Search

Found 33,772 results in 1594ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-42062 critical 9.8 9.8 23d ago ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authenticati…
CVE-2026-40621 critical 9.8 9.8 23d ago ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
CVE-2026-41050 critical 9.9 9.9 23d ago Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVE-2026-32661 critical 9.8 9.8 23d ago Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's…
CVE-2026-44672 critical 9.5 24d ago mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dyna…
CVE-2026-44547 critical 9.6 9.6 24d ago ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/publ…
CVE-2026-42288 critical 10.0 10.0 24d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard …
CVE-2026-41901 critical 9.0 9.0 24d ago Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
CVE-2026-44650 critical 9.1 9.1 24d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44649 critical 9.8 9.8 24d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44593 critical 9.5 24d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ulti…
CVE-2026-44015 critical 9.9 9.9 nginxui 24d ago Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
CVE-2026-43948 critical 9.9 9.9 24d ago wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVE-2026-42854 critical 9.8 9.8 espressif 24d ago arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a …
CVE-2026-45185 critical 9.8 9.8 FIX debian debian sles exim 24d ago Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a C…
CVE-2026-44225 critical 9.3 9.3 24d ago Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the …
CVE-2026-44221 critical 9.0 9.0 24d ago ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
CVE-2026-42889 critical 9.1 9.1 24d ago Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured…
CVE-2026-34660 critical 9.3 9.3 adobe 24d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An …
CVE-2026-34659 critical 9.6 9.6 adobe 24d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current …
CVE-2026-44343 critical 9.8 9.8 wgdashboard 24d ago WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file sys…
CVE-2026-44277 critical 9.1 9.1 fortinet 24d ago A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attack…
CVE-2026-44196 critical 9.1 9.1 24d ago Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and …
CVE-2026-44183 critical 9.8 9.8 24d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.…
CVE-2026-42898 critical 9.9 9.9 windows windows microsoft 24d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42833 critical 9.1 9.1 windows windows microsoft 24d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42823 critical 9.9 9.9 windows windows microsoft 24d ago Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42300 critical 9.5 24d ago DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
CVE-2026-42048 critical 9.6 9.6 langflow 24d ago Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-41103 critical 9.1 9.1 windows windows microsoft 24d ago Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41096 critical 9.8 9.8 FIX windows windows 24d ago Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-41089 critical 9.8 9.8 FIX windows windows 24d ago Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVE-2026-40402 critical 9.3 9.3 FIX windows windows 24d ago Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
CVE-2026-40379 critical 9.3 9.3 windows windows microsoft 24d ago Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33117 critical 9.1 9.1 windows windows microsoft 24d ago Security feature bypass vulnerability in Azure Key Vault Keys library for Java
CVE-2026-31242 critical 9.1 9.1 mem0 24d ago The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE r…
CVE-2026-31239 critical 9.8 9.8 24d ago mamba language model framework vulnerable to insecure deserialization when loading pre-trained models from HuggingFace Hub
CVE-2026-31238 critical 9.8 9.8 24d ago Ludwig framework is vulnerable to insecure deserialization in its model serving component
CVE-2026-31237 critical 9.8 9.8 24d ago Ludwig framework is vulnerable to insecure deserialization through its predict() method.
CVE-2026-31236 critical 9.8 9.8 debian debian 24d ago llm CLI tool contains a code injection vulnerability via `--functions` command-line argument
CVE-2026-31235 critical 9.8 9.8 24d ago imgaug contains an insecure deserialization vulnerability in BackgroundAugmenter class within multicore.py module
CVE-2026-31234 critical 9.8 9.8 24d ago Horovod contains an insecure deserialization vulnerability in its KVStore HTTP server component
CVE-2026-31233 critical 9.8 9.8 24d ago Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
CVE-2026-31231 critical 9.8 9.8 24d ago Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code provided by the user,…
CVE-2026-31230 critical 9.8 9.8 24d ago The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the un…
CVE-2026-31229 critical 9.8 9.8 24d ago The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights f…
CVE-2026-29204 critical 9.1 9.1 24d ago Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized ac…
CVE-2026-26083 critical 9.8 9.8 fortinet 24d ago A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, Fort…
CVE-2026-43992 critical 9.8 9.8 24d ago JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accept…
CVE-2025-65719 critical 9.8 9.8 24d ago An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.
CVE-2026-42074 critical 9.8 9.8 gitlawb 24d ago OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashToo…
CVE-2026-43515 critical 9.1 9.1 FIX slesdebian debian apache 24d ago Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21,…
CVE-2026-43512 critical 9.8 9.8 FIX slesdebian debian apache 24d ago DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fr…
CVE-2026-41293 critical 9.8 9.8 FIX slesdebian debian apache 24d ago Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0…
CVE-2026-34187 critical 9.8 9.8 artica 24d ago Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
CVE-2026-31228 critical 9.8 9.8 24d ago The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe ev…
CVE-2026-31226 critical 9.8 9.8 24d ago The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerabi…
CVE-2026-31220 critical 9.8 9.8 24d ago PySyft server-side arbitrary Python execution after code approval
CVE-2026-31217 critical 9.8 9.8 nebuly 24d ago The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user …
CVE-2026-31216 critical 9.1 9.1 nexent 24d ago The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentica…
CVE-2026-31215 critical 9.1 9.1 nexent 24d ago The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper aut…
CVE-2026-31214 critical 9.8 9.8 24d ago The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The s…
CVE-2026-30805 critical 9.1 9.1 artica 24d ago Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
CVE-2026-8043 critical 9.6 9.6 ivanti 24d ago External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …
CVE-2026-45091 critical 9.1 9.1 24d ago sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
CVE-2026-27851 critical 9.1 9.1 FIX debian debian sles dovecotopen-xchange 24d ago When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP …
CVE-2026-41551 critical 9.1 9.1 24d ago A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote …
CVE-2026-25787 critical 9.1 9.1 24d ago Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker w…
CVE-2026-25786 critical 9.1 9.1 24d ago Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is author…
CVE-2026-22924 critical 9.1 9.1 24d ago A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion…
CVE-2025-6577 critical 9.8 9.8 24d ago Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection. This iss…
CVE-2025-40949 critical 9.1 9.1 24d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2026-34263 critical 9.6 9.6 25d ago Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to hi…
CVE-2026-34260 critical 9.6 9.6 25d ago SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The applica…
CVE-2026-45321 critical 9.6 10.0 KEV tanstackmistralantoinebcx 25d ago TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
CVE-2026-43914 critical 9.8 9.8 dani-garcia 25d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is …
CVE-2026-43900 critical 9.3 9.3 25d ago DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepanc…
CVE-2026-43899 critical 9.6 9.6 25d ago DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerabl…
CVE-2026-42882 critical 9.4 9.4 25d ago S3-Proxy has Security Issues in its Resource Path Matching Implementation
CVE-2026-42869 critical 10.0 10.0 25d ago SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value i…
CVE-2026-43898 critical 10.0 10.0 nyariv 25d ago SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That ca…
CVE-2026-42864 critical 9.9 9.9 25d ago FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
CVE-2026-8305 critical 9.8 9.8 openclaw 25d ago A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component blueb…
CVE-2026-7210 critical 9.8 9.8 slesdebian debianwindows windows libexpat_projectpython 25d ago `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this…
CVE-2026-43995 critical 9.8 9.8 flowiseai 25d ago Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
CVE-2026-43639 critical 9.1 9.1 bitwarden 25d ago Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{provide…
CVE-2026-42858 critical 9.9 9.9 openedx 25d ago Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply …
CVE-2026-38567 critical 9.8 9.8 25d ago HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker c…
CVE-2026-27478 critical 9.5 25d ago Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
CVE-2026-7813 critical 9.9 9.9 sles pgadmin 25d ago pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules
CVE-2026-44643 critical 10.0 10.0 peerigon 25d ago Angular Expressions - Remote Code Execution using filters
CVE-2026-44477 critical 9.9 9.9 linuxfoundation 25d ago CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as t…
CVE-2026-35157 critical 9.8 9.8 dell 25d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthentic…
CVE-2026-8263 critical 9.8 9.8 26d ago A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipula…
CVE-2026-28894 unknown iosmacos macos 26d ago macOS Sonoma 14.8.5
CVE-2026-1837 unknown FIX iosmacos macos tvos 26d ago visionOS 26.5
CVE-2021-47940 critical 9.8 9.8 26d ago WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fi…
CVE-2021-47936 critical 9.8 9.8 26d ago OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Att…
CVE-2021-47933 critical 9.8 9.8 26d ago WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers…
CVE-2021-47932 critical 9.8 9.8 26d ago WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler…