Search

Found 133 results in 23ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-46447 medium 5.8 5.8 debian debian 19h ago OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.
CVE-2026-22055 unknown 19h ago Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
CVE-2026-22054 unknown 19h ago Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
CVE-2026-44182 unknown 19h ago Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering
CVE-2026-44181 unknown 19h ago Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution
CVE-2026-44180 unknown 19h ago Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass
CVE-2026-44023 unknown 20h ago Docling Core: Unsafe remote filename resolution
CVE-2026-44019 unknown 20h ago Docling Core: Insufficient validation of image reference URIs
CVE-2026-47214 unknown 20h ago Docling: Unsafe URI and Path Handling in HTML Backend
CVE-2026-44022 unknown 20h ago Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
CVE-2026-44020 unknown 20h ago Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2026-44018 unknown 20h ago Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-44016 unknown 20h ago Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-43980 unknown 20h ago malla: Stored XSS via Meshtastic node names in multiple frontend pages
CVE-2026-41234 unknown 20h ago Froxlor: BIND Zone File Injection via TXT Record Content
CVE-2026-40898 unknown 20h ago quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVE-2026-43924 unknown 21h ago FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs befo…
CVE-2026-40495 unknown 21h ago FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hid…
CVE-2026-37700 unknown 21h ago Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page
CVE-2026-26825 unknown 21h ago A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory origi…
CVE-2026-26824 medium 6.5 6.5 sles 21h ago libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not ful…
CVE-2026-44017 unknown 21h ago Docling: Unsafe Zip Extraction in EasyOCR Model Download
CVE-2026-8889 unknown 22h ago Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
CVE-2026-8888 unknown 22h ago Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. A…
CVE-2026-8881 unknown 22h ago Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since 2004 and a single iteration provides no …
CVE-2026-7888 unknown 22h ago Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticat…
CVE-2026-45702 medium 4.4 4.4 debian debian 22h ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.3.0 and prior t…
CVE-2026-45614 medium 4.7 4.7 debian debian 22h ago OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of t…
CVE-2026-42840 unknown 22h ago An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every ope…
CVE-2026-42839 unknown 22h ago An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the …
CVE-2026-26379 medium 6.5 6.5 22h ago An issue in Koha v.25.11 and before allows a remote attacker to execute arbitrary code via the Z39.50 configuration module
CVE-2026-26378 medium 5.4 5.4 22h ago Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features
CVE-2019-25720 medium 6.5 6.5 1d ago Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot th…