Search

Found 58,277 results in 6571ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-46693 medium 5.5 FIX debian debian 14d ago ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
CVE-2026-46692 medium 5.5 FIX debian debian 14d ago ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
CVE-2026-5755 medium 6.5 6.5 mattermost 14d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, whic…
CVE-2026-4646 medium 4.3 4.3 mattermost 14d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to cr…
CVE-2026-4635 medium 5.3 5.3 mattermost 14d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to c…
CVE-2026-3636 medium 4.3 4.3 mattermost 14d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allow…
CVE-2026-8692 medium 4.3 4.3 14d ago The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due …
CVE-2026-8684 medium 5.3 5.3 14d ago The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is aut…
CVE-2026-8381 medium 5.4 5.4 14d ago A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an a…
CVE-2026-7798 medium 5.4 5.4 14d ago The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions…
CVE-2026-7636 medium 4.3 4.3 14d ago The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. …
CVE-2026-7615 medium 4.3 4.3 14d ago The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widge…
CVE-2026-5072 medium 6.5 6.5 14d ago A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT message to se…
CVE-2026-9104 medium 6.4 6.4 15d ago The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output esc…
CVE-2026-7509 medium 6.4 6.4 15d ago The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` attributes in all versions up to, and including, 4.0.…
CVE-2026-7249 medium 4.3 4.3 15d ago The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()`…
CVE-2026-6864 medium 6.1 6.1 15d ago The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sani…
CVE-2026-4070 medium 4.3 4.3 15d ago The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_manage() fun…
CVE-2026-3481 medium 6.1 6.1 15d ago The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input saniti…
CVE-2026-2518 medium 4.3 4.3 15d ago The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' fun…
CVE-2026-46598 medium 5.3 5.3 FIX debian debian sleswindows windows golang 15d ago For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.
CVE-2026-46595 critical 10.0 10.0 FIX debian debian sleswindows windows golang 15d ago Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would…
CVE-2026-42508 critical 9.1 9.1 FIX debian debian sleswindows windows golang 15d ago Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-39835 medium 5.3 5.3 FIX debian debian sleswindows windows golang 15d ago SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an…
CVE-2026-39834 critical 9.1 9.1 FIX debian debian sleswindows windows golang 15d ago When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty pack…
CVE-2026-39833 critical 9.1 9.1 FIX debian debian sleswindows windows golang 15d ago The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indicatio…
CVE-2026-39832 critical 9.1 9.1 FIX debian debian sleswindows windows golang 15d ago When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forward…
CVE-2026-39831 critical 9.1 9.1 FIX debian debian sleswindows windows golang 15d ago The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch …
CVE-2026-39830 critical 9.1 9.1 FIX debian debian sleswindows windows golang 15d ago A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), r…
CVE-2026-39828 medium 6.3 6.3 FIX debian debian sleswindows windows golang 15d ago When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as forc…
CVE-2026-39827 medium 6.5 6.5 FIX debian debian sleswindows windows golang 15d ago An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.…
CVE-2026-9264 critical 9.3 9.3 15d ago A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerabil…
CVE-2026-34910 critical 10.0 10.0 15d ago A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
CVE-2026-34909 critical 10.0 10.0 15d ago A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an und…
CVE-2026-34908 critical 10.0 10.0 15d ago A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
CVE-2026-33000 critical 9.1 9.1 15d ago A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
CVE-2026-8435 medium 6.5 6.5 concretecms 15d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4…
CVE-2026-8337 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unau…
CVE-2026-8327 medium 4.3 4.3 concretecms 15d ago Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo…
CVE-2026-8245 medium 5.4 5.4 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL fi…
CVE-2026-8240 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealing the existence of private, draft, and restricted …
CVE-2026-8239 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security …
CVE-2026-8238 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enume…
CVE-2026-8237 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enu…
CVE-2026-8236 medium 4.3 4.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns int…
CVE-2026-8139 medium 5.4 5.4 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnera…
CVE-2026-7890 medium 6.4 6.4 concretecms 15d ago In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.  The Concrete CM…
CVE-2026-7887 medium 6.4 6.4 concretecms 15d ago For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and r…
CVE-2026-7886 medium 4.3 4.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation …
CVE-2026-7882 medium 4.3 4.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and procee…
CVE-2026-7881 medium 4.3 4.3 concretecms 15d ago Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express…
CVE-2026-7879 medium 5.3 5.3 concretecms 15d ago In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypa…
CVE-2026-6960 critical 9.8 9.8 15d ago The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versio…
CVE-2026-5091 medium 5.1 5.1 FIX debian debian 15d ago Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess…
CVE-2026-4929 medium 5.4 5.4 simple_hierarchical_select_project 15d ago Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_fie…
CVE-2026-4093 medium 5.4 5.4 taxonomy_term_reference_tree_widget_project 15d ago In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token di…
CVE-2026-22678 medium 5.4 5.4 webmin 15d ago Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attack…
CVE-2026-46678 medium 5.5 15d ago Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
CVE-2026-46671 medium 5.5 15d ago Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
CVE-2026-46645 medium 5.5 15d ago SQLAdmin: Authorization Bypass on `ajax_lookup`
CVE-2026-8205 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being…
CVE-2026-8204 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot…
CVE-2026-8203 medium 5.4 5.4 concretecms 15d ago Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that execute…
CVE-2026-8197 medium 4.8 4.8 concretecms 15d ago Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation he…
CVE-2026-8140 medium 6.5 6.5 concretecms 15d ago Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dash…
CVE-2026-6826 medium 5.3 5.3 concretecms 15d ago Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unauthenticated visitor can request /ccm/system/dialogs…
CVE-2026-46609 medium 5.5 15d ago Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
CVE-2026-46556 medium 5.5 15d ago FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
CVE-2026-46554 low 2.5 15d ago NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-46553 low 2.5 15d ago NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-46552 medium 5.5 15d ago NocoDB: Shared-base link access can invite arbitrary users as persistent base members
CVE-2026-46551 medium 5.5 15d ago NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
CVE-2026-46550 medium 5.5 15d ago NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
CVE-2026-46549 low 2.5 15d ago NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-46548 medium 5.5 15d ago NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
CVE-2026-46547 medium 5.5 15d ago NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
CVE-2026-46668 low 2.5 15d ago SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-46683 medium 5.5 15d ago Snappy : SSRF and local file read via the xsl-style-sheet option
CVE-2026-46618 medium 5.5 15d ago Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
CVE-2026-4843 medium 4.3 4.3 15d ago The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and …
CVE-2026-46614 critical 9.5 15d ago Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
CVE-2026-46616 medium 5.5 15d ago Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
CVE-2026-46561 medium 5.0 5.0 15d ago pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An…
CVE-2026-46543 medium 5.5 15d ago nimiq-blockchain: Genesis batch set request
CVE-2026-46542 medium 5.5 15d ago nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
CVE-2026-46539 medium 5.5 15d ago nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
CVE-2026-46497 low 2.5 15d ago Crawlee for Python: SSRF via sitemap-derived URLs
CVE-2026-48249 medium 5.9 5.9 15d ago Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing …
CVE-2026-48248 medium 5.9 5.9 15d ago Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound H…
CVE-2026-48247 medium 5.9 5.9 15d ago Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbou…
CVE-2026-48246 medium 5.9 5.9 15d ago Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTT…
CVE-2026-48245 medium 5.3 5.3 15d ago Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can be extracted by anyone with read access to the sour…
CVE-2026-48244 medium 5.3 5.3 15d ago Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to th…
CVE-2026-48243 medium 5.3 5.3 15d ago Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can ext…
CVE-2026-48230 medium 5.4 5.4 15d ago Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsan…
CVE-2026-48229 medium 5.4 5.4 15d ago Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized va…
CVE-2026-48228 medium 5.4 5.4 15d ago Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized v…
CVE-2026-48227 medium 5.4 5.4 15d ago Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized val…
CVE-2026-48226 medium 5.4 5.4 15d ago Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized va…
CVE-2026-48225 medium 5.4 5.4 15d ago Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value…