Search

Found 24,841 results in 1023ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-39842 unknown 2mo ago Expression Injection in OpenRemote
CVE-2026-33414 unknown FIX debian debian 2mo ago Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the…
CVE-2026-40683 unknown FIX debian debian 2mo ago OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
CVE-2026-40176 unknown FIX debian debian sles 2mo ago Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs she…
CVE-2026-40261 unknown FIX debian debian sles 2mo ago Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source…
CVE-2026-40312 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malico…
CVE-2026-40310 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with w…
CVE-2026-40183 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the im…
CVE-2026-40169 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a y…
CVE-2026-33905 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an s…
CVE-2026-33902 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expres…
CVE-2026-33929 unknown debian debian sles 2mo ago Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
CVE-2026-40490 unknown debian debian 2mo ago AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
CVE-2026-39984 unknown FIX debian debian sles 2mo ago Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimest…
CVE-2026-33901 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that cou…
CVE-2026-33908 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyX…
CVE-2026-40869 unknown 2mo ago Decidim amendments can be accepted or rejected by anyone
CVE-2009-0238 unknown 1.5 KEV 2mo ago Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that i…
CVE-2026-6216 low 3.5 3.5 2mo ago DbGate has cross site scripting via the SVG Icon String Handler component
CVE-2026-33899 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single…
CVE-2026-34238 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a h…
CVE-2026-33900 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparoun…
CVE-2026-6192 low 3.3 3.3 FIX slesdebian debian 2mo ago A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. T…
CVE-2026-40179 unknown FIX slesdebian debian 2mo ago Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of…
CVE-2026-35582 unknown 2mo ago Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
CVE-2026-6184 low 2.4 2.4 2mo ago A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Ti…
CVE-2026-36942 low 2.7 2.7 2mo ago Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.
CVE-2026-36946 low 2.7 2.7 oretnom23 2mo ago Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.
CVE-2026-36874 low 2.7 2.7 razormist 2mo ago Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.
CVE-2026-35565 unknown 2mo ago Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata
CVE-2026-35337 unknown 2mo ago Apache Storm: Deserialization of Untrusted Data vulnerability
CVE-2025-15632 low 3.5 3.5 2mo ago A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting.…
CVE-2026-6162 low 3.5 3.5 2mo ago A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdat…
CVE-2026-34621 unknown 1.5 KEV 2mo ago Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-21643 unknown 1.5 KEV 2mo ago Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2025-60710 unknown 1.5 KEV 2mo ago Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2023-36424 unknown 1.5 KEV 2mo ago Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2023-21529 unknown 1.5 KEV 2mo ago Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2020-9715 unknown 1.5 KEV 2mo ago Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2012-1854 unknown 1.5 KEV 2mo ago Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
CVE-2026-6106 low 3.5 3.5 2mo ago A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the co…
CVE-2026-40194 low 3.7 3.7 FIX debian debian phpseclib 2mo ago phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
CVE-2026-34177 unknown FIX debian debian 2mo ago Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of k…
CVE-2026-34178 unknown FIX debian debian 2mo ago In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a …
CVE-2026-34179 unknown FIX debian debian 2mo ago In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint…
CVE-2026-34481 unknown FIX debian debian sles google 2mo ago Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVE-2026-34480 unknown debian debian sles google 2mo ago Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 spec…
CVE-2026-34478 unknown FIX debian debian sles google 2mo ago Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
CVE-2026-40228 low 3.3 3.3 slesdebian debian systemd_project 2mo ago In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
CVE-2026-22750 unknown 2mo ago Spring Cloud Gateway's SSL bundle configuration silently bypassed
CVE-2026-33551 unknown FIX debian debian 2mo ago An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application…
CVE-2026-6003 low 2.4 2.4 2mo ago A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument f…
CVE-2026-34487 unknown FIX slesdebian debian google 2mo ago Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat…
CVE-2026-34483 unknown FIX slesdebian debian 2mo ago Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 1…
CVE-2026-32990 unknown FIX debian debian 2mo ago Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, fro…
CVE-2026-29146 unknown FIX slesdebian debian google 2mo ago Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from …
CVE-2026-25854 unknown FIX slesdebian debian 2mo ago Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, fro…
CVE-2026-40046 unknown FIX debian debian 2mo ago Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
CVE-2026-34020 unknown 2mo ago Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
CVE-2026-33266 unknown 2mo ago Apache OpenMeetings Uses Hard-coded Cryptographic Key
CVE-2026-33005 unknown 2mo ago Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
CVE-2026-21388 low 2.5 2mo ago Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
CVE-2025-62188 unknown 2mo ago Apache DolphinScheduler vulnerable to sensitive information disclosure
CVE-2026-5836 low 2.4 2.4 2mo ago A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument prod…
CVE-2026-5835 low 2.4 2.4 2mo ago A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argumen…
CVE-2026-5834 low 2.4 2.4 2mo ago A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name resul…
CVE-2026-5810 low 3.5 3.5 2mo ago A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argume…
CVE-2026-5806 low 3.5 3.5 2mo ago A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cro…
CVE-2026-39987 unknown 1.5 KEV 2mo ago Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
CVE-2026-39883 unknown FIX debian debian google 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command us…
CVE-2026-39882 unknown FIX debian debian 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a si…
CVE-2026-5795 unknown debian debian sles 2mo ago Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
CVE-2026-33229 unknown 2mo ago XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
CVE-2026-39510 low 2.7 2.7 2mo ago Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control S…
CVE-2026-39395 unknown FIX debian debian sles 2mo ago Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with…
CVE-2026-35583 unknown 2mo ago Emissary has a Path Traversal via Blacklist Bypass in Configuration API
CVE-2026-35581 unknown 2mo ago Emissary has a Command Injection via PLACE_NAME Configuration in Executrix
CVE-2026-35580 unknown 2mo ago Emissary has GitHub Actions Shell Injection via Workflow Inputs
CVE-2026-1340 unknown 2.5 KEVEXP 2mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-32289 unknown FIX debian debian sles google 2mo ago Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS …
CVE-2026-32288 unknown FIX debian debian sles google 2mo ago tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
CVE-2026-5739 unknown 2mo ago PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injection
CVE-2026-35571 unknown 2mo ago Emissary has Stored XSS via Navigation Template Link Injection
CVE-2026-35568 unknown 2mo ago Java-SDK has a DNS Rebinding Vulnerability
CVE-2026-35406 unknown FIX debian debian sles 2mo ago Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable…
CVE-2026-29181 unknown FIX debian debian google 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across va…
CVE-2026-32588 unknown 2mo ago Apache Cassandra has an authenticated DoS over CQL
CVE-2026-27315 unknown 2mo ago Apache Cassandra has sensitive Information Leak in cqlsh
CVE-2026-27314 unknown 2mo ago Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator
CVE-2026-33439 unknown 2mo ago OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
CVE-2026-4292 unknown FIX slesdebian debian 2mo ago An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via for…
CVE-2026-4277 unknown FIX slesdebian debian 2mo ago An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInl…
CVE-2026-3902 unknown FIX slesdebian debian 2mo ago An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variant…
CVE-2026-33034 unknown FIX slesdebian debian 2mo ago An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SI…
CVE-2026-33033 unknown FIX slesdebian debian 2mo ago An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-T…
CVE-2026-35554 unknown sles 2mo ago Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
CVE-2026-28808 unknown FIX debian debian sles 2mo ago Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a U…
CVE-2026-32144 unknown FIX debian debian sles 2mo ago Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP respons…
CVE-2026-34197 unknown 2.5 KEVEXP debian debian 2mo ago Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-33227 unknown debian debian 2mo ago Apache ActiveMQ: Improper validation and restriction of a classpath path name