Search

Found 33,772 results in 1259ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2021-47923 critical 9.8 9.8 26d ago OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID c…
CVE-2026-6104 critical 9.1 9.1 FIX slesdebian debian php 26d ago In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectl…
CVE-2026-7261 critical 9.8 9.8 FIX slesdebian debianwindows windows php 27d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted acr…
CVE-2026-6722 critical 9.8 9.8 FIX slesdebian debianwindows windows php 27d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global m…
CVE-2025-14179 critical 9.8 9.8 FIX slesdebian debianwindows windows php 27d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by…
CVE-2026-42571 critical 9.5 27d ago Pelican Web UI Affected by a Privilege Escalation Attack
CVE-2026-42560 critical 9.1 9.1 27d ago auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
CVE-2026-6665 critical 9.8 9.8 FIX debian debianwindows windows pgbouncer 28d ago The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM se…
CVE-2026-44313 critical 9.1 9.1 28d ago Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the f…
CVE-2026-42556 critical 9.0 9.0 gitroom 28d ago Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their ow…
CVE-2026-42454 critical 9.9 9.9 28d ago Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate t…
CVE-2026-42354 critical 9.8 9.8 sentry 28d ago Sentry's improper authentication on SAML SSO process allows user identity linking
CVE-2026-42302 critical 9.8 9.8 28d ago FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The star…
CVE-2026-42298 critical 9.8 9.8 gitroom 28d ago Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows a…
CVE-2026-37709 critical 9.8 9.8 snipeitapp 28d ago Snipe-IT has insecure permissions in file uploads
CVE-2026-42193 critical 9.1 9.1 28d ago Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verif…
CVE-2026-44400 critical 9.8 9.8 mailenable 28d ago MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing Authent…
CVE-2026-44211 critical 9.6 9.6 cline 28d ago Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time o…
CVE-2026-44694 critical 9.1 9.1 n8n-mcp 28d ago n8n-mcp webhook and API client paths has an authenticated SSRF
CVE-2026-44551 critical 9.1 9.1 openwebui 28d ago Open WebUI has an LDAP Empty Password Authentication Bypass
CVE-2026-42072 critical 9.8 9.8 28d ago NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
CVE-2026-41889 critical 9.8 9.8 debian debian sleswindows windows jackc 28d ago pgx: SQL Injection via placeholder confusion with dollar quoted string literals
CVE-2026-38360 critical 9.8 9.8 28d ago Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHan…
CVE-2026-44212 critical 9.3 9.3 28d ago PrestaShop has a stored XSS executable in customer service view
CVE-2026-41070 critical 10.0 10.0 FIX debian debian 28d ago openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
CVE-2026-44497 critical 9.1 9.1 zfnd 28d ago Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer
CVE-2026-43465 critical 9.8 9.8 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf programs can modify the layout of the XDP buffer whe…
CVE-2026-43414 critical 9.8 9.8 FIX slesdebian debianwindows windows 28d ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When a…
CVE-2026-43407 critical 9.1 9.1 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_a…
CVE-2026-43406 critical 9.1 9.1 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If the message frame is (maliciously) corrupted in a w…
CVE-2026-43402 critical 9.8 9.8 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume reported crashes via corrupted RCU callback function …
CVE-2026-43384 critical 9.8 9.8 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the…
CVE-2026-43383 critical 9.4 9.4 FIX slesdebian debian linux-kernel google 28d ago In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use th…
CVE-2026-43379 critical 9.8 9.8 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is bei…
CVE-2026-43376 critical 9.8 9.8 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even t…
CVE-2026-41583 critical 9.1 9.1 zfnd 28d ago Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
CVE-2026-41574 critical 9.8 9.8 nhost 28d ago Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
CVE-2026-37431 critical 9.8 9.8 28d ago Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers …
CVE-2026-44336 critical 9.6 9.6 praison 28d ago PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
CVE-2026-44335 critical 9.8 9.8 praison 28d ago PraisonAI has an SSRF bypass
CVE-2026-43341 critical 9.8 9.8 FIX slesdebian debian linux-kernel google 28d ago In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trace_data() stores the schema contribution to the tra…
CVE-2026-43304 critical 9.8 9.8 FIX slesdebian debian linux-kernel 28d ago In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that the key material would fit into a fixed-size buff…
CVE-2026-41512 critical 9.9 9.9 mozilla 28d ago ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection in `BrowserAutomati…
CVE-2026-41509 critical 9.8 9.8 cross-crypto 28d ago CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused b…
CVE-2026-41507 critical 9.8 9.8 mauriciopoppe 28d ago Remote Code Execution (RCE) via String Literal Injection into math-codegen
CVE-2026-41497 critical 9.8 9.8 praison 28d ago PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
CVE-2026-25199 critical 9.1 9.1 apache 28d ago Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxm…
CVE-2026-8153 critical 9.8 9.8 28d ago OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS.
CVE-2013-10075 critical 9.1 9.1 debian debian chorny 28d ago Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not ex…
CVE-2025-69691 critical 9.9 9.9 pfsense 28d ago Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally all…
CVE-2025-69690 critical 9.1 9.1 pfsense 28d ago Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes …
CVE-2025-69599 critical 9.8 9.8 28d ago RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to c…
CVE-2025-67887 critical 9.8 9.8 28d ago 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess fil…
CVE-2023-46453 critical 9.8 9.8 28d ago Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular express…
CVE-2024-51092 critical 9.1 10.0 EXP librenms 28d ago LibreNMS has an Authenticated OS Command Injection
CVE-2026-43944 critical 9.6 9.6 electerm_project 29d ago Electerm users can run dangrous code through link or command line
CVE-2026-43941 critical 9.6 9.6 electerm_project 29d ago Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
CVE-2026-42264 critical 9.1 9.1 FIX slesdebian debian axios 29d ago Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
CVE-2026-42208 critical 9.8 10.0 KEV litellm 29d ago BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the cr…
CVE-2026-41900 critical 10.0 10.0 th30d4y 29d ago OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution envir…
CVE-2026-41501 critical 9.8 9.8 electerm_project 29d ago electerm has Command Injection via runLinux funtion
CVE-2026-41500 critical 9.8 9.8 electerm_project 29d ago electerm: electerm_install_script_CommandInjection Vulnerability Report
CVE-2026-42880 critical 9.6 9.6 argoproj 29d ago ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-8034 critical 9.8 9.8 github 29d ago A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusi…
CVE-2026-42826 critical 10.0 10.0 windows windows microsoft 29d ago Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
CVE-2026-35428 critical 9.6 9.6 windows windows microsoft 29d ago Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33844 critical 9.0 9.0 windows windows microsoft 29d ago Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
CVE-2026-33823 critical 9.6 9.6 windows windows microsoft 29d ago Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-33109 critical 9.9 9.9 windows windows microsoft 29d ago Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
CVE-2026-41691 critical 9.1 9.1 i18next 29d ago Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3…
CVE-2026-42284 critical 9.8 9.8 FIX slesdebian debian gitpython_project 29d ago GitPython: Unsafe option check validates multi_options before shlex.split transformation
CVE-2026-41902 critical 9.1 9.1 29d ago FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new use…
CVE-2026-7415 critical 9.8 9.8 29d ago The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetr…
CVE-2026-7414 critical 9.8 9.8 29d ago Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or r…
CVE-2026-7413 critical 9.8 9.8 29d ago A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cann…
CVE-2026-7821 critical 9.1 9.1 ivanti 29d ago Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled…
CVE-2026-5788 critical 9.8 9.8 ivanti 29d ago An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
CVE-2026-5787 critical 9.1 9.1 ivanti 29d ago An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-…
CVE-2025-63704 critical 9.8 9.8 29d ago query-parser-string is vulnerable to Prototype Pollution
CVE-2025-63703 critical 9.8 9.8 29d ago parse-ini is vulnerable to Prototype Pollution in index.js()
CVE-2026-36458 critical 9.8 9.8 29d ago ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered.
CVE-2025-63706 critical 9.8 9.8 29d ago next-npm-version is vulnerable to Command injection
CVE-2026-6795 critical 9.6 9.6 29d ago URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 befor…
CVE-2026-41589 critical 9.6 9.6 charm 29d ago Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A ma…
CVE-2026-30496 critical 9.8 9.8 29d ago The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports bot…
CVE-2026-8091 critical 9.8 9.8 FIX debian debian sles mozilla 29d ago Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.…
CVE-2026-6508 critical 9.8 9.8 29d ago Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Lidera…
CVE-2026-33587 critical 10.0 10.0 lfnovo 29d ago Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (S…
CVE-2025-1978 critical 9.8 9.8 hitachi 29d ago Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Vi…
CVE-2025-9661 critical 9.8 9.8 hitachi 29d ago OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform On…
CVE-2026-41586 critical 9.5 29d ago fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE
CVE-2026-44603 critical 9.1 9.1 FIX debian debian torproject 1mo ago Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
CVE-2026-42217 critical 9.8 9.8 slesdebian debian openexr 1mo ago OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…
CVE-2026-42216 critical 9.1 9.1 slesdebian debian openexr 1mo ago OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…
CVE-2026-41203 critical 9.5 1mo ago CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
CVE-2026-41202 critical 9.5 1mo ago CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
CVE-2026-41201 critical 9.1 9.1 1mo ago CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
CVE-2026-40982 critical 9.1 9.1 vmware 1mo ago Spring Cloud Config vulnerable to Path Traversal
CVE-2026-44597 critical 9.1 9.1 FIX debian debian torproject 1mo ago Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
CVE-2026-40281 critical 9.1 9.1 thecodingmachine 1mo ago Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)