Search

Found 20,840 results in 699ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-33413 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call …
CVE-2026-33343 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use n…
CVE-2026-22737 unknown debian debian 3mo ago Spring Framework Improper Path Limitation with Script View Templates
CVE-2026-22735 unknown debian debian 3mo ago Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-22733 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
CVE-2026-22732 unknown 3mo ago Spring Security HTTP Headers Are not Written Under Some Conditions
CVE-2026-22731 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator Health groups paths
CVE-2025-43520 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel …
CVE-2025-43510 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CVE-2026-33322 unknown sles 3mo ago MinIO has JWT Algorithm Confusion in OIDC Authentication in github.com/minio/minio
CVE-2026-27953 unknown FIX debian debian 3mo ago ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validat…
CVE-2026-33056 unknown FIX debian debian 3mo ago tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path t…
CVE-2026-20131 unknown 1.5 KEV 3mo ago Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management…
CVE-2026-32735 unknown 3mo ago openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project…
CVE-2026-33166 unknown 3mo ago Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)
CVE-2026-33004 unknown 3mo ago Jenkins LoadNinja Plugin does not mask LoadNinja API keys displayed on the job configuration form
CVE-2026-33003 unknown 3mo ago Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in job config.xml files
CVE-2026-33002 unknown 3mo ago Jenkins has a DNS rebinding vulnerability in WebSocket CLI origin validation
CVE-2026-33001 unknown 3mo ago Jenkins has a link following vulnerability allows arbitrary file creation
CVE-2026-22730 unknown 3mo ago SQL Injection in Spring AI MariaDBFilterExpressionConverter
CVE-2026-22729 unknown 3mo ago JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
CVE-2026-2092 unknown 3mo ago Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
CVE-2026-20963 unknown 1.5 KEV 3mo ago Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2025-66376 unknown 1.5 KEV 3mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
CVE-2026-33012 unknown 3mo ago Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
CVE-2026-32636 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due t…
CVE-2026-33013 unknown 3mo ago Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
CVE-2026-30911 unknown 3mo ago Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
CVE-2026-28779 unknown 3mo ago Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
CVE-2026-28563 unknown 3mo ago Apache Airflow: DAG authorization bypass
CVE-2026-26929 unknown 3mo ago Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
CVE-2026-30405 unknown FIX debian debian 3mo ago An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
CVE-2026-32722 unknown FIX debian debian 3mo ago Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no esc…
CVE-2026-27459 unknown FIX slesdebian debian 3mo ago pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value…
CVE-2026-28498 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation…
CVE-2025-54920 unknown 3mo ago Apache Spark: Spark History Server Code Execution Vulnerability
CVE-2026-28490 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning…
CVE-2026-27962 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attac…
CVE-2026-27448 unknown FIX slesdebian debian 3mo ago pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled e…
CVE-2026-25534 unknown 3mo ago Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
CVE-2025-47813 unknown 1.5 KEV 3mo ago Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
CVE-2025-66249 unknown 3mo ago Apache Livy: Unauthorized directory access
CVE-2025-60012 unknown 3mo ago Apache Livy: Restrict file access
CVE-2026-3910 unknown 1.5 KEVFIX debian debian 3mo ago Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via …
CVE-2026-3909 unknown 1.5 KEVFIX debian debian 3mo ago Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome a…
CVE-2023-1289 unknown FIX slesdebian debian 3mo ago A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file …
CVE-2026-32109 unknown 3mo ago Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
CVE-2026-32108 unknown 3mo ago Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
CVE-2026-30937 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) enco…
CVE-2026-30936 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a crafted image could cause an out of bounds heap write inside…
CVE-2026-30935 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect c…
CVE-2026-30931 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncatio…
CVE-2026-30929 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a spec…
CVE-2026-28693 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds r…
CVE-2026-28691 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in t…
CVE-2026-28690 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encode…
CVE-2026-28688 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder,…
CVE-2026-28687 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decod…
CVE-2026-28686 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode …
CVE-2026-28494 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology ker…
CVE-2026-28493 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerabil…
CVE-2026-26284 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huf…
CVE-2026-25986 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVIm…
CVE-2026-25982 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/…
CVE-2026-25971 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs…
CVE-2026-25970 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL…
CVE-2026-25968 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribut…
CVE-2026-2366 unknown 3mo ago Keycloak vulnerable to authorization bypass via the Admin API
CVE-2026-3429 unknown 3mo ago Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
CVE-2026-31853 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when…
CVE-2026-30883 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overfl…
CVE-2026-28692 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MAT decoder uses 32-bit arithmetic due to incorrect parenthesi…
CVE-2026-28689 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain="path" authorization is checked before final file open/…
CVE-2026-23907 unknown debian debian sles 3mo ago Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
CVE-2026-24713 unknown 3mo ago Apache IoTDB has an Improper Input Validation vulnerability
CVE-2026-24015 unknown 3mo ago Apache IoTDB has an Insecure Default Configuration Vulnerability
CVE-2026-1603 unknown 1.5 KEV 3mo ago Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential …
CVE-2025-26399 unknown 1.5 KEV 3mo ago SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
CVE-2021-22054 unknown 1.5 KEV 3mo ago Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send …
CVE-2026-24308 unknown FIX debian debian 3mo ago Apache ZooKeeper has improper handling of configuration values
CVE-2026-24281 unknown FIX debian debian 3mo ago Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager
CVE-2026-27142 unknown FIX debian debian sles google 3mo ago Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG set…
CVE-2026-27139 unknown FIX debian debian sles google 3mo ago On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impac…
CVE-2026-27138 unknown FIX debian debian sles 3mo ago Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either di…
CVE-2026-3047 unknown 3mo ago Keycloak SAML Broken has Authentication Bypass by Primary Weakness
CVE-2026-3009 unknown 3mo ago Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator
CVE-2026-1605 unknown FIX debian debian 3mo ago The Eclipse Jetty Server Artifact has a Gzip request memory leak
CVE-2026-27982 unknown FIX debian debian 3mo ago django-allauth has an open redirect vulnerability
CVE-2026-29000 unknown 3mo ago pac4j-jwt: JwtAuthenticator Authentication Bypass via JWE-Wrapped PlainJWT
CVE-2023-41974 unknown 1.5 KEV ios 3mo ago Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
CVE-2021-22681 unknown 1.5 KEV 3mo ago Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controll…
CVE-2017-7921 unknown 2.5 KEVEXP 3mo ago Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
CVE-2026-29062 unknown FIX debian debian 3mo ago jackson-core has Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion
CVE-2026-28802 unknown FIX debian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an emp…
CVE-2026-3351 unknown FIX debian debian 3mo ago Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd se…
CVE-2025-66024 unknown 3mo ago XWiki Blog Application home page vulnerable to Stored XSS via Post Title
CVE-2025-66168 unknown debian debian 3mo ago Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound
CVE-2026-0540 unknown FIX debian debian 3mo ago DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five …
CVE-2025-15599 unknown FIX debian debian 3mo ago DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext elemen…
CVE-2026-25674 unknown FIX slesdebian debian 3mo ago An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file s…