Search

Found 33,933 results in 1790ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-28816 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20701 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20699 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20698 unknown tvos iosmacos macos 3mo ago visionOS 26.4
CVE-2026-20697 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20695 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20694 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20693 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20692 unknown macos macos ios 3mo ago macOS Sonoma 14.8.5
CVE-2026-20688 unknown macos macos ios apple 3mo ago visionOS 26.4
CVE-2026-20660 unknown macos macos 3mo ago macOS Sequoia 15.7.5
CVE-2026-20651 unknown macos macos 3mo ago macOS Sequoia 15.7.5
CVE-2026-20639 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20633 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20632 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-20631 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-20607 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2025-59775 unknown FIX debian debianmacos macos 3mo ago Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server …
CVE-2026-33430 unknown 3mo ago Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions
CVE-2026-31851 critical 9.8 9.8 3mo ago Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authent…
CVE-2026-31848 critical 9.8 9.8 3mo ago Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the e…
CVE-2026-4633 unknown 3mo ago Keycloak's identity-first login flow exposes user information
CVE-2026-4581 critical 9.8 9.8 code-projects 3mo ago A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the ar…
CVE-2026-4628 unknown 3mo ago Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
CVE-2026-4580 critical 9.8 9.8 code-projects 3mo ago A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulati…
CVE-2026-4579 critical 9.8 9.8 code-projects 3mo ago A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the ar…
CVE-2026-4601 critical 9.1 9.1 jsrsasign_project 3mo ago jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction
CVE-2026-4600 critical 9.1 9.1 jsrsasign_project 3mo ago jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic
CVE-2026-29796 critical 9.8 9.8 igl 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-25192 critical 9.8 9.8 ctek 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-33497 unknown 3mo ago langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2026-33413 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call …
CVE-2026-33484 unknown 3mo ago langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33343 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use n…
CVE-2026-4499 critical 9.8 9.8 3mo ago A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can lead to os command injection. The attack may be laun…
CVE-2026-4497 critical 9.8 9.8 3mo ago A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command in…
CVE-2026-4473 critical 9.8 9.8 unguardable 3mo ago A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argume…
CVE-2026-4472 critical 9.8 9.8 adonesevangelista 3mo ago A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulatio…
CVE-2026-4471 critical 9.8 9.8 adonesevangelista 3mo ago A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argume…
CVE-2026-4470 critical 9.8 9.8 adonesevangelista 3mo ago A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_edit_menu.php. Performing a …
CVE-2026-4469 critical 9.8 9.8 adonesevangelista 3mo ago A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such …
CVE-2026-33017 critical 9.8 10.0 KEV langflow 3mo ago Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
CVE-2026-22737 unknown debian debian 3mo ago Spring Framework Improper Path Limitation with Script View Templates
CVE-2026-22735 unknown debian debian 3mo ago Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-22733 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
CVE-2026-22732 unknown 3mo ago Spring Security HTTP Headers Are not Written Under Some Conditions
CVE-2026-22731 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator Health groups paths
CVE-2025-43520 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel …
CVE-2025-43510 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CVE-2026-3548 critical 9.8 9.8 FIX debian debian wolfssl 3mo ago Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string…
CVE-2026-33322 unknown sles 3mo ago MinIO has JWT Algorithm Confusion in OIDC Authentication in github.com/minio/minio
CVE-2026-33309 unknown 3mo ago Langflow has an Arbitrary File Write (RCE) via v2 API
CVE-2026-27953 unknown FIX debian debian 3mo ago ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validat…
CVE-2026-2369 critical 9.1 9.1 FIX debian debian sles gnome 3mo ago A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially acc…
CVE-2026-22557 critical 10.0 10.0 3mo ago A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to …
CVE-2025-60237 critical 9.8 9.8 3mo ago Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.
CVE-2025-60233 critical 9.8 9.8 3mo ago Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.
CVE-2026-27542 critical 9.8 9.8 3mo ago Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce…
CVE-2026-27540 critical 9.0 9.0 3mo ago Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue a…
CVE-2026-27413 critical 9.3 9.3 3mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro:…
CVE-2026-33056 unknown FIX debian debian 3mo ago tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path t…
CVE-2026-20131 unknown 1.5 KEV 3mo ago Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management…
CVE-2026-32735 unknown 3mo ago openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project…
CVE-2026-33166 unknown 3mo ago Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)
CVE-2026-33004 unknown 3mo ago Jenkins LoadNinja Plugin does not mask LoadNinja API keys displayed on the job configuration form
CVE-2026-33003 unknown 3mo ago Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in job config.xml files
CVE-2026-33002 unknown 3mo ago Jenkins has a DNS rebinding vulnerability in WebSocket CLI origin validation
CVE-2026-33001 unknown 3mo ago Jenkins has a link following vulnerability allows arbitrary file creation
CVE-2026-33053 unknown 3mo ago Langflow is Missing Ownership Verification in API Key Deletion (IDOR)
CVE-2026-22730 unknown 3mo ago SQL Injection in Spring AI MariaDBFilterExpressionConverter
CVE-2026-22729 unknown 3mo ago JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
CVE-2026-2092 unknown 3mo ago Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
CVE-2026-20963 unknown 1.5 KEV 3mo ago Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2025-66376 unknown 1.5 KEV 3mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
CVE-2026-33012 unknown 3mo ago Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
CVE-2026-4319 critical 9.8 9.8 carmelo 3mo ago A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/add-item.php. Such manipulation of the ar…
CVE-2026-32636 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due t…
CVE-2026-33013 unknown 3mo ago Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
CVE-2026-30911 unknown 3mo ago Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
CVE-2026-28779 unknown 3mo ago Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
CVE-2026-28563 unknown 3mo ago Apache Airflow: DAG authorization bypass
CVE-2026-26929 unknown 3mo ago Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
CVE-2026-4312 critical 9.8 9.8 dragonsoft 3mo ago GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative acco…
CVE-2026-30405 unknown FIX debian debian 3mo ago An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
CVE-2026-32722 unknown FIX debian debian 3mo ago Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no esc…
CVE-2026-27459 unknown FIX slesdebian debian 3mo ago pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value…
CVE-2025-62319 critical 9.8 9.8 hcltech 3mo ago Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of return…
CVE-2026-28498 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation…
CVE-2025-54920 unknown 3mo ago Apache Spark: Spark History Server Code Execution Vulnerability
CVE-2026-28490 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning…
CVE-2026-27962 unknown FIX slesdebian debian 3mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attac…
CVE-2026-27448 unknown FIX slesdebian debian 3mo ago pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled e…
CVE-2026-25534 unknown 3mo ago Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames
CVE-2026-4228 critical 9.8 9.8 3mo ago A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection. It is possible to launch the…
CVE-2026-4223 critical 9.8 9.8 angeljudesuarez 3mo ago A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee.php. Such manipulation of the argument ID leads t…
CVE-2026-4210 critical 9.8 9.8 3mo ago A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, D…
CVE-2026-4209 critical 9.8 9.8 3mo ago A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-72…
CVE-2026-4207 critical 9.8 9.8 3mo ago A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-72…
CVE-2026-4206 critical 9.8 9.8 3mo ago A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, …
CVE-2026-4205 critical 9.8 9.8 3mo ago A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-72…