Search

Found 41,180 results in 4159ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41256 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 27d ago jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter fil…
CVE-2026-41250 medium 5.7 5.7 27d ago Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.
CVE-2026-40612 medium 5.5 5.5 FIX debian debian sleswindows windows jqlang 27d ago jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with…
CVE-2026-38569 medium 5.4 5.4 27d ago HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add.
CVE-2026-34095 medium 6.1 6.1 FIX debian debian mediawiki 27d ago Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects …
CVE-2026-34093 medium 5.3 5.3 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.P…
CVE-2026-33052 medium 5.5 27d ago MantisBT Has Authorization Bypass in Global Profile Creation
CVE-2026-36906 medium 6.1 6.1 27d ago Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function
CVE-2026-31252 medium 5.7 5.7 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load(…
CVE-2026-8292 medium 6.5 6.5 open5gs 27d ago A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argu…
CVE-2026-8291 medium 6.5 6.5 open5gs 27d ago A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the file lib/sbi/nnrf-handler.c of the component NRF. This manipulation causes denial…
CVE-2026-7820 medium 6.5 6.5 sles pgadmin 27d ago pgAdmin 4: Improper restriction of excessive authentication attempts
CVE-2026-7817 medium 6.5 6.5 sles pgadmin 27d ago pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
CVE-2026-6815 medium 5.9 6.9 EXP casbin 27d ago An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perfo…
CVE-2026-44201 medium 5.3 5.3 torchbox 27d ago Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access t…
CVE-2026-44199 medium 6.5 6.5 torchbox 27d ago Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't hav…
CVE-2026-44198 medium 4.3 4.3 torchbox 27d ago Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, …
CVE-2026-44197 medium 6.5 6.5 torchbox 27d ago Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revis…
CVE-2026-31246 medium 6.5 6.5 27d ago GPT-Pilot contains a command injection vulnerability in the Executor.run() method
CVE-2025-65417 medium 6.1 6.1 27d ago docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.
CVE-2025-65416 medium 6.3 6.3 27d ago docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
CVE-2025-65415 medium 5.4 5.4 27d ago docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.
CVE-2025-61310 medium 6.1 6.1 27d ago A reflected cross-site scripted (XSS) vulnerability in the acc-menu_billings.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in…
CVE-2025-61309 medium 6.1 6.1 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_departments.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript…
CVE-2025-61308 medium 6.1 6.1 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_maintenance.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript…
CVE-2025-61307 medium 6.1 6.1 27d ago A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in t…
CVE-2025-61306 medium 6.1 6.1 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascr…
CVE-2025-61305 medium 6.1 6.1 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in…
CVE-2026-8290 medium 6.5 6.5 open5gs 27d ago A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_in_vsmf of the file /src/smf/nsmf-handler.c of the component SMF. The manipulat…
CVE-2026-8289 medium 6.5 6.5 open5gs 27d ago A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_data_in_vsmf of the file /src/smf/nsmf-handler.c of the component SMF. The manipu…
CVE-2026-44337 medium 6.3 6.3 praison 27d ago PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVE-2026-8288 medium 6.5 6.5 open5gs 27d ago A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos_flow_descriptions of the file src/smf/gsm-handler.c of the component SMF. Exec…
CVE-2026-26946 medium 6.7 6.7 dell 27d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in the OS. A high privileged attacker with local acce…
CVE-2025-43992 medium 5.6 5.6 dell 27d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an authentication bypass by assumed-immutable data vulnerability in Geo replication. An unauthentica…
CVE-2024-0391 medium 4.3 4.3 wso2 27d ago The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid use…
CVE-2026-43826 medium 6.5 6.5 apache 27d ago Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL
CVE-2026-41018 medium 6.5 6.5 apache 27d ago Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
CVE-2026-5084 medium 6.5 6.5 27d ago WebDyne::Session versions through 2.075 for Perl generates the session id insecurely. The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function…
CVE-2026-1677 medium 5.3 5.3 27d ago Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to …
CVE-2026-8274 medium 5.3 5.3 27d ago A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of the file cramfsck.c of the component Directory Handler. Such manipulation leads t…
CVE-2026-8270 medium 6.5 6.5 open5gs 27d ago A vulnerability was determined in Open5GS up to 2.7.7. The affected element is the function ogs_nas_parse_qos_rules of the component SMF. Executing a manipulation can lead to denial of service. The a…
CVE-2026-8269 medium 6.5 6.5 open5gs 27d ago A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function smf_nsmf_handle_create_sm_context of the component SMF. Performing a manipulation results in denial of service. Remote explo…
CVE-2026-8268 medium 6.5 6.5 open5gs 28d ago A vulnerability has been found in Open5GS up to 2.7.7. This issue affects the function OpenAPI_list_create of the component SMF. Such manipulation leads to denial of service. The attack may be launch…
CVE-2026-8267 medium 6.5 6.5 open5gs 28d ago A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vsmf of the component SMF. This manipulation causes denial of service. The attack…
CVE-2026-8266 medium 6.5 6.5 open5gs 28d ago A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accept of the file /src/smf/gsm-build.c of the component SMF. The manipulation resul…
CVE-2026-8261 medium 5.9 5.9 debian debian 28d ago A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attac…
CVE-2026-8258 medium 5.3 5.3 debian debian 28d ago A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The at…
CVE-2026-8257 medium 5.5 5.5 debian debian webassembly 28d ago A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a…
CVE-2026-8252 medium 6.5 6.5 open5gs 28d ago A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference…
CVE-2026-43666 medium 6.2 6.2 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-43659 medium 4.7 4.7 FIX iosmacos macos apple 28d ago visionOS 26.5
CVE-2026-43653 medium 6.2 6.2 FIX iosmacos macos tvos 28d ago The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5. An attacker on …
CVE-2026-39869 medium 4.3 4.3 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28996 medium 5.5 5.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28994 medium 5.3 5.3 FIX iosmacos macos tvos 28d ago watchOS 26.5
CVE-2026-28993 medium 5.5 5.5 FIX iosmacos macos apple 28d ago visionOS 26.5
CVE-2026-28992 medium 4.7 4.7 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28988 medium 5.5 5.5 FIX iosmacos macos watchos 28d ago visionOS 26.5
CVE-2026-28985 medium 6.2 6.2 FIX iosmacos macos tvos 28d ago A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to …
CVE-2026-28977 medium 6.2 6.2 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28972 medium 6.5 6.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28963 medium 4.6 4.6 FIX iosmacos macos 28d ago A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensi…
CVE-2026-28961 medium 4.6 4.6 FIX macos macos 28d ago This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.
CVE-2026-28956 medium 6.5 6.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28950 medium 6.2 6.2 FIX iosmacos macos 28d ago iOS 18.7.8 and iPadOS 18.7.8
CVE-2026-28922 medium 6.5 6.5 FIX macos macos 28d ago This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access private information.
CVE-2026-28920 medium 6.5 6.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28918 medium 6.5 6.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28914 medium 5.5 5.5 FIX macos macos 28d ago A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
CVE-2026-28897 medium 6.2 6.2 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28882 medium 4.0 4.0 FIX iosmacos macos apple 28d ago visionOS 26.4
CVE-2026-28878 medium 6.5 6.5 FIX macos macos ios watchos 28d ago visionOS 26.4
CVE-2026-28877 medium 5.5 5.5 FIX iosmacos macos watchos 28d ago visionOS 26.4
CVE-2026-28870 medium 5.5 5.5 FIX iosmacos macos tvos 28d ago visionOS 26.4
CVE-2026-28819 medium 5.4 5.4 FIX iosmacos macos 28d ago An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may …
CVE-2026-8251 medium 6.5 6.5 open5gs 28d ago A vulnerability was found in Open5GS up to 2.7.7. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation resu…
CVE-2026-8250 medium 6.5 6.5 open5gs 28d ago A vulnerability has been found in Open5GS up to 2.7.7. This affects the function smf_n4_build_qos_flow_to_modify_list of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to …
CVE-2026-8249 medium 6.5 6.5 open5gs 28d ago A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation cause…
CVE-2026-8248 medium 6.5 6.5 open5gs 28d ago A vulnerability was detected in Open5GS up to 2.7.7. The affected element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. The manipulation…
CVE-2026-45191 medium 6.5 6.5 FIX debian debian sles 28d ago Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validatio…
CVE-2026-45190 medium 6.5 6.5 FIX debian debian sles 28d ago Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass. Inputs containing a trailing newline or non-ASCII digit chara…
CVE-2026-45179 medium 5.3 5.3 28d ago Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host o…
CVE-2022-50970 medium 5.4 5.4 28d ago WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can cra…
CVE-2022-50969 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functi…
CVE-2022-50968 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality ar…
CVE-2022-50967 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are…
CVE-2022-50966 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the news/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are no…
CVE-2022-50965 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are n…
CVE-2022-50964 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/loose module. The date_created, date_from, date_to, and created_at parameters in the filter…
CVE-2022-50963 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/myAuctions/status/active module. The date_created, date_from, date_to, and created_at parameters in the filte…
CVE-2022-50962 medium 6.1 6.1 28d ago uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the orders/myOrders module. The date_created, date_from, date_to, and created_at parameters in the filter functionality ar…
CVE-2022-50961 medium 6.4 6.4 28d ago WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Setti…
CVE-2022-50960 medium 6.1 6.1 28d ago WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inj…
CVE-2022-50959 medium 6.1 6.1 28d ago WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Att…
CVE-2022-50958 medium 6.1 6.1 28d ago WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers…
CVE-2022-50957 medium 6.1 6.1 avatar_uploader_project 28d ago Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Atta…
CVE-2022-50956 medium 6.2 6.2 28d ago WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the…
CVE-2022-50955 medium 4.3 4.3 28d ago WordPress Plugin Curtain 1.0.2 contains a cross-site request forgery vulnerability that allows attackers to activate or deactivate site maintenance mode by crafting malicious requests. Attackers can …
CVE-2022-50954 medium 6.2 6.2 28d ago WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tbli…
CVE-2022-50949 medium 6.4 6.4 28d ago WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, we…