Search

Found 54,181 results in 2460ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-33637 medium 6.5 6.5 FIX debian debian faraday_project 20d ago Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
CVE-2026-8769 medium 6.5 6.5 vercel 20d ago @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
CVE-2026-8766 medium 6.5 6.5 kilo 20d ago @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-8765 medium 6.5 6.5 kilo 20d ago A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component Fi…
CVE-2026-8721 critical 9.8 9.8 FIX debian debian 20d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to Sv…
CVE-2026-8507 critical 9.8 9.8 FIX debian debian 20d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info(…
CVE-2026-8757 critical 9.1 9.1 adenhq 20d ago A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Perfor…
CVE-2026-8754 medium 6.3 6.3 20d ago AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
CVE-2026-8753 medium 6.3 6.3 20d ago A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.ph…
CVE-2018-25337 medium 4.3 4.3 20d ago Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo…
CVE-2018-25336 medium 5.3 5.3 20d ago jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML form…
CVE-2018-25335 critical 9.8 9.8 20d ago WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint.…
CVE-2018-25334 medium 5.4 5.4 20d ago Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but…
CVE-2018-25332 critical 9.8 9.8 gitbucket 20d ago GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
CVE-2018-25331 medium 6.1 6.1 20d ago Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attac…
CVE-2018-25327 medium 5.3 5.3 20d ago Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTM…
CVE-2018-25324 medium 6.2 6.2 20d ago Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspat…
CVE-2018-25321 medium 4.3 4.3 20d ago TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker…
CVE-2018-25320 critical 9.8 9.8 20d ago ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
CVE-2026-8752 medium 5.3 5.3 h2o 20d ago A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the compon…
CVE-2026-8751 critical 9.8 9.8 h2o 20d ago A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a…
CVE-2026-8747 medium 6.3 6.3 20d ago A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipu…
CVE-2026-8746 medium 6.5 6.5 open5gs 20d ago A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation res…
CVE-2026-8745 medium 6.5 6.5 open5gs 20d ago A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation le…
CVE-2026-8744 medium 6.5 6.5 open5gs 20d ago A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing …
CVE-2026-8743 medium 6.3 6.3 open5gs 20d ago A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in …
CVE-2026-8740 medium 6.3 6.3 20d ago A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirectiv…
CVE-2026-8739 medium 5.3 5.3 20d ago A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigC…
CVE-2026-8738 medium 6.5 6.5 20d ago A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file public…
CVE-2026-8737 medium 5.3 5.3 20d ago A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListD…
CVE-2026-8736 medium 4.1 4.1 20d ago A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Perfor…
CVE-2026-8735 medium 6.3 6.3 20d ago A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulat…
CVE-2026-8733 medium 6.3 6.3 20d ago A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based …
CVE-2026-8731 medium 6.5 6.5 open5gs 20d ago A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool …
CVE-2026-8730 medium 6.5 6.5 open5gs 20d ago A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manipulation of the argument nfI…
CVE-2026-8729 medium 6.5 6.5 open5gs 20d ago A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/s…
CVE-2026-8728 medium 6.5 6.5 open5gs 20d ago A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. S…
CVE-2026-8723 medium 5.3 5.3 debian debianwindows windows 21d ago ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not ha…
CVE-2021-47981 medium 5.4 5.4 21d ago Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription par…
CVE-2021-47978 medium 6.2 6.2 21d ago ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send req…
CVE-2021-47957 medium 6.4 6.4 21d ago Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Att…
CVE-2021-47955 medium 5.4 5.4 21d ago CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality…
CVE-2021-47952 critical 9.8 9.8 sles 21d ago python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. …
CVE-2021-47934 medium 5.3 5.3 21d ago MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and …
CVE-2020-37246 medium 6.2 6.2 21d ago Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers ca…
CVE-2020-37241 medium 5.3 5.3 21d ago bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can…
CVE-2020-37240 medium 6.4 6.4 21d ago Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can ins…
CVE-2020-37239 critical 9.8 9.8 21d ago libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_…
CVE-2020-37238 medium 6.4 6.4 21d ago CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers…
CVE-2020-37237 medium 6.4 6.4 21d ago Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi…
CVE-2020-37236 medium 6.4 6.4 21d ago NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio…
CVE-2020-37235 medium 6.4 6.4 21d ago WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parame…
CVE-2020-37234 medium 6.2 6.2 21d ago Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …
CVE-2020-37233 medium 6.4 6.4 21d ago WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi…
CVE-2020-37228 critical 9.8 9.8 21d ago iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retr…
CVE-2026-46719 medium 6.5 6.5 21d ago Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject add…
CVE-2025-4202 medium 4.3 4.3 21d ago The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf_add_comment' fu…
CVE-2026-8656 medium 6.1 6.1 21d ago Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an appli…
CVE-2026-8681 medium 5.3 5.3 21d ago The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is auth…
CVE-2026-46703 critical 9.5 22d ago Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
CVE-2026-46695 critical 9.5 22d ago BoxLite: Permission Bypass Allows Modification of Read-Only Files
CVE-2026-8704 medium 6.5 6.5 FIX debian debian 22d ago Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
CVE-2026-45667 medium 6.5 6.5 openwebui 22d ago Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
CVE-2026-45666 medium 6.5 6.5 openwebui 22d ago Open WebUI has an Indirect Object Reference (IDOR) in user notes
CVE-2026-45365 medium 5.4 5.4 openwebui 22d ago Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
CVE-2026-45351 medium 6.5 6.5 openwebui 22d ago Open WebUI Exposes System Prompt to Regular User [Non-Admin]
CVE-2026-45347 medium 5.4 5.4 openwebui 22d ago Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
CVE-2026-45346 medium 5.4 5.4 openwebui 22d ago Open WebUI Has Stored Cross-Site Scripting in SVG Renderer
CVE-2026-45345 medium 6.5 6.5 openwebui 22d ago Open WebUI missing authorization check at the model update function - models from other users can be updated
CVE-2026-45318 medium 5.4 5.4 openwebui 22d ago Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
CVE-2026-45317 medium 4.6 4.6 openwebui 22d ago Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVE-2026-44571 medium 6.5 6.5 openwebui 22d ago Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVE-2026-44566 critical 9.8 9.8 openwebui 22d ago Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
CVE-2026-46365 medium 5.4 5.4 22d ago phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, incl…
CVE-2026-46363 medium 5.4 5.4 22d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authent…
CVE-2026-46360 medium 5.4 5.4 22d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass san…
CVE-2026-45009 medium 4.3 4.3 22d ago phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login statu…
CVE-2026-45008 medium 6.5 6.5 22d ago phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit tr…
CVE-2026-8696 critical 9.8 9.8 FIX debian debian radare 22d ago radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbi…
CVE-2026-45396 medium 5.4 5.4 openwebui 22d ago Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
CVE-2026-45387 medium 4.3 4.3 openwebui 22d ago Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
CVE-2026-45385 medium 4.3 4.3 openwebui 22d ago Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
CVE-2026-44568 medium 4.8 4.8 openwebui 22d ago Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
CVE-2026-44564 medium 5.4 5.4 openwebui 22d ago Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
CVE-2026-44563 medium 5.4 5.4 openwebui 22d ago Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVE-2026-44562 medium 6.5 6.5 openwebui 22d ago Open WebUI's Model Import Overwrites Any Model Without Ownership Check
CVE-2026-44561 medium 5.4 5.4 openwebui 22d ago Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVE-2026-44560 medium 6.5 6.5 openwebui 22d ago Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVE-2026-44559 medium 4.3 4.3 openwebui 22d ago Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
CVE-2026-44558 medium 5.4 5.4 openwebui 22d ago Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
CVE-2026-44550 medium 5.0 5.0 openwebui 22d ago Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVE-2025-67031 medium 6.3 6.3 22d ago ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsystem. Certain field con…
CVE-2026-8686 critical 9.1 9.1 freertosaws 22d ago Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users s…
CVE-2026-4054 medium 6.5 6.5 mattermost 22d ago Mattermost doesn't validate the response body of proxied images
CVE-2026-4053 medium 4.3 4.3 mattermost 22d ago Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
CVE-2026-46364 critical 9.8 9.8 22d ago phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent h…
CVE-2026-46362 medium 6.5 6.5 22d ago phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Att…
CVE-2026-46361 medium 6.9 6.9 22d ago phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protect…
CVE-2026-45010 critical 9.1 9.1 22d ago phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts arbitrary user-id parameters without session bind…
CVE-2026-45007 medium 4.3 4.3 22d ago phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authentic…