Search

Found 41,339 results in 2598ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44451 critical 9.3 9.3 9d ago Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous global…
CVE-2026-44843 high 8.2 8.2 langchain 9d ago LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-9575 high 7.3 7.3 9d ago A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulat…
CVE-2026-8890 high 8.2 8.2 9d ago code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea…
CVE-2026-3660 critical 9.8 9.8 ibm 9d ago IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap…
CVE-2026-9574 high 7.3 7.3 9d ago A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the a…
CVE-2026-9573 high 7.3 7.3 9d ago A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation o…
CVE-2026-3603 high 7.1 7.1 ibm 9d ago IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML exter…
CVE-2026-8854 high 7.5 7.5 linux-kernel ibm 9d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
CVE-2026-8835 high 7.3 7.3 linux-kernel ibm 9d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive informat…
CVE-2026-8834 high 8.0 8.0 linux-kernel ibm 9d ago IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause …
CVE-2026-7251 critical 9.8 9.8 9d ago Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full…
CVE-2026-48695 high 8.1 8.1 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php…
CVE-2026-48694 high 8.1 8.1 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK vari…
CVE-2026-46624 critical 9.9 9.9 twenty 9d ago Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. I…
CVE-2026-44730 high 7.2 7.2 citeum 9d ago OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd
CVE-2026-44706 high 8.5 8.5 9d ago Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type da…
CVE-2026-44669 high 8.7 8.7 9d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview f…
CVE-2026-24195 high 7.1 7.1 9d ago NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-4051 high 7.2 7.2 ibm 9d ago IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.
CVE-2026-44728 high 8.2 8.2 slesdebian debian babel 9d ago Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…
CVE-2026-44668 critical 9.8 9.8 9d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invo…
CVE-2026-44667 high 8.7 8.7 9d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification …
CVE-2026-9560 high 7.8 7.8 openvpn 9d ago Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
CVE-2026-9170 critical 9.8 9.8 ibm 10d ago IBM HTTP Server 8.5, and 9.0
CVE-2026-24200 high 7.0 7.0 10d ago NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to den…
CVE-2026-24194 high 7.8 7.8 10d ago NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead t…
CVE-2026-24191 high 7.8 7.8 10d ago NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service,…
CVE-2026-24190 high 7.8 7.8 10d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability mi…
CVE-2026-24193 high 7.8 7.8 10d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, …
CVE-2026-24196 high 7.1 7.1 10d ago NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information dis…
CVE-2026-8633 critical 9.8 9.8 ibm 10d ago IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code executi…
CVE-2026-9562 high 7.3 7.3 10d ago A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such mani…
CVE-2026-8852 high 7.5 7.5 linux-kernel ibm 10d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
CVE-2026-8850 high 7.5 7.5 linux-kernel ibm 10d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
CVE-2026-48902 critical 9.8 9.8 joomla 10d ago The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVE-2026-48901 high 7.5 7.5 joomla 10d ago The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48864 high 7.8 7.8 debian debian sles rhel opensuseredhat 10d ago A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca…
CVE-2026-48697 high 7.4 7.4 debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl…
CVE-2026-48691 critical 9.8 9.8 FIX debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attr…
CVE-2026-48690 high 7.1 7.1 FIX debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memor…
CVE-2026-48126 high 8.2 8.2 10d ago Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request…
CVE-2026-45728 high 7.5 7.5 10d ago Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-45721 critical 9.0 9.0 10d ago Algernon: handler.lua discovery walks parent directories above the server root
CVE-2026-44723 critical 9.9 9.9 vowpalwabbit 10d ago Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate …
CVE-2026-44680 high 7.6 8.6 EXP 10d ago MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys
CVE-2026-35222 critical 9.8 9.8 joomla 10d ago Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-24212 critical 9.8 9.8 linux-kernel nvidia 10d ago NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalatio…
CVE-2026-24162 high 7.8 7.8 linux-kernel nvidia 10d ago NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code exec…
CVE-2025-36221 high 7.5 7.5 ibm 10d ago IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the inst…
CVE-2025-36220 critical 9.8 9.8 ibm 10d ago IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …
CVE-2026-8620 high 7.5 7.5 ibm 10d ago IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggl…
CVE-2026-24192 high 7.8 7.8 10d ago NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this v…
CVE-2026-24187 high 8.8 8.8 10d ago NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of priv…
CVE-2026-7454 high 7.8 7.8 autodesk 10d ago A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…
CVE-2026-7452 high 7.8 7.8 autodesk 10d ago A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…
CVE-2026-7451 high 7.8 7.8 autodesk 10d ago A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data co…
CVE-2026-8855 high 8.1 8.1 linux-kernel ibm 10d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
CVE-2026-8856 critical 9.1 9.1 linux-kernel ibm 10d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
CVE-2026-44729 high 8.7 8.7 twenty 10d ago Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any…
CVE-2026-35221 critical 9.8 9.8 joomla 10d ago Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
CVE-2026-48896 high 7.5 7.5 joomla 10d ago Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-40383 critical 9.8 9.8 joomla 10d ago An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-40384 high 7.5 7.5 joomla 10d ago An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
CVE-2026-48897 high 7.5 7.5 joomla 10d ago Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48899 critical 9.8 9.8 joomla 10d ago An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-35223 critical 9.8 9.8 joomla 10d ago An improper access check allows unauthorized access to com_config webservice endpoints.
CVE-2026-48904 critical 9.8 9.8 joomla 10d ago An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48898 critical 9.8 9.8 joomla 10d ago An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48692 high 8.1 8.1 debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.c…
CVE-2026-48688 high 7.5 7.5 FIX debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains …
CVE-2026-48686 critical 9.8 9.8 FIX debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() …
CVE-2026-43935 high 8.1 8.1 10d ago e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset l…
CVE-2026-25112 high 7.8 7.8 10d ago A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
CVE-2025-36126 high 7.6 7.6 ibm 10d ago IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows…
CVE-2026-9552 high 7.3 7.3 10d ago A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Valu…
CVE-2026-9551 high 7.3 7.3 10d ago A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The …
CVE-2026-9550 high 7.3 7.3 10d ago A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWE…
CVE-2026-46368 high 8.8 8.8 10d ago luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — …
CVE-2026-45247 critical 9.8 10.0 KEV mirasvit 10d ago Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying …
CVE-2026-45082 high 7.6 7.6 10d ago Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following proces…
CVE-2026-42785 high 7.2 7.2 10d ago OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can sub…
CVE-2026-42425 high 7.2 7.2 10d ago OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the Database…
CVE-2026-40034 high 7.8 7.8 sleswindows windows 10d ago gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration …
CVE-2026-9544 high 7.3 7.3 10d ago A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. …
CVE-2026-9543 critical 9.8 9.8 10d ago A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipul…
CVE-2026-48133 high 7.5 7.5 10d ago When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
CVE-2026-48132 high 8.1 8.1 10d ago The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing…
CVE-2026-48131 high 8.1 8.1 10d ago The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, r…
CVE-2025-11482 high 7.5 7.5 10d ago An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by an unauthenticated network-based attack…
CVE-2026-40033 high 8.8 8.8 FIX slesdebian debian freerdp 10d ago FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle v…
CVE-2026-4480 critical 9.0 9.0 FIX slesdebian debian rhel redhatsamba 10d ago Important: samba security update
CVE-2026-7374 critical 9.9 9.9 sleswindows windows 10d ago A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation whe…
CVE-2026-39661 high 7.5 7.5 10d ago Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core…
CVE-2026-25713 high 7.8 7.8 mediaarea 10d ago MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
CVE-2026-25104 high 7.8 7.8 mediaarea 10d ago MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
CVE-2026-8047 high 7.5 7.5 10d ago The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw t…
CVE-2026-8046 high 8.1 8.1 10d ago The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including tho…
CVE-2026-44469 high 7.0 7.0 codesys 10d ago The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU r…
CVE-2026-44468 high 7.8 7.8 codesys 10d ago The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the comp…