92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,601–3,650 of 92,816 · page 73 of 1857

IDTitleSummary
CVE-2026-9219CVE-2026-9219
CVSS 6.5
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lack…
CVE-2026-92184CVE-2026-92184
CVSS 6.3
A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/…
CVE-2026-92180CVE-2026-92180
CVSS 7.8
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows l…
CVE-2026-92179CVE-2026-92179
CVSS 7.8
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…
CVE-2026-92178CVE-2026-92178
CVSS 7.8
pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …
CVE-2026-92177CVE-2026-92177
CVSS 7.8
pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…
CVE-2026-92176CVE-2026-92176
CVSS 7.8
pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …
CVE-2026-92174CVE-2026-92174
CVSS 7.5
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter…
CVE-2026-92173CVE-2026-92173
CVSS 9.1
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIde…
CVE-2026-92172CVE-2026-92172
CVSS 8.8
Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity …
CVE-2026-92164CVE-2026-92164
CVSS 6.5
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file …
CVE-2026-92161CVE-2026-92161
CVSS 9.8
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth …
CVE-2026-9216CVE-2026-9216
CVSS 3.5netgear
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi c…
CVE-2026-9215CVE-2026-9215
CVSS 6.7netgear
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router ad…
CVE-2026-92144CVE-2026-92144
CVSS 7.2
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-…
CVE-2026-92142CVE-2026-92142
CVSS 8.8apache
Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the r…
CVE-2026-92141CVE-2026-92141
CVSS 4.3
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
CVE-2026-92140CVE-2026-92140
CVSS 6.8
Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cro…
CVE-2026-9214CVE-2026-9214
CVSS 4.5netgear
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthoriz…
CVE-2026-92139CVE-2026-92139
CVSS 6.5
Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bit…
CVE-2026-92138CVE-2026-92138
CVSS 4.2
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather…
CVE-2026-92137CVE-2026-92137
CVSS 8.8
Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the …
CVE-2026-92136CVE-2026-92136
CVSS 8.0
Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross…
CVE-2026-92135CVE-2026-92135
CVSS 8.0
Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, …
CVE-2026-92134CVE-2026-92134
CVSS 8.0
Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST …
CVE-2026-92133CVE-2026-92133
CVSS 5.4
Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key deriv…
CVE-2026-92132CVE-2026-92132
CVSS 5.4
Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity…
CVE-2026-92131CVE-2026-92131
CVSS 4.2
Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative…
CVE-2026-92130CVE-2026-92130
CVSS 3.1
Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step…
CVE-2026-9213CVE-2026-9213
CVSS 8.1netgear
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Intern…
CVE-2026-92129CVE-2026-92129
CVSS 7.5jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime…
CVE-2026-92128CVE-2026-92128
CVSS 7.5jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and…
CVE-2026-92127CVE-2026-92127
CVSS 8.0jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall…
CVE-2026-92126CVE-2026-92126
CVSS 8.5jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, al…
CVE-2026-92125CVE-2026-92125
CVSS 8.8jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permissi…
CVE-2026-92124CVE-2026-92124
CVSS 8.8jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a …
CVE-2026-92123CVE-2026-92123
CVSS 8.8jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribu…
CVE-2026-92122CVE-2026-92122
CVSS 8.8jenkins
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a v…
CVE-2026-92121CVE-2026-92121
CVSS 7.5apache
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. …
CVE-2026-9212CVE-2026-9212
CVSS 8.0netgear
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the prod…
CVE-2026-92114CVE-2026-92114
CVSS 5.3
A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functio…
CVE-2026-9211CVE-2026-9211
CVSS 8.8netgear
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
CVE-2026-92106CVE-2026-92106Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and s…
CVE-2026-92103CVE-2026-92103Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 …
CVE-2026-9210CVE-2026-9210
CVSS 4.5netgear
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorize…
CVE-2026-92099CVE-2026-92099
CVSS 6.5
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persiste…
CVE-2026-92091CVE-2026-92091
CVSS 5.9
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexit…
CVE-2026-9209CVE-2026-9209
CVSS 9.8
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postb…
CVE-2026-92087CVE-2026-92087
CVSS 8.1
@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0…
CVE-2026-92085CVE-2026-92085
CVSS 5.4
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TMT Machinery Industry and Trade Co. Ltd. Talassoft Indus…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.