Search

Found 25,271 results in 931ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-59775 unknown FIX debian debianmacos macos 2mo ago Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server …
CVE-2026-33430 unknown 2mo ago Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions
CVE-2026-4595 low 2.4 2.4 2mo ago A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the file /admin/update_s6.php. Executing a manipulation of the argument sname can …
CVE-2026-4590 low 3.1 3.1 2mo ago A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the compo…
CVE-2026-4588 low 3.7 3.7 2mo ago A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-le…
CVE-2026-4633 unknown 2mo ago Keycloak's identity-first login flow exposes user information
CVE-2026-4584 low 3.1 3.1 2mo ago A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmissi…
CVE-2026-4628 unknown 2mo ago Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
CVE-2026-4578 low 2.4 2.4 3mo ago A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_s3.php. Executing a manipulation of the argument sname …
CVE-2026-4577 low 2.4 2.4 3mo ago A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname resu…
CVE-2026-4576 low 2.4 2.4 3mo ago A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /admin/update_s5.php. Such manipulation of the argument sname leads to cross site…
CVE-2026-4575 low 2.4 2.4 3mo ago A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site…
CVE-2026-33168 low 2.5 FIX slesdebian debian 3mo ago Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in…
CVE-2026-33167 low 2.5 FIX slesdebian debian 3mo ago Rails has a possible XSS vulnerability in its Action Pack debug exceptions
CVE-2026-4115 low 3.7 3.7 FIX debian debian putty 3mo ago A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verific…
CVE-2026-4541 low 2.5 2.5 FIX debian debian 3mo ago A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulat…
CVE-2026-4539 low 3.3 3.3 slesdebian debian 3mo ago A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular e…
CVE-2026-33413 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call …
CVE-2026-33343 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use n…
CVE-2026-4495 low 3.5 3.5 3mo ago A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results i…
CVE-2026-4494 low 3.5 3.5 3mo ago A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross s…
CVE-2026-4477 low 3.1 3.1 3mo ago A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function of the component WPA/WPS. Executing a manipulation can lead to use of hard-code…
CVE-2026-22737 unknown debian debian 3mo ago Spring Framework Improper Path Limitation with Script View Templates
CVE-2026-22735 unknown debian debian 3mo ago Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-22733 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
CVE-2026-22732 unknown 3mo ago Spring Security HTTP Headers Are not Written Under Some Conditions
CVE-2026-22731 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator Health groups paths
CVE-2025-43520 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel …
CVE-2025-43510 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CVE-2026-4159 low 3.3 3.3 FIX debian debian wolfssl 3mo ago 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_Decode…
CVE-2026-33322 unknown sles 3mo ago MinIO has JWT Algorithm Confusion in OIDC Authentication in github.com/minio/minio
CVE-2026-27953 unknown FIX debian debian 3mo ago ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validat…
CVE-2026-33056 unknown FIX debian debian 3mo ago tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path t…
CVE-2026-20131 unknown 1.5 KEV 3mo ago Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management…
CVE-2026-32735 unknown 3mo ago openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project…
CVE-2026-33166 unknown 3mo ago Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)
CVE-2026-33004 unknown 3mo ago Jenkins LoadNinja Plugin does not mask LoadNinja API keys displayed on the job configuration form
CVE-2026-33003 unknown 3mo ago Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in job config.xml files
CVE-2026-33002 unknown 3mo ago Jenkins has a DNS rebinding vulnerability in WebSocket CLI origin validation
CVE-2026-33001 unknown 3mo ago Jenkins has a link following vulnerability allows arbitrary file creation
CVE-2026-22730 unknown 3mo ago SQL Injection in Spring AI MariaDBFilterExpressionConverter
CVE-2026-22729 unknown 3mo ago JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
CVE-2026-2092 unknown 3mo ago Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
CVE-2026-4356 low 2.4 2.4 3mo ago A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add_result.php. Executing a manipulation of the argument vr can lead to cross site…
CVE-2026-4355 low 3.5 3.5 3mo ago A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of …
CVE-2026-4354 low 3.5 3.5 3mo ago A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 of the file apply_sec.cgi of the component Web Interface. Such manipulation of …
CVE-2026-20963 unknown 1.5 KEV 3mo ago Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2025-66376 unknown 1.5 KEV 3mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
CVE-2026-33012 unknown 3mo ago Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
CVE-2026-32636 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due t…
CVE-2026-33013 unknown 3mo ago Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
CVE-2026-30911 unknown 3mo ago Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
CVE-2026-28779 unknown 3mo ago Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
CVE-2026-28563 unknown 3mo ago Apache Airflow: DAG authorization bypass
CVE-2026-26929 unknown 3mo ago Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
CVE-2026-4285 low 2.7 2.7 3mo ago A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-module-digitalcourse/yudao-module…
CVE-2026-30405 unknown FIX debian debian 3mo ago An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
CVE-2026-4251 low 2.5 2.5 3mo ago A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credentials.…
CVE-2026-32722 unknown FIX debian debian 3mo ago Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no esc…
CVE-2026-4250 low 2.5 2.5 3mo ago A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the compone…
CVE-2026-28498 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation…
CVE-2025-54920 unknown 3mo ago Apache Spark: Spark History Server Code Execution Vulnerability
CVE-2026-28490 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning…
CVE-2026-27962 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attac…
CVE-2026-4243 low 2.5 2.5 3mo ago A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activi…
CVE-2026-4242 low 2.5 2.5 3mo ago A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an unknown function of the file file app/babychakra/babychakra/Configuration.java of…
CVE-2026-25534 unknown 3mo ago Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
CVE-2026-4239 low 3.5 3.5 3mo ago A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object pr…
CVE-2026-4225 low 2.4 2.4 3mo ago A security flaw has been discovered in CMS Made Simple up to 2.2.21. Impacted is an unknown function of the file admin/listusers.php of the component User Management Module. Performing a manipulation…
CVE-2026-4222 low 3.8 3.8 3mo ago A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of t…
CVE-2026-4218 low 2.5 2.5 3mo ago A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/me/beta/utils/EngageBayUtils.java of the component aedes.me.beta. Performing a m…
CVE-2026-4217 low 2.5 2.5 3mo ago A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function of the file in ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the com…
CVE-2026-4186 low 3.5 3.5 3mo ago A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. This man…
CVE-2026-4174 low 3.3 3.3 FIX debian debian 3mo ago A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation lea…
CVE-2026-4168 low 2.4 2.4 3mo ago A vulnerability was identified in Tecnick TCExam 16.5.0. This impacts an unknown function of the file /admin/code/tce_edit_group.php of the component Group Handler. Such manipulation of the argument …
CVE-2026-4166 low 3.5 3.5 3mo ago A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in c…
CVE-2026-4165 low 2.4 2.4 3mo ago A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. The affected element is an unknown function of the file /account/orders/create. The manipulation of the argume…
CVE-2025-47813 unknown 1.5 KEV 3mo ago Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
CVE-2025-66249 unknown 3mo ago Apache Livy: Unauthorized directory access
CVE-2025-60012 unknown 3mo ago Apache Livy: Restrict file access
CVE-2026-3910 unknown 1.5 KEVFIX debian debian 3mo ago Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via …
CVE-2026-3909 unknown 1.5 KEVFIX debian debian 3mo ago Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome a…
CVE-2023-1289 unknown FIX slesdebian debian 3mo ago A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file …
CVE-2026-4045 low 3.7 3.7 3mo ago A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable re…
CVE-2026-4044 low 3.8 3.8 3mo ago A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument …
CVE-2026-30937 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) enco…
CVE-2026-30936 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a crafted image could cause an out of bounds heap write inside…
CVE-2026-30935 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, BilateralBlurImage contains a heap buffer over-read caused by an incorrect c…
CVE-2026-30931 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncatio…
CVE-2026-30929 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a spec…
CVE-2026-28693 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds r…
CVE-2026-28691 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in t…
CVE-2026-28690 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encode…
CVE-2026-28688 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder,…
CVE-2026-28687 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decod…
CVE-2026-28686 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode …
CVE-2026-28494 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology ker…
CVE-2026-28493 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerabil…
CVE-2026-26284 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huf…
CVE-2026-25986 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVIm…