Search

Found 41,182 results in 2155ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6073 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arb…
CVE-2026-6063 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authent…
CVE-2026-5243 medium 6.4 6.4 24d ago The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` …
CVE-2026-4527 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to creat…
CVE-2026-4524 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access…
CVE-2026-3829 medium 5.4 5.4 24d ago The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks…
CVE-2026-3607 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with develo…
CVE-2026-3160 medium 5.8 5.8 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jir…
CVE-2026-3074 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to downlo…
CVE-2026-3073 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with develo…
CVE-2026-1338 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with devel…
CVE-2025-15345 medium 6.1 6.1 24d ago The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.2…
CVE-2025-13874 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest …
CVE-2025-12669 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject …
CVE-2026-7648 medium 4.3 4.3 24d ago The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. …
CVE-2026-7525 medium 4.3 4.3 24d ago The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying tha…
CVE-2026-5361 medium 6.4 6.4 24d ago The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in th…
CVE-2026-5486 medium 6.5 6.5 24d ago The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.…
CVE-2026-44919 medium 4.3 4.3 FIX debian debian 24d ago In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
CVE-2026-41281 medium 4.8 4.8 24d ago Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify commun…
CVE-2026-44448 medium 6.5 6.5 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyo…
CVE-2026-44445 medium 6.5 6.5 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enab…
CVE-2026-44441 medium 4.3 4.3 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making…
CVE-2026-44440 medium 5.7 5.7 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on …
CVE-2026-44437 medium 6.1 6.1 angular 25d ago The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix he…
CVE-2026-44426 medium 6.5 6.5 shellhub 25d ago ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
CVE-2026-44425 medium 5.4 5.4 shellhub 25d ago ShellHub has crash-DoS via field injection in filter and sort-by parameters
CVE-2026-44424 medium 6.5 6.5 shellhub 25d ago ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
CVE-2026-44423 medium 6.5 6.5 shellhub 25d ago ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
CVE-2026-44195 medium 6.5 6.5 opnsense 25d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication fa…
CVE-2026-45228 medium 5.4 5.4 25d ago Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without…
CVE-2026-45054 medium 4.9 4.9 25d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-con…
CVE-2026-44381 medium 5.3 5.3 misp 25d ago MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow …
CVE-2026-44379 medium 5.3 5.3 misp 25d ago MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or mo…
CVE-2026-44376 medium 6.1 7.1 EXP 25d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.p…
CVE-2026-44373 medium 5.3 5.3 nitro 25d ago Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward…
CVE-2026-44372 medium 6.1 6.1 nitro 25d ago Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after…
CVE-2026-44368 medium 5.5 25d ago pyquorum: Timing side‑channel in mul_mod
CVE-2026-39428 medium 4.8 4.8 25d ago CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can inject malicious …
CVE-2025-27852 medium 5.0 5.0 garmin 25d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary Jav…
CVE-2026-44363 medium 5.5 25d ago misp-modules has nsafe remote resource fetching in expansion
CVE-2026-33381 medium 5.9 5.9 sles 25d ago When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
CVE-2026-33380 medium 6.3 6.3 sles 25d ago A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vul…
CVE-2026-33378 medium 6.5 6.5 sles grafana 25d ago Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the …
CVE-2026-28383 medium 6.5 6.5 sles grafana 25d ago A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-me…
CVE-2026-28380 medium 6.5 6.5 sles grafana 25d ago Any Editor could delete any snapshot, even if they have no access to read or write them.
CVE-2026-28379 medium 6.5 6.5 sles grafana 25d ago A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete ser…
CVE-2026-28376 medium 6.5 6.5 sles grafana 25d ago The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated us…
CVE-2026-28374 medium 4.3 4.3 sles grafana 25d ago Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
CVE-2026-8496 medium 6.1 6.1 FIX debian debian 25d ago A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated S…
CVE-2026-42580 medium 6.5 6.5 slesdebian debian netty 25d ago Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
CVE-2026-41255 medium 6.1 6.1 okfn 25d ago CKAN has CSRF exemption primed by anonymous requests
CVE-2026-33584 medium 5.3 5.3 25d ago Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Sym…
CVE-2026-30904 medium 4.3 4.3 zoom 25d ago Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access.
CVE-2026-22677 medium 6.5 6.5 25d ago Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted session with an…
CVE-2026-44581 medium 4.7 4.7 vercel 25d ago Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
CVE-2026-44580 medium 6.1 6.1 vercel 25d ago Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
CVE-2026-44003 medium 5.8 5.8 vm2_project 25d ago vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
CVE-2026-44002 medium 5.8 5.8 vm2_project 25d ago vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
CVE-2026-44577 medium 5.9 5.9 vercel 25d ago Next.js has a Denial of Service in the Image Optimization API
CVE-2026-44576 medium 5.4 5.4 vercel 25d ago Next.js vulnerable to cache poisoning in React Server Component responses
CVE-2026-2695 medium 6.3 6.3 25d ago A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users…
CVE-2024-48519 medium 6.2 6.2 25d ago Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRo…
CVE-2026-8367 medium 4.8 4.8 debian debian 25d ago aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be ab…
CVE-2026-45028 medium 6.1 6.1 astro 25d ago Astro: Server island encrypted parameters vulnerable to cross-component replay
CVE-2026-44665 medium 6.1 6.1 25d ago fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
CVE-2026-44664 medium 6.1 6.1 25d ago fast-xml-builder Comment Value regex can be bypassed
CVE-2026-44572 medium 5.9 5.9 vercel 25d ago Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-44479 medium 5.5 5.5 vercel 25d ago Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), comma…
CVE-2026-44467 medium 6.8 6.8 anthropic 25d ago The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development fea…
CVE-2026-44458 medium 4.3 4.3 hono 25d ago Hono has CSS Declaration Injection via Style Object Values in JSX SSR
CVE-2026-44457 medium 5.3 5.3 hono 25d ago Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
CVE-2026-44456 medium 6.5 6.5 hono 25d ago Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
CVE-2026-44455 medium 6.1 6.1 hono 25d ago hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
CVE-2026-44431 medium 5.3 5.3 slesdebian debianwindows windows pythongoogle 25d ago urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fa…
CVE-2026-44294 medium 5.3 5.3 protobufjs_project 25d ago protobuf.js: Denial of service from crafted field names in generated code
CVE-2026-44292 medium 5.3 5.3 protobufjs_project 25d ago protobuf.js: Prototype injection in generated message constructors
CVE-2026-44288 medium 5.3 5.3 protobufjs_project 25d ago protobufjs has overlong UTF-8 decoding
CVE-2026-42946 medium 6.5 6.5 FIX slesdebian debianwindows windows 25d ago A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured…
CVE-2026-42937 medium 6.5 6.5 25d ago Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attack…
CVE-2026-42934 medium 4.8 4.8 FIX slesdebian debianwindows windows 25d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar…
CVE-2026-42926 medium 5.8 5.8 FIX slesdebian debian 25d ago When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the…
CVE-2026-42919 medium 6.7 6.7 25d ago A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a secur…
CVE-2026-42781 medium 6.5 6.5 25d ago When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utiliz…
CVE-2026-42780 medium 4.9 4.9 25d ago A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software …
CVE-2026-42408 medium 4.4 4.4 25d ago When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Soft…
CVE-2026-42063 medium 4.9 4.9 25d ago A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files.  Note: Software versions which have reached…
CVE-2026-42058 medium 4.3 4.3 25d ago An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names.  Note: Software versions which have reached End of Technic…
CVE-2026-41959 medium 6.5 6.5 25d ago Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated…
CVE-2026-41954 medium 4.9 4.9 25d ago Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator rol…
CVE-2026-41219 medium 6.5 6.5 25d ago An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which ha…
CVE-2026-40703 medium 5.4 5.4 25d ago A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not eval…
CVE-2026-40701 medium 4.8 4.8 FIX slesdebian debianwindows windows 25d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or…
CVE-2026-40699 medium 6.5 6.5 25d ago A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information.  Note: Software ver…
CVE-2026-40462 medium 6.5 6.5 25d ago Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information.  Note: Softwa…
CVE-2026-40460 medium 6.5 6.5 FIX slesdebian debianwindows windows 25d ago When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limi…
CVE-2026-40435 medium 5.3 5.3 25d ago When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Su…
CVE-2026-36742 medium 6.8 6.8 25d ago Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).
CVE-2026-36738 medium 6.8 6.8 25d ago U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control me…
CVE-2026-35062 medium 6.5 6.5 25d ago An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.