Search

Found 33,802 results in 1341ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6887 critical 9.8 9.8 1mo ago Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, mod…
CVE-2026-6886 critical 9.8 9.8 1mo ago Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.
CVE-2026-6885 critical 9.8 9.8 1mo ago Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell back…
CVE-2026-3960 critical 9.8 9.8 h2o 1mo ago H2O-3 is Vulnerable to Code Injection
CVE-2026-41211 critical 10.0 10.0 voidzero 1mo ago Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
CVE-2026-41196 critical 10.0 10.0 FIX debian debian minetest 1mo ago Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to…
CVE-2026-5935 critical 9.8 9.8 ibm 1mo ago IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due …
CVE-2026-41179 critical 9.8 9.8 debian debian rclone 1mo ago RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CVE-2026-29198 critical 9.8 9.8 rocket.chat 1mo ago In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OA…
CVE-2026-42087 critical 9.6 9.6 openc3 1mo ago OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
CVE-2026-41167 critical 9.1 9.1 1mo ago Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields direct…
CVE-2026-41239 unknown FIX debian debian 1mo ago DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrust…
CVE-2026-41238 unknown FIX debian debian 1mo ago DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMP…
CVE-2026-32885 critical 9.1 9.1 ddev 1mo ago DDEV has ZipSlip path traversal in tar and zip archive extraction
CVE-2018-25272 critical 9.8 9.8 1mo ago ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to …
CVE-2026-41176 critical 9.5 debian debian 1mo ago Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
CVE-2026-41166 unknown 1mo ago OpenRemote has Improper Access Control via updateUserRealmRoles function
CVE-2026-6356 critical 9.6 9.6 augmentt 1mo ago A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitiv…
CVE-2026-31501 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_hdesc_get_psdata() returns a pointer into the CPPI …
CVE-2026-31478 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add supp…
CVE-2026-31463 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Commit aa35dd5cbc06 ("iomap: fix invalid folio access…
CVE-2026-31448 critical 9.4 9.4 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if in…
CVE-2026-31444 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequen…
CVE-2026-31436 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal c…
CVE-2026-6023 critical 9.8 9.8 progress 2mo ago In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the c…
CVE-2026-41144 critical 9.8 9.8 nasa 2mo ago F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize …
CVE-2026-40575 critical 9.1 9.1 oauth2_proxy_project 2mo ago OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-5845 critical 9.6 9.6 github 2mo ago An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the int…
CVE-2026-40942 unknown 2mo ago Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
CVE-2026-40939 unknown 2mo ago Data Sharing Framework is Missing Session Timeout for OIDC Sessions
CVE-2026-40910 critical 9.1 9.1 fatedier 2mo ago frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access control
CVE-2026-33519 critical 9.8 9.8 linux-kernel esrikubernetes 2mo ago An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentia…
CVE-2026-40903 critical 9.1 9.1 goshs 2mo ago goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the…
CVE-2026-40372 critical 9.1 9.1 microsoft 2mo ago Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-39386 unknown 2mo ago Neko has a Self-service Privilege Escalation for Authenticated Users in github.com/m1k1o/neko/server
CVE-2026-5652 critical 9.0 9.0 craftycontrol 2mo ago An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permiss…
CVE-2026-32613 unknown 2mo ago Spinnaker: RCE via expression parsing due to unrestricted context handling
CVE-2026-32604 unknown 2mo ago Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVE-2026-6783 unknown FIX debian debian 2mo ago Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6782 unknown FIX debian debian 2mo ago Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6781 unknown FIX debian debian 2mo ago Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6778 unknown FIX debian debian 2mo ago Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6777 unknown FIX debian debian 2mo ago Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6775 unknown FIX debian debian 2mo ago Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6774 unknown FIX debian debian 2mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6773 unknown FIX debian debian 2mo ago Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6768 unknown FIX debian debian 2mo ago Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6755 unknown FIX debian debian 2mo ago Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-5965 critical 9.8 9.8 2mo ago NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-6257 critical 9.1 9.1 2mo ago Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to r…
CVE-2026-32311 critical 9.8 9.8 flowsint 2mo ago Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to ma…
CVE-2026-33558 unknown 2mo ago Apache Kafka exposes sensitive information in its DEBUG logs
CVE-2026-33557 unknown 2mo ago Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
CVE-2026-5760 critical 9.8 9.8 lmsys 2mo ago SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered usin…
CVE-2026-5964 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-5963 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-6644 critical 9.1 9.1 2mo ago A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary co…
CVE-2026-20133 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
CVE-2026-20128 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential fil…
CVE-2026-20122 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulne…
CVE-2025-48700 unknown 1.5 KEV 2mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to una…
CVE-2025-32975 unknown 1.5 KEV 2mo ago Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
CVE-2025-2749 unknown 1.5 KEV 2mo ago Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
CVE-2024-27199 unknown 1.5 KEV 2mo ago JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2023-27351 unknown 1.5 KEV 2mo ago PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2026-32690 unknown 2mo ago Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
CVE-2026-30912 unknown 2mo ago Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
CVE-2026-40324 critical 9.1 9.1 2mo ago ChilliCream GraphQL Platform: Utf8GraphQLParser Stack Overflow via Deeply Nested GraphQL Documents
CVE-2026-5720 critical 9.1 9.1 FIX debian debian miniupnp_project 2mo ago miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPActio…
CVE-2026-40351 critical 9.8 9.8 fastgpt 2mo ago FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attac…
CVE-2026-40258 critical 9.1 9.1 2mo ago gramps-webapi: Zip Slip Path Traversal in Media Archive Import
CVE-2026-29013 critical 9.8 9.8 FIX debian debian libcoap 2mo ago libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which i…
CVE-2026-23500 critical 9.1 9.1 dolibarr 2mo ago Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
CVE-2026-35546 critical 9.8 9.8 2mo ago Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
CVE-2026-40525 critical 9.1 9.1 volcengine 2mo ago OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
CVE-2026-40518 critical 9.1 9.1 bytedance 2mo ago ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attacker…
CVE-2026-40458 unknown 2mo ago PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2025-15625 critical 9.8 9.8 sparxsystems 2mo ago Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
CVE-2026-41242 critical 9.5 2mo ago Arbitrary code execution in protobufjs
CVE-2026-40611 unknown FIX debian debian 2mo ago Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A ma…
CVE-2026-41245 unknown 2mo ago Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
CVE-2026-30778 unknown 2mo ago SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information
CVE-2026-5426 critical 9.1 9.1 2mo ago Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot…
CVE-2026-33804 critical 9.1 9.1 fastify 2mo ago @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
CVE-2026-6270 critical 9.1 9.1 fastify 2mo ago @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CVE-2026-31843 critical 9.8 9.8 2mo ago goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
CVE-2026-6350 critical 9.8 9.8 2mo ago MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
CVE-2026-6349 critical 9.8 9.8 2mo ago The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-40504 critical 9.8 9.8 2mo ago Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string li…
CVE-2026-40959 critical 9.3 9.3 FIX slesdebian debian 2mo ago Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
CVE-2026-32179 critical 9.5 2mo ago MsQuic has a Remote Elevation of Privilege Vulnerability
CVE-2026-33808 critical 9.1 9.1 fastify 2mo ago Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-…
CVE-2026-33807 critical 9.1 9.1 fastify 2mo ago @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is register…
CVE-2026-6296 critical 9.6 9.6 FIX debian debian linux-kernelmacos macos google 2mo ago Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-40478 unknown 2mo ago Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
CVE-2026-40477 unknown 2mo ago Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-40347 unknown FIX slesdebian debian 2mo ago Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
CVE-2026-40882 unknown 2mo ago OpenRemote has XXE in Velbus Asset Import
CVE-2026-6313 unknown FIX debian debian 2mo ago Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. …
CVE-2026-5598 unknown FIX debian debian sles 2mo ago Bouncy Castle Has Covert Timing Channel Vulnerability