CVEs we hold for Ge
Records whose assigning authority named Ge as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-93532gedelumbung HospitalManagement Password Change password.php simpan improper authenticationgedelumbung HospitalManagement
CVE-2026-93531gedelumbung HospitalManagement cross-site request forgerygedelumbung HospitalManagement
CVE-2026-92221gedelumbung HospitalManagement app_global_admin_model.php generate_index_pasien sql injectiongedelumbung HospitalManagement
CVE-2026-90984Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery via Array-Valued Form FieldUnknown Generate PDF using Contact Form 7
CVE-2026-88290GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource ExhaustionGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88289GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request HandlersGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88288GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink CreationGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88287GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88286GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88285GV-LPC2011/LPC2211 - Unauthenticated PTZ Control ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88284GV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211 -
CVE-2026-88283GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88282GV-LPCLPC2011/2211 - Stored FTP-Username Command InjectionGeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-88281GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88280GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88279GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88278GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest ReplayGeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-88277GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command InjectionGeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-88276GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command InjectionGeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-88275GV-LPC2011/LPC2211 - Wireless WPA-PSK Command InjectionGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88273GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command InjectionGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88272GV-LPC2011/LPC2211 - Stored Administrator-Username Command InjectionGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88271GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential TakeoverGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88270GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of ServiceGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88269GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential DisclosureGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-88268GV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of ServiceGeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-86196Grav API Plugin before 1.0.20 Authentication Bypass via Host Headergetgrav grav-plugin-api
CVE-2026-86195grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flaggetgrav grav-plugin-api
CVE-2026-86193Grav API Plugin Authentication Bypass via Group-Inherited Supergetgrav grav-plugin-api
CVE-2026-86114Arcane before 2.0.0 Missing Administrator Authorization on the Compose Template Mutation Endpointsgetarcaneapp arcane
CVE-2026-85602Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypassgetgrav grav-plugin-form
CVE-2026-85599Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parametersgetgrav grav-plugin-shortcode-core
CVE-2026-84908WPFunnels <= 3.12.13 - Missing Authorization to Unauthenticated Arbitrary Product Price Manipulation via…getwpfunnels WPFunnels – Funnel Builder for WooCommerce…
CVE-2026-82964Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sysGen Digital Norton Antivirus Plus, Norton 360 Standard…
CVE-2026-79784Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configurationgemelo-ai vocos
CVE-2026-77354kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decodinggetkin kin-openapi
CVE-2026-76905kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables…getkin kin-openapi
CVE-2026-76904GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layersgeotools
CVE-2026-75594Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media…getkirby kirby
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlinggetkirby kirby
CVE-2026-74933GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration OverwriteUnknown GenieWords
CVE-2026-7404getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversalgetsimpletool mcpo-simple-server
CVE-2026-7400geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversalgeekgod382 filesystem-mcp-server
CVE-2026-7372GeoVision GV-VMS V20 WebCam Server Login stack overflow vulnerabilityGeoVision Inc. GV-VMS V20.0.2
CVE-2026-7371GeoVision LPC2011/LPC2211 Web Interface / ssi.cgi reflected cross-site scripting (XSS) vulnerabilitiesGeoVision Inc. GV-LPC2011/LPC2211
CVE-2026-73502kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter…getkin kin-openapi
CVE-2026-73501kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Defaultgetkin kin-openapi
CVE-2026-73382WordPress Site Reviews plugin <= 8.2.0 - Cross Site Scripting (XSS) vulnerabilityGemini Labs Site Reviews
CVE-2026-73183WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerabilityGet Maps Marker Pro Maps Marker Pro
CVE-2026-72699Grav Login Plugin before 3.9.1 Email Enumeration via Registrationgetgrav grav-plugin-login
CVE-2026-7161GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerabilityGeoVision Inc. GV-IP Device Utility
CVE-2026-71415Kirby: File upload permissions are not checked during processing of chunk datagetkirby kirby
CVE-2026-69087Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twiggetgrav grav-plugin-form
CVE-2026-67184TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP RequestGeneralSandman TinyWeb
CVE-2026-6676Avira antivirus engine heap buffer OOB write when scanning a malformed POSIX tar archiveGen Digital Avira Antivirus
CVE-2026-64852Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any accountgetgrav grav-plugin-api
CVE-2026-64851Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlersgetgrav grav-plugin-shortcode-core
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()getgrav grav
CVE-2026-63408Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parametergetgrav grav-plugin-api
CVE-2026-63407Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responsesgetgrav grav-plugin-api
CVE-2026-63219Unauthenticated file upload via missing authorization on formatter upload endpointgeonetwork core-geonetwork
CVE-2026-62673Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsgetgrav grav
CVE-2026-62671CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on…getgrav grav-plugin-login
CVE-2026-62670Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less…getgrav grav-plugin-flex-objects
CVE-2026-62669Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challengegetgrav grav-plugin-login
CVE-2026-62667Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACLgetgrav grav-plugin-api
CVE-2026-62666Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190)…getgrav grav-plugin-api
CVE-2026-61842Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)getgrav grav
CVE-2026-61607Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizergetgrav grav-plugin-api
CVE-2026-59193Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()getgrav grav
CVE-2026-58656Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parametergetgrav grav
CVE-2026-58493grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Constructiongetgrav grav
CVE-2026-58492grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolationgetgrav grav
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattergeonetwork core-geonetwork
CVE-2026-57881GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (vlsvr)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57880GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57879GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57878GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57877GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57876GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57875GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsingGeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57874GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57873GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload.cgi)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57872GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)GeoVision Inc. GV-LPCLPC2011/2211
CVE-2026-57318WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerabilityGemini Labs Site Reviews
CVE-2026-57278GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57277GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57276GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57275GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57274GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57273GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57272GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57271GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57270GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57269GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57268GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57267GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57266GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57265GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
CVE-2026-57264GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerabilityGeoVision Inc. GeoWebPlayer
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.