | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values,… |
| CVE-2026-92224 | CVE-2026-92224 CVSS 6.7joomla | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, lead… |
| CVE-2026-92223 | CVE-2026-92223 CVSS 3.8joomla | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthor… |
| CVE-2026-92222 | CVE-2026-92222 CVSS 8.0joomla | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improper… |
| CVE-2026-92221 | CVE-2026-92221 CVSS 4.7 | A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function… |
| CVE-2026-92220 | CVE-2026-92220 CVSS 5.3 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_fini… |
| CVE-2026-9222 | CVE-2026-9222 CVSS 8.1 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from th… |
| CVE-2026-92217 | CVE-2026-92217 CVSS 6.3 | A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/… |
| CVE-2026-92216 | CVE-2026-92216 CVSS 4.3 | A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/g… |
| CVE-2026-92215 | CVE-2026-92215 CVSS 7.3 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_a… |
| CVE-2026-92214 | CVE-2026-92214 CVSS 3.5 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/… |
| CVE-2026-92213 | CVE-2026-92213 CVSS 5.5 | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client… |
| CVE-2026-92212 | CVE-2026-92212 CVSS 6.1 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parame… |
| CVE-2026-9221 | CVE-2026-9221 CVSS 7.5 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communicatio… |
| CVE-2026-9220 | CVE-2026-9220 CVSS 7.5 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES ke… |