Search

Found 45,574 results in 2161ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44874 medium 4.9 4.9 25d ago A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Succe…
CVE-2026-44873 medium 5.4 5.4 arubanetworks 25d ago A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated wh…
CVE-2026-44223 medium 6.5 6.5 vllm 25d ago vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect sh…
CVE-2026-44220 low 3.2 3.2 25d ago ciguard: discover_pipeline_files follows symlinks out of scan root
CVE-2026-44219 low 3.7 3.7 25d ago ciguard: SCA HTTP client reads response body without size cap
CVE-2026-44218 low 3.0 3.0 25d ago ciguard: Container image runs as root (no USER directive)
CVE-2026-44217 medium 5.5 25d ago sse-channel: SSE Injection via unsanitized event fields
CVE-2026-42445 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPat…
CVE-2026-42444 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method re…
CVE-2026-42443 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when …
CVE-2026-42442 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when…
CVE-2026-42355 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .…
CVE-2026-42338 medium 6.1 6.1 debian debian beaugunderson 25d ago ip-address has XSS in Address6 HTML-emitting methods
CVE-2026-34688 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34685 low 3.4 3.4 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier [NEEDS REVIEW: impact mismatch — ticket says 'Arbitrary file system write', CIA triad derives 'Sec…
CVE-2026-34680 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…
CVE-2026-34679 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34678 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34677 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34673 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34672 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…
CVE-2026-34671 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…
CVE-2026-34670 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34669 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34668 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34667 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…
CVE-2026-34666 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34658 medium 4.8 4.8 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…
CVE-2026-34656 medium 4.3 4.3 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature by…
CVE-2026-34655 medium 4.8 4.8 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…
CVE-2026-34654 medium 5.3 5.3 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result i…
CVE-2026-34664 medium 6.3 6.3 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file sy…
CVE-2026-23822 medium 5.3 5.3 25d ago A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…
CVE-2026-5146 medium 4.3 4.3 devolutions 25d ago Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session v…
CVE-2026-44279 medium 5.5 5.5 fortinet 25d ago A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow atta…
CVE-2026-44278 medium 5.5 5.5 fortinet 25d ago A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert at…
CVE-2026-44204 medium 6.5 6.5 25d ago Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role)…
CVE-2026-42891 medium 6.5 6.5 windows windows microsoft 25d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42838 medium 5.4 5.4 windows windows microsoft 25d ago Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a netw…
CVE-2026-42830 medium 6.5 6.5 windows windows microsoft 25d ago Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42541 medium 4.3 4.3 25d ago Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
CVE-2026-42303 medium 5.5 25d ago Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-42177 medium 5.3 5.3 FIX debian debian 25d ago linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter i…
CVE-2026-42175 medium 6.5 6.5 25d ago requests-hardened is Vulnerable to Server-Side Request Forgery
CVE-2026-42045 medium 6.2 6.2 25d ago LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
CVE-2026-41614 medium 6.2 6.2 windows windows microsoft 25d ago Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41612 medium 5.5 5.5 windows windows microsoft 25d ago Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
CVE-2026-41610 medium 6.3 6.3 windows windows microsoft 25d ago Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-41100 medium 4.4 4.4 windows windows microsoft 25d ago Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-41097 medium 6.7 6.7 FIX windows windows 25d ago Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-40421 medium 4.3 4.3 windows windows microsoft 25d ago Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40416 medium 4.3 4.3 windows windows microsoft 25d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-40380 medium 6.2 6.2 FIX windows windows 25d ago Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
CVE-2026-40374 medium 6.5 6.5 windows windows microsoft 25d ago Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2026-35440 medium 5.5 5.5 windows windows microsoft 25d ago Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-35429 medium 4.3 4.3 windows windows microsoft 25d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35423 medium 5.4 5.4 FIX windows windows 25d ago Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-35422 medium 6.5 6.5 FIX windows windows 25d ago Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
CVE-2026-35419 medium 5.5 5.5 FIX windows windows 25d ago Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-34663 medium 5.5 5.5 macos macos adobe 25d ago Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to d…
CVE-2026-34662 medium 5.5 5.5 macos macos adobe 25d ago Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerabil…
CVE-2026-34350 medium 6.5 6.5 FIX windows windows 25d ago Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-34339 medium 5.5 5.5 FIX windows windows 25d ago Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
CVE-2026-32209 medium 4.4 4.4 FIX windows windows 25d ago Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
CVE-2026-32185 medium 5.5 5.5 windows windows microsoft 25d ago Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-32175 medium 4.3 4.3 windows windows 25d ago A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to ce…
CVE-2026-32170 medium 6.7 6.7 FIX windows windows 25d ago Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-31245 medium 5.3 5.3 mem0 25d ago mem0 server lacks authentication and authorization controls for its memory creation API endpoint
CVE-2026-31244 medium 6.5 6.5 mem0 25d ago The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrar…
CVE-2026-31243 medium 6.5 6.5 mem0 25d ago The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacke…
CVE-2026-31241 medium 6.5 6.5 mem0 25d ago mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
CVE-2026-25690 medium 6.5 6.5 fortinet 25d ago An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2…
CVE-2026-21530 medium 6.7 6.7 FIX windows windows 25d ago Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2025-67604 medium 5.3 5.3 fortinet 25d ago A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions,…
CVE-2025-53870 medium 6.7 6.7 fortinet 25d ago An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versi…
CVE-2025-53680 medium 6.7 6.7 fortinet 25d ago An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5…
CVE-2026-8407 medium 4.3 4.3 devolutions 25d ago Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted re…
CVE-2026-40300 medium 6.5 6.5 zulip 25d ago Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allo…
CVE-2026-25431 medium 5.3 5.3 25d ago Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.
CVE-2026-20914 medium 5.5 5.5 intel 25d ago Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…
CVE-2026-20905 medium 6.6 6.6 intel 25d ago Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…
CVE-2026-20881 medium 5.5 5.5 intel 25d ago Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authentic…
CVE-2026-20793 low 3.3 3.3 intel 25d ago Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an a…
CVE-2026-20782 medium 6.6 6.6 intel 25d ago Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenti…
CVE-2026-20771 medium 6.1 6.1 intel 25d ago Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…
CVE-2026-20717 medium 6.6 6.6 intel 25d ago Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…
CVE-2026-43514 low 3.7 3.7 FIX slesdebian debian apache 25d ago Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M…
CVE-2023-30059 medium 5.4 5.4 25d ago An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.
CVE-2026-42073 medium 6.5 6.5 gitlawb 25d ago OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP serv…
CVE-2026-8368 medium 6.5 6.5 FIX debian debian sleswindows windows 25d ago LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …
CVE-2026-8109 medium 6.5 6.5 ivanti 25d ago An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
CVE-2026-7431 medium 4.4 4.4 ivanti 25d ago An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…
CVE-2026-5061 medium 4.7 4.7 25d ago The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) …
CVE-2025-70842 medium 5.4 5.4 25d ago A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containin…
CVE-2026-43930 medium 5.9 5.9 parseplatform 25d ago parse-server: MFA SMS one-time password accepted twice under concurrent login
CVE-2026-42006 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 25d ago An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left op…
CVE-2026-40638 medium 6.7 6.7 dell 25d ago Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this v…
CVE-2026-40020 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 25d ago Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is lim…
CVE-2026-40016 medium 6.5 6.5 FIX debian debian sles dovecotopen-xchange 25d ago Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to deg…
CVE-2026-33603 medium 5.3 5.3 FIX debian debian sles dovecotopen-xchange 25d ago Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the c…