Search

Found 54,181 results in 2435ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44366 medium 6.1 6.1 22d ago Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Vvveb CMS com…
CVE-2021-47968 medium 6.4 6.4 22d ago Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description p…
CVE-2021-47967 medium 6.1 6.1 22d ago PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers …
CVE-2021-47965 critical 9.8 9.8 22d ago WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation.…
CVE-2021-47962 medium 6.4 6.4 22d ago Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers…
CVE-2021-47958 medium 4.3 4.3 22d ago CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG file…
CVE-2026-45619 medium 6.5 6.5 wwbn 22d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS …
CVE-2026-45610 medium 6.5 6.5 wwbn 22d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA val…
CVE-2026-45580 medium 5.4 5.4 wwbn 22d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream …
CVE-2026-23695 medium 5.4 5.4 22d ago Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option
CVE-2026-8695 critical 9.8 9.8 FIX debian debian radare 22d ago radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed b…
CVE-2026-46383 medium 5.5 5.5 22d ago Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
CVE-2026-44774 critical 9.9 9.9 traefik 22d ago Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
CVE-2026-44717 critical 9.8 9.8 22d ago MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitiz…
CVE-2026-44310 medium 5.4 5.4 debian debian 22d ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereference…
CVE-2026-44309 medium 5.3 5.3 debian debian 22d ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's …
CVE-2026-41258 critical 9.1 9.1 22d ago OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange
CVE-2026-41181 medium 5.8 5.8 traefik 22d ago Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2026-45106 medium 5.5 22d ago Weblate: Stored HTML injection in editor search preview
CVE-2025-65954 medium 6.1 6.1 simplesamlphp 22d ago SimpleSAMLphp casserver: Open Redirect in logout
CVE-2026-45773 medium 6.5 6.5 vercel 22d ago Trubo: Login callback CSRF/session fixation
CVE-2026-45772 critical 9.8 9.8 vercel 22d ago Turbo: Unexpected local code execution during Yarn Berry detection
CVE-2026-8669 medium 6.5 6.5 FIX debian debian 22d ago Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized…
CVE-2026-39053 medium 6.5 6.5 22d ago Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils…
CVE-2026-39052 medium 6.5 6.5 22d ago Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled sc…
CVE-2025-67437 medium 6.5 6.5 22d ago Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.
CVE-2026-41553 critical 10.0 10.0 dhtmlx 22d ago PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicio…
CVE-2026-8503 medium 6.5 6.5 FIX debian debian guimard 22d ago Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator re…
CVE-2026-8454 medium 5.3 5.3 tonyc 22d ago Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer G…
CVE-2026-41971 medium 5.5 5.5 22d ago Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-41970 medium 6.8 6.8 22d ago Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41969 medium 6.2 6.2 22d ago Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-41968 medium 5.9 5.9 22d ago Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41967 medium 5.9 5.9 22d ago Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41966 medium 5.6 5.6 22d ago Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2026-41965 medium 5.6 5.6 22d ago Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41961 medium 5.9 5.9 22d ago Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41960 medium 5.8 5.8 22d ago Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-8425 medium 4.3 4.3 22d ago The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettin…
CVE-2026-7563 medium 4.3 4.3 22d ago The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to t…
CVE-2026-7046 medium 4.9 4.9 22d ago The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to …
CVE-2026-6415 medium 6.4 6.4 22d ago The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due to insufficient input validation of JSON …
CVE-2026-5229 critical 9.8 9.8 22d ago The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which W…
CVE-2026-4683 medium 6.5 6.5 22d ago The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and …
CVE-2026-8398 critical 9.8 10.0 KEV disc-soft 22d ago Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2026-6646 medium 6.4 6.4 22d ago The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitiz…
CVE-2026-24662 medium 5.4 5.4 22d ago Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script …
CVE-2026-8612 medium 5.3 5.3 sles oalders 23d ago WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache…
CVE-2026-6811 medium 5.9 5.9 debian debian 23d ago Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is…
CVE-2026-45248 medium 5.3 5.3 hedera 23d ago Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user inform…
CVE-2026-44428 medium 4.7 4.7 lfprojects 23d ago MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
CVE-2026-44427 medium 5.5 23d ago MCP Registry has open redirect via protocol-relative path in trailing-slash middleware
CVE-2026-44662 medium 5.5 FIX debian debianwindows windows 23d ago rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorr…
CVE-2026-44430 medium 4.0 4.0 lfprojects 23d ago MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
CVE-2026-44429 medium 5.4 5.4 lfprojects 23d ago MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
CVE-2026-45366 medium 4.7 4.7 23d ago typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency bet…
CVE-2026-45288 critical 9.8 9.8 23d ago Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generate…
CVE-2026-45787 critical 9.1 9.1 electerm_project 23d ago electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
CVE-2026-45374 critical 9.6 9.6 23d ago CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:14…
CVE-2026-45311 critical 9.6 9.6 23d ago CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user…
CVE-2026-42573 medium 5.5 23d ago Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
CVE-2026-42567 medium 5.5 23d ago Svelte: ReDoS in `<svelte:element>` Tag Validation
CVE-2026-45397 medium 5.3 5.3 openwebui 23d ago Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
CVE-2026-45386 medium 4.3 4.3 openwebui 23d ago Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
CVE-2026-45339 medium 6.5 6.5 openwebui 23d ago Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
CVE-2026-42599 medium 5.5 23d ago Svelte SSR vulnerable to cross-site scripting via spread attributes
CVE-2026-45314 medium 6.1 6.1 openwebui 23d ago Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
CVE-2026-45306 medium 6.5 6.5 23d ago pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect…
CVE-2026-8634 critical 9.1 9.1 23d ago Crabbox: environment variable exposure vulnerability
CVE-2026-8586 medium 5.5 5.5 FIX debian debianwindows windows google 23d ago Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: …
CVE-2026-8584 medium 4.2 4.2 FIX debian debianmacos macoswindows windows google 23d ago Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page…
CVE-2026-8583 medium 5.3 5.3 FIX debian debianwindows windows google 23d ago Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informa…
CVE-2026-8582 medium 5.3 5.3 FIX debian debianwindows windows google 23d ago Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium se…
CVE-2026-8580 critical 9.6 9.6 FIX debian debianwindows windows google 23d ago Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-8576 medium 4.3 4.3 FIX debian debian linux-kernelwindows windows google 23d ago Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sev…
CVE-2026-8570 medium 6.5 6.5 FIX debian debianwindows windows google 23d ago Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security sev…
CVE-2026-8567 medium 4.3 4.3 FIX debian debianwindows windows google 23d ago Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: …
CVE-2026-8566 medium 4.3 4.3 FIX debian debianwindows windows google 23d ago Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium sec…
CVE-2026-8565 medium 4.7 4.7 FIX debian debianmacos macoswindows windows google 23d ago Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafte…
CVE-2026-8564 medium 4.2 4.2 FIX debian debianmacos macoswindows windows google 23d ago Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: M…
CVE-2026-8563 medium 4.3 4.3 FIX debian debianwindows windows google 23d ago Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium se…
CVE-2026-8562 medium 4.3 4.3 FIX debian debianmacos macos linux-kernel google 23d ago Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Mediu…
CVE-2026-8561 medium 5.4 5.4 FIX debian debianmacos macos linux-kernel google 23d ago Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-8560 medium 4.3 4.3 FIX debian debianmacos macoswindows windows google 23d ago Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium securi…
CVE-2026-8559 medium 4.3 4.3 FIX debian debianwindows windows google 23d ago Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium secu…
CVE-2026-8552 medium 4.3 4.3 FIX debian debianwindows windows google 23d ago Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity…
CVE-2026-8550 medium 6.5 6.5 FIX debian debianmacos macos linux-kernel google 23d ago Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memo…
CVE-2026-8546 medium 5.3 5.3 FIX debian debianmacos macoswindows windows google 23d ago Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information fr…
CVE-2026-8543 medium 5.3 5.3 FIX debian debianmacos macoswindows windows google 23d ago Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive infor…
CVE-2026-8541 medium 5.3 5.3 FIX debian debianmacos macos linux-kernel google 23d ago Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory vi…
CVE-2026-8539 medium 5.4 5.4 FIX debian debianwindows windows google 23d ago Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security s…
CVE-2026-8538 medium 5.3 5.3 FIX debian debianwindows windows google 23d ago Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a denial of service via a craf…
CVE-2026-8537 medium 4.3 4.3 FIX debian debianwindows windows google 23d ago Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: H…
CVE-2026-8535 medium 5.3 5.3 FIX debian debian linux-kernelwindows windows google 23d ago Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informati…
CVE-2026-8528 medium 4.3 4.3 FIX debian debianmacos macos linux-kernel google 23d ago Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a …
CVE-2026-8516 medium 5.3 5.3 FIX debian debianmacos macos linux-kernel google 23d ago Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentia…
CVE-2026-8511 critical 9.6 9.6 FIX debian debianmacos macos linux-kernel google 23d ago Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-43996 medium 5.5 5.5 debian debian openimageio 23d ago OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, the bounds check in TGAInput::decode_…
CVE-2026-26191 critical 9.8 9.8 fleetdm 23d ago Fleet vulnerable to OS command injection in software packages
CVE-2026-26062 medium 6.5 6.5 fleetdm 23d ago Fleet server may terminate unexpectedly when handling certain gRPC requests