Search

Found 33,068 results in 1420ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-43476 high 7.8 7.8 FIX slesdebian debian 24d ago In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) in…
CVE-2026-42930 high 8.7 8.7 24d ago When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have …
CVE-2026-42924 high 8.7 8.7 24d ago An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions…
CVE-2026-42920 high 7.5 7.5 24d ago When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software …
CVE-2026-42409 high 7.5 7.5 24d ago When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) …
CVE-2026-42406 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running ar…
CVE-2026-42290 high 7.8 7.8 protobufjs_project 24d ago protobuf.js is Vulnerable to OS Command Injection in the CLI
CVE-2026-41957 high 8.8 8.8 24d ago An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Software versions which have reached End of Technical S…
CVE-2026-41956 high 7.5 7.5 24d ago When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached …
CVE-2026-41953 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escala…
CVE-2026-41227 high 7.5 7.5 24d ago On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to ter…
CVE-2026-41218 high 7.5 7.5 24d ago When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause …
CVE-2026-41217 high 7.9 7.9 24d ago A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system comman…
CVE-2026-40698 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iCont…
CVE-2026-40631 high 8.7 8.7 24d ago An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions whic…
CVE-2026-40629 high 7.5 7.5 24d ago When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Te…
CVE-2026-40618 high 7.5 7.5 24d ago When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacc…
CVE-2026-40423 high 7.5 7.5 24d ago When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technica…
CVE-2026-40067 high 7.5 7.5 24d ago When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (…
CVE-2026-40061 high 8.7 8.7 24d ago When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or…
CVE-2026-40060 high 7.5 7.5 24d ago When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End o…
CVE-2026-39459 high 7.2 7.2 24d ago A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running …
CVE-2026-39458 high 7.5 7.5 24d ago When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which…
CVE-2026-39455 high 7.5 7.5 24d ago When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file d…
CVE-2026-36741 high 7.2 7.2 24d ago U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. A…
CVE-2026-34176 high 8.7 8.7 24d ago When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a securit…
CVE-2026-32673 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher priv…
CVE-2026-32643 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running ar…
CVE-2026-20916 high 8.1 8.1 24d ago An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.  Note: Software versions which have re…
CVE-2025-28344 high 7.5 7.5 24d ago striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343 high 7.5 7.5 24d ago striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2024-55045 high 7.3 7.3 24d ago Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.
CVE-2020-37226 high 7.1 7.1 24d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37224 high 7.1 7.1 24d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37223 high 7.8 7.8 24d ago IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou…
CVE-2020-37222 high 7.2 7.2 24d ago Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi…
CVE-2020-37221 high 8.4 8.4 24d ago Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Cloc…
CVE-2020-37220 high 7.5 7.5 24d ago Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer…
CVE-2020-37219 high 7.5 7.5 24d ago Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques…
CVE-2020-37218 high 8.2 8.2 24d ago Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the …
CVE-2026-45152 high 7.8 7.8 24d ago uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files u…
CVE-2026-45136 high 7.8 7.8 cnighswonger 24d ago claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directl…
CVE-2026-44798 high 7.1 7.1 networktocode 24d ago Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the cu…
CVE-2026-44797 high 8.5 8.5 networktocode 24d ago Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient…
CVE-2026-44738 high 7.7 7.7 getgrav 24d ago Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()
CVE-2026-45134 high 7.1 7.1 24d ago LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_promp…
CVE-2026-44724 high 7.8 7.8 FIX debian debian 24d ago systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active Netwo…
CVE-2026-4609 high 7.1 7.1 24d ago The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up t…
CVE-2026-37430 high 7.3 7.3 24d ago An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2026-39806 high 7.5 7.5 mtrudel 24d ago Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder
CVE-2026-39803 high 7.5 7.5 mtrudel 24d ago Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`
CVE-2026-6177 high 7.2 7.2 24d ago The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elemen…
CVE-2026-3425 high 8.8 8.8 24d ago The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This …
CVE-2026-35506 high 7.2 7.2 24d ago ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary …
CVE-2026-6276 high 7.5 7.5 FIX debian debian sleswindows windows haxxgoogle 24d ago Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the seco…
CVE-2026-5773 high 7.5 7.5 FIX debian debian sleswindows windows haxxgoogle 24d ago libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avo…
CVE-2026-4798 high 7.5 7.5 24d ago The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the use…
CVE-2024-47091 high 7.8 7.8 checkmk 24d ago Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MyS…
CVE-2026-25705 high 8.4 8.4 24d ago Rancher Extensions have arbitrary file access via path traversal
CVE-2026-45793 high 8.0 FIX debian debian 24d ago Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
CVE-2026-6929 high 7.5 7.5 24d ago The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including,…
CVE-2026-44612 high 7.8 7.8 24d ago Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer,…
CVE-2026-21020 high 7.8 7.8 24d ago Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2025-11159 high 7.2 7.2 hitachi 24d ago Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data…
CVE-2026-7635 high 8.1 8.1 24d ago The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or…
CVE-2026-8201 high 8.8 8.8 mongodb 24d ago A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability req…
CVE-2026-8053 high 8.8 8.8 mongodb 24d ago An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issu…
CVE-2026-6888 high 7.2 7.2 24d ago Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to acc…
CVE-2026-44697 high 8.6 8.6 25d ago Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any p…
CVE-2026-43660 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-43658 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-40164 high 7.5 7.5 FIX rheldebian debian sles 25d ago Important: jq security update
CVE-2026-39979 high 8.0 FIX rheldebian debian sles 25d ago Important: jq security update
CVE-2026-28962 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28955 high 8.8 8.8 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28953 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28947 high 8.8 8.8 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28944 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28913 high 7.5 7.5 FIX safari iosmacos macos 25d ago watchOS 26.5
CVE-2026-28907 high 8.1 8.1 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28905 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28904 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28883 high 7.5 7.5 FIX ios safarimacos macos 25d ago visionOS 26.5
CVE-2026-28847 high 8.8 8.8 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-8108 high 7.8 7.8 25d ago The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
CVE-2026-5371 high 7.1 7.1 25d ago The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability…
CVE-2026-44548 high 8.1 8.1 25d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDele…
CVE-2026-43685 high 7.2 7.2 claris 25d ago A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External OD…
CVE-2026-43680 high 7.2 7.2 claris 25d ago A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operat…
CVE-2026-42289 high 8.8 8.8 25d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token valid…
CVE-2026-1250 high 7.5 7.5 25d ago The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insuf…
CVE-2026-44660 high 7.5 7.5 debian debian ultrajson_project 25d ago UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an excepti…
CVE-2026-44648 high 7.5 7.5 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44594 high 7.5 7.5 25d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in…
CVE-2026-45227 high 8.8 8.8 25d ago Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspec…
CVE-2026-45226 high 7.1 7.1 25d ago Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without pro…
CVE-2026-45225 high 7.6 7.6 25d ago Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted…
CVE-2026-44871 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
CVE-2026-44302 high 7.5 7.5 25d ago Snappier has an infinite loop during SnappyStream decompression with malformed framed input
CVE-2026-44301 high 8.1 8.1 FIX debian debian gohugo 25d ago Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools with…