CVE Analysis Index
12268 curated vulnerability analyses with independent analyst commentary. Each entry includes executive summary, technical breakdown, business impact, and remediation guidance.
Recent analyses
- CVE-2026-16736 WordPress The User Registration & Membership WordPress plugin before 5.2.6 fails to enforce site registration settings, allowing unauthenticated users to create accounts when registration is disabled.
- CVE-2026-16605 MultiVendorX The MultiVendorX WordPress plugin contains a missing authorization vulnerability in its REST API, allowing authorized vendors to manipulate other vendors' store data.
- CVE-2026-61484 Apache Software Foundation Apache Lucy is vulnerable to a deserialization of untrusted data issue, potentially allowing remote code execution due to improper input handling.
- CVE-2026-61486 Apache Software Foundation A stack-based buffer overflow vulnerability exists in Apache Lucy, potentially allowing attackers to execute arbitrary code.
- CVE-2026-19788 Tenda A stack-based buffer overflow in the Tenda AC1206 web interface allows remote attackers to execute arbitrary code via the set_device_name function.
- CVE-2026-19792 Tenda A remote buffer overflow vulnerability in the Tenda G0 web management interface allows code execution via the setPortMapping function in /goform/module.
- CVE-2026-19791 Tenda A stack-based buffer overflow in the Tenda G0 httpd web management interface allows remote attackers to execute arbitrary code via the addStaticRoute function.
- CVE-2026-19811 TOTOLINK A stack-based buffer overflow in the setIpQosRules function of the TOTOLINK A800R router allows remote code execution via manipulation of the Comment argument.
- CVE-2026-19812 TOTOLINK A stack-based buffer overflow in the UploadCustomModule function of the TOTOLINK A800R router allows remote code execution via manipulation of the File argument.
- CVE-2026-19813 TOTOLINK A stack-based buffer overflow in the setMacFilterRules function of the TOTOLINK A800R router allows remote code execution via manipulation of the Comment argument.
- CVE-2026-73417 jupyterlab JupyterLab is vulnerable to Cross-site Scripting (XSS) due to improper neutralization of input and output encoding, allowing attackers to execute arbitrary scripts in a user's browser session.
- CVE-2026-73661 FreePBX The FreePBX framework is susceptible to external control of system configuration settings, which allows low-privileged users to modify critical system parameters.
- CVE-2026-73664 FreePBX The FreePBX backup module contains an access control vulnerability that allows authenticated users with high privileges to perform unauthorized actions due to improper privilege management.
- CVE-2026-15803 Eclipse Eclipse RDF4J fails to restrict XML External Entity (XXE) processing in several XML parser entry points, allowing unauthorized data access via external entity references.
- CVE-2026-73332 owen2345 A stored cross-site scripting vulnerability in the CamaleonCMS contact form plugin allows authenticated attackers to inject arbitrary HTML via the before_html field.
- CVE-2026-63298 NVIDIA An OS command injection vulnerability in NVIDIA LXD instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives.
- CVE-2026-49478 sigstore The sigstore fulcio certificate authority is vulnerable to Server-Side Request Forgery, which could allow unauthorized certificate issuance.
- CVE-2026-55402 Absolute Security Absolute Security Secure Access servers prior to version 14.57 contain an out-of-bounds read vulnerability that could lead to system instability or information disclosure.
- CVE-2026-73569 NaturalIntelligence The fast-xml-parser library is vulnerable to XML Entity Expansion, which could allow an attacker to cause a denial of service via specially crafted XML input.
- CVE-2026-68454 Linux A memory handling vulnerability in the Linux kernel KVM subsystem for s390 architecture allows for improper AISB location management when registering IRQs without a summary bit.
- CVE-2026-73614 Jovancoding The ClaudeHookBridge component in Network-AI allows for a deny-pattern bypass via truncation, enabling unauthorized access to restricted network pathways.
- CVE-2026-73615 Jovancoding The SandboxPolicy component in Network-AI contains a blocklist bypass vulnerability caused by a quote mismatch during input processing.
- CVE-2026-19291 Silicon Labs A vulnerability in Silicon Labs WiseConnect allows Bluetooth re-pairing with existing devices to occur at a lower security level, facilitating potential authentication bypass.
- CVE-2026-19292 Silicon Labs A vulnerability in Silicon Labs WiseConnect allows re-pairing with a lower security level, making the Long Term Key (LTK) susceptible to brute-force attacks.
- CVE-2026-16101 Silicon Labs A vulnerability in Silicon Labs WiseConnect allows unauthenticated attackers to spoof bonded devices, forcing RS9116W or SiWx917 hardware to re-pair with a rogue device.
- CVE-2026-19293 silabs.com The Silabs WiseConnect platform fails to include maximum encryption key size information in SMP security requests, leading to potential weaknesses in Bluetooth Low Energy pairing.
- CVE-2026-73305 Budibase Budibase is vulnerable to improper privilege management and authorization flaws, allowing authenticated users to perform unauthorized actions within the low-code platform.
- CVE-2026-73514 PostGIS The PostGIS address_standardizer extension contains an out-of-bounds write vulnerability that can be triggered during address standardization processes.
- CVE-2026-19789 Tenda The Tenda AC1206 router is vulnerable to a stack-based buffer overflow, allowing memory corruption via specifically crafted input.
- CVE-2026-19790 Tenda Tenda G0 devices are vulnerable to a stack-based buffer overflow, which can lead to memory corruption and potential system compromise.
Browse all
Looking for a specific CVE? The full searchable database has filters by vendor, severity, CISA KEV status, and free-text search.