Search

Found 38,276 results in 2980ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41211 critical 10.0 10.0 voidzero 2mo ago Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
CVE-2026-41196 critical 10.0 10.0 FIX debian debian minetest 2mo ago Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to…
CVE-2026-5935 critical 9.8 9.8 ibm 2mo ago IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due …
CVE-2026-41179 critical 9.8 9.8 debian debian rclone 2mo ago RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CVE-2026-29198 critical 9.8 9.8 rocket.chat 2mo ago In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OA…
CVE-2026-42087 critical 9.6 9.6 openc3 2mo ago OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
CVE-2026-41167 critical 9.1 9.1 2mo ago Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields direct…
CVE-2026-35381 low 2.5 FIX debian debian 2mo ago A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) options together. The im…
CVE-2026-35377 low 2.5 debian debian 2mo ago uutils coreutils has an Improper Input Validation Issue in its env Utility
CVE-2026-35367 low 2.5 FIX debian debian 2mo ago uutils coreutils has an Incorrect Permission Assignment for Critical Resource
CVE-2026-35362 low 2.5 FIX debian debian 2mo ago The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to…
CVE-2026-35361 low 2.5 FIX debian debian 2mo ago The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std…
CVE-2026-35353 low 2.5 FIX debian debian 2mo ago The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them …
CVE-2026-35346 low 2.5 FIX debian debian 2mo ago The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 b…
CVE-2026-41239 unknown FIX debian debian 2mo ago DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrust…
CVE-2026-41238 unknown FIX debian debian 2mo ago DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMP…
CVE-2026-35379 low 3.3 3.3 FIX debian debian uutils 2mo ago A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space char…
CVE-2026-35378 low 3.3 3.3 FIX debian debian uutils 2mo ago A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the execution phase. This implementation flaw…
CVE-2026-35375 low 3.3 3.3 FIX debian debian uutils 2mo ago A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-UTF-8 prefix or suffix inputs. The implementation utilizes to_string_lossy() wh…
CVE-2026-35371 low 3.3 3.3 debian debian uutils 2mo ago uutils coreutils's User Interface (UI) Misrepresents Critical Information
CVE-2026-35344 low 3.3 3.3 debian debian uutils 2mo ago uutils coreutils has an Unchecked Return Value Issue
CVE-2026-35343 low 3.3 3.3 FIX debian debian uutils 2mo ago The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited fl…
CVE-2026-35342 low 3.3 3.3 FIX debian debian uutils 2mo ago The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementa…
CVE-2026-32885 critical 9.1 9.1 ddev 2mo ago DDEV has ZipSlip path traversal in tar and zip archive extraction
CVE-2018-25272 critical 9.8 9.8 2mo ago ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to …
CVE-2026-41176 critical 9.5 debian debian 2mo ago Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
CVE-2026-41166 unknown 2mo ago OpenRemote has Improper Access Control via updateUserRealmRoles function
CVE-2026-6356 critical 9.6 9.6 augmentt 2mo ago A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitiv…
CVE-2026-31501 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_hdesc_get_psdata() returns a pointer into the CPPI …
CVE-2026-31478 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add supp…
CVE-2026-31463 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Commit aa35dd5cbc06 ("iomap: fix invalid folio access…
CVE-2026-31448 critical 9.4 9.4 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if in…
CVE-2026-31444 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequen…
CVE-2026-31436 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal c…
CVE-2026-6023 critical 9.8 9.8 progress 2mo ago In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the c…
CVE-2026-22746 low 2.5 2mo ago Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVE-2026-6408 low 2.7 2.7 tanium 2mo ago Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-6392 low 2.7 2.7 tanium 2mo ago Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2026-41144 critical 9.8 9.8 nasa 2mo ago F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize …
CVE-2026-40575 critical 9.1 9.1 oauth2_proxy_project 2mo ago OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-5845 critical 9.6 9.6 github 2mo ago An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the int…
CVE-2026-3307 low 2.7 2.7 github 2mo ago An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated b…
CVE-2026-40942 unknown 2mo ago Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
CVE-2026-40939 unknown 2mo ago Data Sharing Framework is Missing Session Timeout for OIDC Sessions
CVE-2026-6745 low 3.5 3.5 2mo ago Bagisto affected by Cross-site Scripting
CVE-2026-40910 critical 9.1 9.1 fatedier 2mo ago frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access control
CVE-2026-33519 critical 9.8 9.8 linux-kernel esrikubernetes 2mo ago An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentia…
CVE-2026-41066 unknown FIX slesdebian debian 2mo ago lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-40903 critical 9.1 9.1 goshs 2mo ago goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the…
CVE-2026-40372 critical 9.1 9.1 microsoft 2mo ago Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-39386 unknown 2mo ago Neko has a Self-service Privilege Escalation for Authenticated Users in github.com/m1k1o/neko/server
CVE-2026-6743 low 3.5 3.5 2mo ago A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated rem…
CVE-2026-5652 critical 9.0 9.0 craftycontrol 2mo ago An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permiss…
CVE-2026-40279 low 3.7 3.7 bacnetstack 2mo ago BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacnet/bacint.c reconstructs a 32-bit signed integer from four APDU bytes …
CVE-2026-32613 unknown 2mo ago Spinnaker: RCE via expression parsing due to unrestricted context handling
CVE-2026-32604 unknown 2mo ago Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVE-2026-6783 unknown FIX debian debian 2mo ago Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6782 unknown FIX debian debian 2mo ago Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6781 unknown FIX debian debian 2mo ago Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6778 unknown FIX debian debian 2mo ago Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6777 unknown FIX debian debian 2mo ago Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6775 unknown FIX debian debian 2mo ago Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6774 unknown FIX debian debian 2mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6773 unknown FIX debian debian 2mo ago Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6768 unknown FIX debian debian 2mo ago Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6755 unknown FIX debian debian 2mo ago Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-31369 low 3.2 3.2 2mo ago PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability
CVE-2026-5965 critical 9.8 9.8 2mo ago NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-6257 critical 9.1 9.1 2mo ago Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to r…
CVE-2026-32311 critical 9.8 9.8 flowsint 2mo ago Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to ma…
CVE-2026-6651 low 2.4 2.4 2mo ago A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item N…
CVE-2026-33558 unknown 2mo ago Apache Kafka exposes sensitive information in its DEBUG logs
CVE-2026-33557 unknown 2mo ago Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
CVE-2026-5760 critical 9.8 9.8 lmsys 2mo ago SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered usin…
CVE-2026-6648 low 3.5 3.5 2mo ago A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripti…
CVE-2026-6633 low 3.5 3.5 2mo ago A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Exte…
CVE-2026-6624 low 2.4 2.4 2mo ago A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipula…
CVE-2026-6622 low 2.4 2.4 2mo ago A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulati…
CVE-2026-6619 low 3.5 3.5 2mo ago A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePrevie…
CVE-2026-5964 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-5963 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-6644 critical 9.1 9.1 2mo ago A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary co…
CVE-2026-6611 low 3.1 3.1 2mo ago A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulatio…
CVE-2024-7083 low 3.5 3.5 2mo ago The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks…
CVE-2026-6610 low 3.7 3.7 2mo ago A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipula…
CVE-2026-6600 low 3.5 3.5 2mo ago A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of …
CVE-2026-6597 low 2.7 2.7 2mo ago A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flo…
CVE-2026-6593 low 3.5 3.5 2mo ago A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cros…
CVE-2026-6592 low 3.5 3.5 2mo ago A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulatio…
CVE-2026-20133 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
CVE-2026-20128 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential fil…
CVE-2026-20122 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulne…
CVE-2025-48700 unknown 1.5 KEV 2mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to una…
CVE-2025-32975 unknown 1.5 KEV 2mo ago Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
CVE-2025-2749 unknown 1.5 KEV 2mo ago Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
CVE-2024-27199 unknown 1.5 KEV 2mo ago JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2023-27351 unknown 1.5 KEV 2mo ago PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2026-6570 low 2.7 2.7 2mo ago A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argum…
CVE-2026-32690 unknown 2mo ago Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
CVE-2026-30912 unknown 2mo ago Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false