92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,551–3,600 of 92,816 · page 72 of 1857

IDTitleSummary
CVE-2026-9230CVE-2026-9230
CVSS 4.3
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …
CVE-2026-92299CVE-2026-92299
CVSS 7.4
@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in th…
CVE-2026-92298CVE-2026-92298
CVSS 4.8
EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographicall…
CVE-2026-92289CVE-2026-92289
CVSS 9.1
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPoint…
CVE-2026-92288CVE-2026-92288
CVSS 9.1
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndP…
CVE-2026-92284CVE-2026-92284Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/replacer.go, resolving http.request.body r…
CVE-2026-9226CVE-2026-9226
CVSS 6.8
Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account v…
CVE-2026-92259CVE-2026-92259
CVSS 5.5
Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-…
CVE-2026-92257CVE-2026-92257
CVSS 5.4
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the cal…
CVE-2026-92256CVE-2026-92256
CVSS 6.5
NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json…
CVE-2026-92255CVE-2026-92255
CVSS 5.4
Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Att…
CVE-2026-92254CVE-2026-92254Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Mic…
CVE-2026-92253CVE-2026-92253Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Windows allows local, low-privileged attack…
CVE-2026-92252CVE-2026-92252Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete a…
CVE-2026-9225CVE-2026-9225
CVSS 6.5langflow
IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access …
CVE-2026-92249CVE-2026-92249
CVSS 6.1
The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.…
CVE-2026-92248CVE-2026-92248
CVSS 7.8
A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer ov…
CVE-2026-92247CVE-2026-92247
CVSS 4.7
A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of th…
CVE-2026-92245CVE-2026-92245
CVSS 7.5
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the '…
CVE-2026-92244CVE-2026-92244
CVSS 7.2
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company…
CVE-2026-92243CVE-2026-92243
CVSS 6.1
The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, an…
CVE-2026-92240CVE-2026-92240
CVSS 9.1mozilla
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbi…
CVE-2026-9224CVE-2026-9224
CVSS 4.3devolutions
Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attrib…
CVE-2026-92239CVE-2026-92239
CVSS 8.1mozilla
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderb…
CVE-2026-92238CVE-2026-92238
CVSS 9.8mozilla
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in…
CVE-2026-92237CVE-2026-92237
CVSS 6.5
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authentic…
CVE-2026-92235CVE-2026-92235
CVSS 8.1
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the …
CVE-2026-92234CVE-2026-92234
CVSS 5.4
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page…
CVE-2026-92232CVE-2026-92232
CVSS 6.5joomla
Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanA…
CVE-2026-92231CVE-2026-92231
CVSS 6.7joomla
Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute me…
CVE-2026-92230CVE-2026-92230
CVSS 7.5
Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outli…
CVE-2026-9223CVE-2026-9223
CVSS 4.3devolutions
Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vault…
CVE-2026-92229CVE-2026-92229
CVSS 9.1
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions…
CVE-2026-92227CVE-2026-92227
CVSS 7.5joomla
Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an remem…
CVE-2026-92226CVE-2026-92226
CVSS 6.0joomla
Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows un…
CVE-2026-92225CVE-2026-92225
CVSS 6.7joomla
Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values,…
CVE-2026-92224CVE-2026-92224
CVSS 6.7joomla
Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, lead…
CVE-2026-92223CVE-2026-92223
CVSS 3.8joomla
Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthor…
CVE-2026-92222CVE-2026-92222
CVSS 8.0joomla
Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improper…
CVE-2026-92221CVE-2026-92221
CVSS 4.7
A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function…
CVE-2026-92220CVE-2026-92220
CVSS 5.3
A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_fini…
CVE-2026-9222CVE-2026-9222
CVSS 8.1
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from th…
CVE-2026-92217CVE-2026-92217
CVSS 6.3
A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/…
CVE-2026-92216CVE-2026-92216
CVSS 4.3
A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/g…
CVE-2026-92215CVE-2026-92215
CVSS 7.3
A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_a…
CVE-2026-92214CVE-2026-92214
CVSS 3.5
A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/…
CVE-2026-92213CVE-2026-92213
CVSS 5.5
A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client…
CVE-2026-92212CVE-2026-92212
CVSS 6.1
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parame…
CVE-2026-9221CVE-2026-9221
CVSS 7.5
The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communicatio…
CVE-2026-9220CVE-2026-9220
CVSS 7.5
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES ke…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.