Search

Found 38,260 results in 2131ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-24207 critical 9.8 9.8 linux-kernel nvidia 17d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of …
CVE-2026-24206 critical 9.8 9.8 linux-kernel nvidia 17d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, deni…
CVE-2026-24163 critical 9.8 9.8 nvidia 17d ago NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execut…
CVE-2026-24142 critical 9.8 9.8 nvidia 17d ago NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and i…
CVE-2025-33255 critical 9.8 9.8 nvidia 17d ago NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code executio…
CVE-2026-7284 critical 9.8 9.8 17d ago The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due …
CVE-2026-6555 critical 9.8 9.8 17d ago The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in…
CVE-2026-45232 low 3.7 3.7 FIX slesdebian debianwindows windows samba 17d ago Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memor…
CVE-2026-31607 critical 9.8 9.8 FIX rhel slesdebian debian 17d ago In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_…
CVE-2026-8495 critical 9.8 9.8 date_ical_project 17d ago This module enables you to export entity date fields as iCal feeds. The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds. This vulnerabili…
CVE-2026-8492 low 2.7 2.7 gtranslate 17d ago The GTranslate module provides a language switcher widget for Drupal sites. The module’s widget JavaScript did not sufficiently validate that document.currentScript referred to the executing script …
CVE-2026-8491 low 3.7 3.7 adcisolutions 17d ago Node view permissions module enables permissions "View own content" and "View any content" for each content type on permissions page The module doesn't sufficiently handle the case where a user is …
CVE-2026-34234 critical 10.0 10.0 17d ago CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Executi…
CVE-2026-46412 critical 9.5 17d ago Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
CVE-2026-46354 critical 9.5 17d ago Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CVE-2026-46342 low 2.5 17d ago Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
CVE-2026-46339 critical 9.5 17d ago 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVE-2026-45695 critical 9.5 17d ago Kopia: RCE via SSH ProxyCommand Injection
CVE-2026-33642 critical 9.8 9.8 FIX debian debian kovidgoyal 17d ago Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …
CVE-2026-8605 critical 9.8 9.8 scadabr 18d ago In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
CVE-2026-8603 critical 9.8 9.8 scadabr 18d ago In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
CVE-2026-8602 critical 9.1 9.1 scadabr 18d ago In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
CVE-2026-48019 unknown debian debian 18d ago Laravel CRLF injection in default email rule
CVE-2026-5511 low 2.7 2.7 tp-link 18d ago In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.  …
CVE-2026-36829 critical 9.8 9.8 18d ago An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based …
CVE-2026-37281 critical 9.8 9.8 18d ago An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.
CVE-2026-31072 critical 9.8 9.8 debian debian sles 18d ago APScheduler's JSONSerializer and CBORSerializer are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
CVE-2026-31071 critical 9.1 9.1 18d ago API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…
CVE-2026-31070 critical 9.8 9.8 18d ago The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/…
CVE-2026-30118 critical 9.8 9.8 18d ago scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers…
CVE-2026-30117 critical 9.8 9.8 18d ago scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execut…
CVE-2026-45758 critical 9.6 9.6 18d ago Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. …
CVE-2026-44159 critical 9.8 9.8 18d ago Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 202…
CVE-2026-2587 critical 9.6 9.6 eclipse 18d ago GlassFish's gadget handler is vulnerable to RCE
CVE-2026-2586 critical 9.1 9.1 eclipse 18d ago GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-45568 critical 9.5 18d ago rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
CVE-2026-46395 critical 9.5 18d ago HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementat…
CVE-2026-8948 critical 9.1 9.1 FIX debian debian sles mozilla 18d ago Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-47323 critical 9.8 9.8 apache 18d ago Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
CVE-2026-43633 critical 10.0 10.0 18d ago HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated rem…
CVE-2025-14575 unknown sleswindows windows 18d ago An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted syste…
CVE-2026-4883 critical 9.8 9.8 18d ago The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…
CVE-2026-7860 unknown 18d ago Vaadin Build Plugins is Affected by a Possible Information Disclosure Vulnerability
CVE-2026-43493 critical 9.8 9.8 FIX slesdebian debianwindows windows 18d ago In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that va…
CVE-2026-43492 unknown FIX slesdebian debianwindows windows 18d ago In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() …
CVE-2026-43491 unknown FIX slesdebian debianwindows windows 18d ago In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added …
CVE-2026-8726 unknown 18d ago SQL Injection in extension "News system" (news)
CVE-2026-45434 critical 9.8 9.8 apache 18d ago Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgr…
CVE-2026-41919 critical 9.1 9.1 apache 18d ago Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…
CVE-2026-31986 critical 9.1 9.1 apache 18d ago Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVE-2026-2611 critical 9.6 9.6 lfprojects 18d ago MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
CVE-2026-4885 critical 9.8 9.8 18d ago The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…
CVE-2026-47314 critical 9.8 9.8 samsung 18d ago Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-47311 critical 9.8 9.8 samsung 18d ago Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-47310 critical 9.8 9.8 samsung 18d ago Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-33565 low 3.3 3.3 18d ago in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28751 low 3.3 3.3 18d ago in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-27781 low 3.3 3.3 18d ago in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-25110 low 3.3 3.3 18d ago in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-7321 critical 9.6 9.6 FIX rheldebian debianalmalinux almalinux mozilla 18d ago RHSA-2026:20586: thunderbird security update (Important)
CVE-2026-39373 low 2.5 FIX rhel slesdebian debian 18d ago JWCrypto: JWE ZIP decompression bomb
CVE-2026-0968 low 3.1 3.1 FIX rheldebian debian sles libssh 18d ago Moderate: libssh security update
CVE-2026-0965 low 3.3 3.3 FIX rheldebian debian sles libssh 18d ago Moderate: libssh security update
CVE-2025-9615 low 3.3 3.3 FIX rhel slesdebian debian 18d ago Low: NetworkManager security update
CVE-2025-8277 low 3.1 3.1 FIX rheldebian debian sles 18d ago Moderate: libssh security update
CVE-2025-68121 critical 10.0 10.0 FIX rocky rheldebian debian golanggoogle 18d ago Unexpected session resumption in crypto/tls
CVE-2025-55754 critical 9.6 9.6 FIX rhel slesdebian debian apache 18d ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Win…
CVE-2025-4878 low 3.6 3.6 FIX rheldebian debian sles 18d ago Moderate: libssh security update
CVE-2026-8838 critical 9.8 9.8 aws 18d ago amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
CVE-2026-27130 critical 9.9 9.9 18d ago Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input…
CVE-2026-25244 critical 9.8 9.8 openjsf 18d ago WebdriverIO BrowserStack Service has a Command Injection issue
CVE-2026-47091 low 3.3 3.3 jarrodwatts 18d ago Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…
CVE-2026-45683 low 3.8 3.8 sles opentelemetry 18d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_pr…
CVE-2026-8836 critical 9.8 9.8 FIX debian debian 18d ago A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…
CVE-2026-45230 critical 9.1 9.1 19d ago DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…
CVE-2026-42822 critical 10.0 10.0 windows windows microsoft 19d ago Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
CVE-2023-24215 critical 9.1 9.1 19d ago Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.
CVE-2026-45697 critical 9.8 9.8 19d ago Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as …
CVE-2026-45829 unknown 19d ago ChromaDB Python project has a pre-authentication code injection vulnerability
CVE-2026-2728 low 2.5 19d ago LibreNMS: Cross-Site Scripting in ShowConfigController
CVE-2026-41948 critical 9.4 9.4 dify 19d ago Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficie…
CVE-2026-41947 critical 9.1 9.1 dify 19d ago Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant owners…
CVE-2026-46724 unknown 19d ago TYPO3-EXT-SA-2026-011: Path Traversal in extension "Faceted Search" (ke_search)
CVE-2026-46722 unknown 19d ago TYPO3-EXT-SA-2026-011: XML External Entity Injection in extension "Faceted Search" (ke_search)
CVE-2026-45625 critical 9.9 9.9 19d ago Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /a…
CVE-2026-8803 low 3.7 3.7 19d ago A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation cau…
CVE-2026-7304 critical 9.8 9.8 lmsys 19d ago SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7302 critical 9.1 9.1 lmsys 19d ago SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7301 critical 9.8 9.8 lmsys 19d ago SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-4643 low 3.5 3.5 mattermost 19d ago Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server …
CVE-2026-6334 low 3.8 3.8 mattermost 19d ago Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
CVE-2026-8770 low 3.3 3.3 continue 19d ago A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/tools/implementations/lsTool.ts of the component JSON-RPC Server. Such manipulat…
CVE-2026-8721 critical 9.8 9.8 FIX debian debian 19d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to Sv…
CVE-2026-8507 critical 9.8 9.8 FIX debian debian 19d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info(…
CVE-2026-8757 critical 9.1 9.1 adenhq 20d ago A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Perfor…
CVE-2018-25335 critical 9.8 9.8 20d ago WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint.…
CVE-2018-25332 critical 9.8 9.8 gitbucket 20d ago GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
CVE-2018-25320 critical 9.8 9.8 20d ago ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
CVE-2026-8751 critical 9.8 9.8 h2o 20d ago A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a…
CVE-2026-8741 low 3.1 3.1 emqx 20d ago A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_persistent_session_ds.erl of the component QoS 2 PUBLISH Packet Handler. Such manip…