92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,601–3,650 of 92,816 · page 73 of 1857
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9219 | CVE-2026-9219 CVSS 6.5 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lack… |
| CVE-2026-92184 | CVE-2026-92184 CVSS 6.3 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/… |
| CVE-2026-92180 | CVE-2026-92180 CVSS 7.8 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows l… |
| CVE-2026-92179 | CVE-2026-92179 CVSS 7.8 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… |
| CVE-2026-92178 | CVE-2026-92178 CVSS 7.8 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … |
| CVE-2026-92177 | CVE-2026-92177 CVSS 7.8 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… |
| CVE-2026-92176 | CVE-2026-92176 CVSS 7.8 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code … |
| CVE-2026-92174 | CVE-2026-92174 CVSS 7.5 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter… |
| CVE-2026-92173 | CVE-2026-92173 CVSS 9.1 | Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIde… |
| CVE-2026-92172 | CVE-2026-92172 CVSS 8.8 | Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity … |
| CVE-2026-92164 | CVE-2026-92164 CVSS 6.5 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file … |
| CVE-2026-92161 | CVE-2026-92161 CVSS 9.8 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth … |
| CVE-2026-9216 | CVE-2026-9216 CVSS 3.5netgear | An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi c… |
| CVE-2026-9215 | CVE-2026-9215 CVSS 6.7netgear | A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router ad… |
| CVE-2026-92144 | CVE-2026-92144 CVSS 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-… |
| CVE-2026-92142 | CVE-2026-92142 CVSS 8.8apache | Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the r… |
| CVE-2026-92141 | CVE-2026-92141 CVSS 4.3 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. |
| CVE-2026-92140 | CVE-2026-92140 CVSS 6.8 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cro… |
| CVE-2026-9214 | CVE-2026-9214 CVSS 4.5netgear | Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthoriz… |
| CVE-2026-92139 | CVE-2026-92139 CVSS 6.5 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bit… |
| CVE-2026-92138 | CVE-2026-92138 CVSS 4.2 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather… |
| CVE-2026-92137 | CVE-2026-92137 CVSS 8.8 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the … |
| CVE-2026-92136 | CVE-2026-92136 CVSS 8.0 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross… |
| CVE-2026-92135 | CVE-2026-92135 CVSS 8.0 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, … |
| CVE-2026-92134 | CVE-2026-92134 CVSS 8.0 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST … |
| CVE-2026-92133 | CVE-2026-92133 CVSS 5.4 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key deriv… |
| CVE-2026-92132 | CVE-2026-92132 CVSS 5.4 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity… |
| CVE-2026-92131 | CVE-2026-92131 CVSS 4.2 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative… |
| CVE-2026-92130 | CVE-2026-92130 CVSS 3.1 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step… |
| CVE-2026-9213 | CVE-2026-9213 CVSS 8.1netgear | A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Intern… |
| CVE-2026-92129 | CVE-2026-92129 CVSS 7.5jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime… |
| CVE-2026-92128 | CVE-2026-92128 CVSS 7.5jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and… |
| CVE-2026-92127 | CVE-2026-92127 CVSS 8.0jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall… |
| CVE-2026-92126 | CVE-2026-92126 CVSS 8.5jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, al… |
| CVE-2026-92125 | CVE-2026-92125 CVSS 8.8jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permissi… |
| CVE-2026-92124 | CVE-2026-92124 CVSS 8.8jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a … |
| CVE-2026-92123 | CVE-2026-92123 CVSS 8.8jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribu… |
| CVE-2026-92122 | CVE-2026-92122 CVSS 8.8jenkins | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a v… |
| CVE-2026-92121 | CVE-2026-92121 CVSS 7.5apache | In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. … |
| CVE-2026-9212 | CVE-2026-9212 CVSS 8.0netgear | Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the prod… |
| CVE-2026-92114 | CVE-2026-92114 CVSS 5.3 | A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functio… |
| CVE-2026-9211 | CVE-2026-9211 CVSS 8.8netgear | An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. |
| CVE-2026-92106 | CVE-2026-92106 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and s… |
| CVE-2026-92103 | CVE-2026-92103 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 … |
| CVE-2026-9210 | CVE-2026-9210 CVSS 4.5netgear | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorize… |
| CVE-2026-92099 | CVE-2026-92099 CVSS 6.5 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persiste… |
| CVE-2026-92091 | CVE-2026-92091 CVSS 5.9 | A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexit… |
| CVE-2026-9209 | CVE-2026-9209 CVSS 9.8 | mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postb… |
| CVE-2026-92087 | CVE-2026-92087 CVSS 8.1 | @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0… |
| CVE-2026-92085 | CVE-2026-92085 CVSS 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TMT Machinery Industry and Trade Co. Ltd. Talassoft Indus… |