Search

Found 5,184 results in 3488ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44596 medium 6.5 EXP 8d ago Yamcs has No Rate Limiting on Authentication Endpoint
CVE-2026-44595 medium 6.5 EXP 8d ago Yamcs vulnerable to unauthorized user enumeration via IAM API endpoints
CVE-2026-42568 medium 6.5 EXP 8d ago Yamcs Vulnerable to LDAP Injection in LdapAuthModule
CVE-2026-9082 critical 9.8 10.0 KEVEXP drupal 14d ago Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-20182 critical 10.0 10.0 KEVEXP cisco 21d ago Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges…
CVE-2026-44376 medium 6.1 7.1 EXP 21d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.p…
CVE-2026-6815 medium 5.9 6.9 EXP casbin 24d ago An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perfo…
CVE-2024-51092 critical 9.1 10.0 EXP librenms 27d ago LibreNMS has an Authenticated OS Command Injection
CVE-2024-30167 medium 6.3 7.3 EXP 27d ago /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.
CVE-2026-44262 critical 9.4 10.0 EXP 28d ago Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules
CVE-2026-42607 critical 9.1 10.0 EXP 29d ago Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
CVE-2026-36356 critical 9.1 10.0 EXP 1mo ago The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
CVE-2026-7567 critical 9.8 10.0 EXP 1mo ago The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() fun…
CVE-2026-41940 critical 9.8 10.0 KEVEXP cpanel 1mo ago WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized a…
CVE-2024-7399 unknown 2.5 KEVEXP 1mo ago Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
CVE-2026-32202 medium 4.3 6.8 KEVEXPFIX windows windows 2mo ago Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33829 medium 4.3 5.3 EXP 2mo ago Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-4631 critical 10.0 EXPFIX rheldebian debian sles 2mo ago Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit…
CVE-2026-1340 unknown 2.5 KEVEXP 2mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-34197 unknown 2.5 KEVEXP debian debian 2mo ago Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-3055 unknown 2.5 KEVEXP 2mo ago Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP lea…
CVE-2026-32746 critical 9.8 10.0 EXPFIX debian debian sles gnu 3mo ago telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
CVE-2017-7921 unknown 2.5 KEVEXP 3mo ago Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
CVE-2026-28517 critical 9.8 10.0 EXP opendcim 3mo ago openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the databas…
CVE-2026-20127 unknown 2.5 KEVEXP 3mo ago Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, re…
CVE-2026-2441 unknown 2.5 KEVEXPFIX debian debian sles 4mo ago Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple…
CVE-2008-0015 unknown 2.5 KEVEXP 4mo ago Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the…
CVE-2026-1731 unknown 2.5 KEVEXP 4mo ago BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute oper…
CVE-2025-40536 unknown 2.5 KEVEXP 4mo ago SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
CVE-2025-40271 medium 6.5 EXPFIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which m…
CVE-2025-64328 unknown 2.5 KEVEXP 4mo ago Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> c…
CVE-2025-40551 unknown 2.5 KEVEXP 4mo ago SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This c…
CVE-2026-1281 unknown 2.5 KEVEXP 4mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-24486 unknown 1.0 EXPFIX slesdebian debian 4mo ago Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_…
CVE-2016-15057 unknown 1.0 EXP 4mo ago Apache Continuum vulnerable to Command Injection through Installations REST API
CVE-2026-24061 unknown 2.5 KEVEXPFIX debian debian 4mo ago GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2025-52691 unknown 2.5 KEVEXP 4mo ago SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail s…
CVE-2018-14634 unknown 2.5 KEVEXPFIX slesdebian debian 4mo ago Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escala…
CVE-2025-37164 unknown 2.5 KEVEXP 5mo ago Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.
CVE-2025-14847 unknown 2.5 KEVEXP 5mo ago MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by a…
CVE-2025-68613 unknown 2.5 KEVEXP 5mo ago n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
CVE-2025-14611 unknown 2.5 KEVEXP 6mo ago Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoin…
CVE-2025-55182 unknown 2.5 KEVEXP aws 6mo ago Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Ser…
CVE-2025-58360 unknown 2.5 KEVEXP 6mo ago OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation…
CVE-2025-58034 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI comman…
CVE-2025-64446 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-62215 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could ena…
CVE-2025-64459 unknown 1.0 EXPFIX debian debian 7mo ago An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to…
CVE-2025-11371 unknown 2.5 KEVEXP 7mo ago Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-59287 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-33073 unknown 2.5 KEVEXP 8mo ago Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the …
CVE-2025-61882 unknown 2.5 KEVEXP 8mo ago Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise O…
CVE-2013-3918 unknown 2.5 KEVEXP 8mo ago Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a sp…
CVE-2011-3402 unknown 2.5 KEVEXP 8mo ago Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via …
CVE-2010-3962 unknown 2.5 KEVEXP 8mo ago Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service…
CVE-2010-3765 unknown 2.5 KEVEXP 8mo ago Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCo…
CVE-2015-7755 unknown 2.5 KEVEXP 8mo ago Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
CVE-2014-6278 unknown 2.5 KEVEXPFIX debian debian 8mo ago GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2025-32463 unknown 2.5 KEVEXPFIX slesdebian debian 8mo ago Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary command…
CVE-2025-10370 medium 5.4 6.4 EXP sourcefabric 9mo ago A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script le…
CVE-2025-10327 critical 9.8 10.0 EXP sourcefabric 9mo ago A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulatio…
CVE-2025-54236 critical 9.1 10.0 KEVEXP adobe 9mo ago Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2020-24363 unknown 2.5 KEVEXP 9mo ago TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST …
CVE-2025-57819 unknown 2.5 KEVEXP 9mo ago Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database…
CVE-2025-9090 critical 9.8 10.0 EXP 10mo ago A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injecti…
CVE-2012-10060 critical 9.8 10.0 EXP sysax 10mo ago Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies th…
CVE-2013-3893 unknown 2.5 KEVEXP 10mo ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shoul…
CVE-2012-10024 unknown 1.0 EXP 10mo ago XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authentic…
CVE-2012-10026 unknown 1.0 EXP 10mo ago The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded f…
CVE-2025-8550 medium 5.4 6.4 EXP pybbs_project 10mo ago A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/topic/list. The manipulation o…
CVE-2025-8471 critical 9.8 10.0 EXP projectworlds 10mo ago A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulatio…
CVE-2025-8191 medium 5.4 6.4 EXP macrozheng 10mo ago A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The man…
CVE-2025-32429 unknown 1.0 EXP 10mo ago XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
CVE-2025-49706 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view…
CVE-2025-49704 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-…
CVE-2025-53770 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could b…
CVE-2025-25257 unknown 2.5 KEVEXP 11mo ago Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVE-2025-47812 unknown 2.5 KEVEXP 11mo ago Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arb…
CVE-2025-5777 unknown 2.5 KEVEXP 11mo ago Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a…
CVE-2019-9621 unknown 2.5 KEVEXP 11mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
CVE-2025-3248 unknown 2.5 KEVEXP 1y ago Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
CVE-2025-6095 critical 9.8 10.0 EXP codesiddhant 1y ago A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation of the argument use…
CVE-2025-33053 unknown 2.5 KEVEXP 1y ago Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribut…
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2025-49113 critical 10.0 KEVEXPFIX arch archdebian debian 1y ago RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/…
CVE-2025-4524 critical 9.8 10.0 EXP 1y ago The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. …
CVE-2025-4428 unknown 2.5 KEVEXP 1y ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. T…
CVE-2025-4427 unknown 2.5 KEVEXP 1y ago Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted…
CVE-2025-4123 medium 6.1 7.1 EXPFIX rhel rocky sles grafana 1y ago RHSA-2025:7894: grafana security update (Important)
CVE-2025-30397 unknown 2.5 KEVEXP 1y ago Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.
CVE-2025-27533 unknown 1.0 EXPFIX debian debian 1y ago Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
CVE-2025-32432 unknown 2.5 KEVEXP 1y ago Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2025-24016 unknown 2.5 KEVEXP 1y ago Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.
CVE-2025-24054 unknown 2.5 KEVEXP 1y ago Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-30406 unknown 2.5 KEVEXP 1y ago Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploi…
CVE-2025-31161 unknown 2.5 KEVEXP 1y ago CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., c…
CVE-2025-24813 medium 8.0 KEVEXPFIX rhel rocky sles 1y ago Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2025-22457 unknown 2.5 KEVEXP 1y ago Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2025-2783 unknown 2.5 KEVEXPFIX debian debian 1y ago Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability…
CVE-2025-26633 unknown 2.5 KEVEXP 1y ago Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.