Search

Found 25,271 results in 1155ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-40611 unknown FIX debian debian 2mo ago Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A ma…
CVE-2026-41245 unknown 2mo ago Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
CVE-2026-30778 unknown 2mo ago SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information
CVE-2026-40505 low 3.3 3.3 FIX debian debian artifex 2mo ago MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious…
CVE-2026-6312 low 3.1 3.1 FIX debian debian linux-kernelmacos macos google 2mo ago Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML p…
CVE-2026-40478 unknown 2mo ago Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
CVE-2026-40477 unknown 2mo ago Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-40347 unknown FIX slesdebian debian 2mo ago Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
CVE-2026-40882 unknown 2mo ago OpenRemote has XXE in Velbus Asset Import
CVE-2026-6313 unknown FIX debian debian 2mo ago Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. …
CVE-2026-5598 unknown FIX debian debian sles 2mo ago Bouncy Castle Has Covert Timing Channel Vulnerability
CVE-2026-5588 unknown debian debian sles google 2mo ago Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
CVE-2026-3505 unknown debian debian sles 2mo ago Bouncy Castle Uncontrolled Resource Consumption vulnerability
CVE-2026-0636 unknown debian debian sles 2mo ago Bouncy Castle has an LDAP injection
CVE-2026-40104 unknown 2mo ago XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVE-2026-40105 unknown 2mo ago XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
CVE-2026-39842 unknown 2mo ago Expression Injection in OpenRemote
CVE-2026-33414 unknown FIX debian debian 2mo ago Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the…
CVE-2026-40683 unknown FIX debian debian 2mo ago OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
CVE-2026-40176 unknown FIX debian debian sles 2mo ago Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs she…
CVE-2026-40261 unknown FIX debian debian sles 2mo ago Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source…
CVE-2026-40312 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malico…
CVE-2026-40310 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with w…
CVE-2026-40183 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the im…
CVE-2026-40169 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a y…
CVE-2026-33905 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an s…
CVE-2026-33902 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expres…
CVE-2026-33929 unknown debian debian sles 2mo ago Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
CVE-2026-40490 unknown debian debian 2mo ago AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects
CVE-2026-39984 unknown FIX debian debian sles 2mo ago Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimest…
CVE-2026-33901 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that cou…
CVE-2026-33908 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyX…
CVE-2026-40869 unknown 2mo ago Decidim amendments can be accepted or rejected by anyone
CVE-2009-0238 unknown 1.5 KEV 2mo ago Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that i…
CVE-2026-6216 low 3.5 3.5 2mo ago DbGate has cross site scripting via the SVG Icon String Handler component
CVE-2026-33899 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single…
CVE-2026-34238 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a h…
CVE-2026-33900 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparoun…
CVE-2026-6192 low 3.3 3.3 FIX slesdebian debian 2mo ago A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. T…
CVE-2026-40179 unknown FIX slesdebian debian 2mo ago Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of…
CVE-2026-35582 unknown 2mo ago Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
CVE-2026-6184 low 2.4 2.4 2mo ago A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Ti…
CVE-2026-33858 unknown 2mo ago Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
CVE-2025-66236 unknown 2mo ago Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
CVE-2026-36942 low 2.7 2.7 2mo ago Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.
CVE-2026-36946 low 2.7 2.7 oretnom23 2mo ago Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.
CVE-2026-36874 low 2.7 2.7 razormist 2mo ago Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.
CVE-2026-35565 unknown 2mo ago Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata
CVE-2026-35337 unknown 2mo ago Apache Storm: Deserialization of Untrusted Data vulnerability
CVE-2025-15632 low 3.5 3.5 2mo ago A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting.…
CVE-2026-6162 low 3.5 3.5 2mo ago A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdat…
CVE-2026-34621 unknown 1.5 KEV 2mo ago Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CVE-2026-21643 unknown 1.5 KEV 2mo ago Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2025-60710 unknown 1.5 KEV 2mo ago Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2023-36424 unknown 1.5 KEV 2mo ago Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2023-21529 unknown 1.5 KEV 2mo ago Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2020-9715 unknown 1.5 KEV 2mo ago Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CVE-2012-1854 unknown 1.5 KEV 2mo ago Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
CVE-2026-6106 low 3.5 3.5 2mo ago A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the co…
CVE-2026-40194 low 3.7 3.7 FIX debian debian phpseclib 2mo ago phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
CVE-2026-34177 unknown FIX debian debian 2mo ago Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of k…
CVE-2026-34178 unknown FIX debian debian 2mo ago In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a …
CVE-2026-34179 unknown FIX debian debian 2mo ago In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint…
CVE-2026-34481 unknown FIX debian debian sles google 2mo ago Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVE-2026-34480 unknown debian debian sles google 2mo ago Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 spec…
CVE-2026-34478 unknown FIX debian debian sles google 2mo ago Apache Log4j Core: log injection in `Rfc5424Layout` due to silent configuration incompatibility
CVE-2026-40228 low 3.3 3.3 slesdebian debian systemd_project 2mo ago In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
CVE-2026-6003 low 2.4 2.4 2mo ago A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument f…
CVE-2026-34487 unknown FIX slesdebian debian google 2mo ago Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat…
CVE-2026-34483 unknown FIX slesdebian debian 2mo ago Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 1…
CVE-2026-32990 unknown FIX debian debian 2mo ago Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, fro…
CVE-2026-29146 unknown FIX slesdebian debian google 2mo ago Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from …
CVE-2026-25854 unknown FIX slesdebian debian 2mo ago Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, fro…
CVE-2026-40046 unknown FIX debian debian 2mo ago Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
CVE-2026-34020 unknown 2mo ago Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
CVE-2026-33266 unknown 2mo ago Apache OpenMeetings Uses Hard-coded Cryptographic Key
CVE-2026-33005 unknown 2mo ago Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
CVE-2026-21388 low 2.5 2mo ago Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint
CVE-2026-34538 unknown 2mo ago Apache Airflow has an authorization bypass in DagRun wait endpoint
CVE-2025-62188 unknown 2mo ago Apache DolphinScheduler vulnerable to sensitive information disclosure
CVE-2026-5836 low 2.4 2.4 2mo ago A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument prod…
CVE-2026-5835 low 2.4 2.4 2mo ago A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argumen…
CVE-2026-5834 low 2.4 2.4 2mo ago A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name resul…
CVE-2026-5810 low 3.5 3.5 2mo ago A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argume…
CVE-2026-5806 low 3.5 3.5 2mo ago A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cro…
CVE-2026-39987 unknown 1.5 KEV 2mo ago Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
CVE-2026-39883 unknown FIX debian debian google 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command us…
CVE-2026-39882 unknown FIX debian debian 2mo ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a si…
CVE-2026-5795 unknown debian debian sles 2mo ago Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
CVE-2026-33229 unknown 2mo ago XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
CVE-2026-39510 low 2.7 2.7 2mo ago Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control S…
CVE-2026-39395 unknown FIX debian debian sles 2mo ago Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with…
CVE-2026-35583 unknown 2mo ago Emissary has a Path Traversal via Blacklist Bypass in Configuration API
CVE-2026-35581 unknown 2mo ago Emissary has a Command Injection via PLACE_NAME Configuration in Executrix
CVE-2026-35580 unknown 2mo ago Emissary has GitHub Actions Shell Injection via Workflow Inputs
CVE-2026-1340 unknown 2.5 KEVEXP 2mo ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CVE-2026-32289 unknown FIX debian debian sles google 2mo ago Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS …
CVE-2026-32288 unknown FIX debian debian sles google 2mo ago tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
CVE-2026-5739 unknown 2mo ago PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injection
CVE-2026-35571 unknown 2mo ago Emissary has Stored XSS via Navigation Template Link Injection