Search

Found 33,935 results in 2693ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-24485 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the Deco…
CVE-2026-24484 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions t…
CVE-2026-24481 unknown FIX debian debian sles 3mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMag…
CVE-2026-3069 critical 9.8 9.8 admerc 3mo ago A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to s…
CVE-2026-3068 critical 9.8 9.8 admerc 3mo ago A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to…
CVE-2026-3057 critical 9.8 9.8 a54552239 3mo ago A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Inter…
CVE-2026-3053 critical 9.8 9.8 dinky 3mo ago A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component Ope…
CVE-2026-3046 critical 9.8 9.8 emiloi 3mo ago A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The ma…
CVE-2026-3042 critical 9.8 9.8 admerc 3mo ago A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID result…
CVE-2026-25108 unknown 1.5 KEV 3mo ago Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.
CVE-2026-26198 unknown FIX debian debian 3mo ago Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sq…
CVE-2026-3025 critical 9.8 9.8 shuoren 3mo ago A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.a…
CVE-2026-2983 critical 9.8 9.8 munyweki 3mo ago A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Impor…
CVE-2026-25747 unknown 3mo ago Apache Camel Deserializes Untrusted Data in its LevelDB Component
CVE-2026-23552 unknown 3mo ago Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realm
CVE-2026-2964 critical 9.8 9.8 higuma 3mo ago A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipul…
CVE-2026-2954 critical 9.8 9.8 ujcms 3mo ago A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a ma…
CVE-2026-2953 critical 9.1 9.1 ujcms 3mo ago A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulatio…
CVE-2026-2952 critical 9.8 9.8 vaelsys 3mo ago A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request Handler. This manipulation of the argument xajaxar…
CVE-2026-2944 critical 9.8 9.8 tosei-corporation 3mo ago A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file /cgi-bin/monitor.php of the component HTTP POST Request Handl…
CVE-2026-2912 critical 9.8 9.8 fabian 4mo ago A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation…
CVE-2026-2867 critical 9.8 9.8 admerc 4mo ago A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql …
CVE-2026-2865 critical 9.8 9.8 adonesevangelista 4mo ago A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler.…
CVE-2026-2848 critical 9.8 9.8 oretnom23 4mo ago A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component R…
CVE-2026-26725 critical 9.8 9.8 edubusinesssolutions 4mo ago An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID parameter.
CVE-2026-22384 critical 9.8 9.8 4mo ago Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.
CVE-2025-10970 critical 9.8 9.8 4mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection. This issue affects Talentics: through …
CVE-2026-21620 unknown FIX debian debian sles 4mo ago Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file module…
CVE-2025-68461 unknown 1.5 KEVFIX debian debian 4mo ago RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2026-24122 unknown FIX debian debian sles 4mo ago Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be conside…
CVE-2025-13590 unknown 4mo ago carbon-apimgt does not properly restrict uploaded files
CVE-2026-2733 unknown 4mo ago Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
CVE-2025-9953 critical 9.8 9.8 4mo ago Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Data…
CVE-2025-8350 critical 9.8 9.8 4mo ago Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splittin…
CVE-2026-2691 critical 9.8 9.8 admerc 4mo ago A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argum…
CVE-2026-2690 critical 9.8 9.8 admerc 4mo ago A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. Th…
CVE-2026-2689 critical 9.8 9.8 admerc 4mo ago A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql inj…
CVE-2026-2684 critical 9.8 9.8 unigroup 4mo ago A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html.…
CVE-2026-2682 critical 9.8 9.8 unigroup 4mo ago A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.html?token=java. Such…
CVE-2026-26318 unknown FIX debian debian 4mo ago systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixe…
CVE-2026-26280 unknown FIX debian debian 4mo ago systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arb…
CVE-2026-24708 unknown FIX debian debian 4mo ago An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user ma…
CVE-2025-14009 unknown FIX debian debian 4mo ago NLTK has a Zip Slip Vulnerability
CVE-2026-27100 unknown 4mo ago Jenkins has a build information disclosure vulnerability through Run Parameter
CVE-2026-27099 unknown 4mo ago Jenkins has a stored XSS vulnerability in node offline cause description
CVE-2026-2654 critical 9.8 9.8 huggingface 4mo ago Hugging Face Smolagents has a Server-Side Request Forgery issue
CVE-2026-22769 unknown 1.5 KEV 4mo ago Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlyi…
CVE-2021-22175 unknown 1.5 KEV 4mo ago GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
CVE-2026-24734 unknown FIX slesdebian debian google 4mo ago Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verific…
CVE-2026-24733 unknown FIX slesdebian debian 4mo ago Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny…
CVE-2025-66614 unknown FIX slesdebian debian 4mo ago Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were…
CVE-2026-2616 critical 9.8 9.8 4mo ago A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials…
CVE-2026-22208 critical 9.6 9.6 4mo ago OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua u…
CVE-2026-25087 unknown FIX debian debian 4mo ago Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-…
CVE-2026-25903 unknown 4mo ago Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates
CVE-2026-2441 unknown 2.5 KEVEXPFIX debian debian sles 4mo ago Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2024-7694 unknown 1.5 KEV 4mo ago TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Rem…
CVE-2020-7796 unknown 1.5 KEV 4mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
CVE-2008-0015 unknown 2.5 KEVEXP 4mo ago Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the…
CVE-2026-2528 critical 9.8 9.8 4mo ago A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument…
CVE-2026-2527 critical 9.8 9.8 4mo ago A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command i…
CVE-2026-23112 critical 9.8 9.8 FIX slesdebian debian linux-kernel 4mo ago In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU leng…
CVE-2025-33042 unknown 4mo ago Apache Avro Java SDK is Vulnerable to Code Injection
CVE-2026-1731 unknown 2.5 KEVEXP 4mo ago BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute oper…
CVE-2025-47911 unknown FIX debian debian sles 4mo ago The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted H…
CVE-2026-26000 unknown 4mo ago XWiki vulnerable to click-jacking through CSS injection in comments
CVE-2025-14014 critical 9.8 9.8 4mo ago Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality …
CVE-2025-10969 critical 9.8 9.8 farktor 4mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection. This is…
CVE-2026-20700 unknown 1.5 KEV 4mo ago Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capab…
CVE-2025-40536 unknown 2.5 KEVEXP 4mo ago SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
CVE-2025-15556 unknown 1.5 KEV 4mo ago Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute…
CVE-2024-43468 unknown 1.5 KEV 4mo ago Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment w…
CVE-2025-12059 critical 9.8 9.8 4mo ago Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access …
CVE-2026-26010 unknown 4mo ago Leaky JWTs in OpenMetadata exposing highly-privileged bot users
CVE-2025-8668 critical 9.4 9.4 4mo ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd…
CVE-2025-8025 critical 9.8 9.8 4mo ago Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This …
CVE-2026-23906 unknown 4mo ago Apache Druid Vulnerable to Authentication Bypass
CVE-2026-23901 unknown debian debian 4mo ago Apache Shiro Affected by an Observable Timing Discrepancy Vulnerability
CVE-2025-11537 unknown 4mo ago Keycloak logs sensitive headers
CVE-2025-11242 critical 9.8 9.8 4mo ago Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Side Request Forgery. This issue affects Okulistik:…
CVE-2026-25934 unknown FIX debian debian sles 4mo ago go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not …
CVE-2026-21533 unknown 1.5 KEV 4mo ago Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21525 unknown 1.5 KEV 4mo ago Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
CVE-2026-21519 unknown 1.5 KEV 4mo ago Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21514 unknown 1.5 KEV 4mo ago Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
CVE-2026-21513 unknown 1.5 KEV 4mo ago Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
CVE-2026-21510 unknown 1.5 KEV 4mo ago Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
CVE-2026-1529 unknown 4mo ago Keycloak affected by improper invitation token validation
CVE-2026-1486 unknown 4mo ago Keycloak fails to verify if an Identity Provider (IdP) is enabled before issuing tokens
CVE-2025-14778 unknown 4mo ago Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionService
CVE-2026-23903 unknown debian debian 4mo ago Apache Shiro has an Authentication Bypass
CVE-2026-22922 unknown 4mo ago Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
CVE-2025-6830 critical 9.8 9.8 4mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affec…
CVE-2026-2225 critical 9.8 9.8 clive_21 4mo ago A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argu…
CVE-2026-2223 critical 9.8 9.8 fabian 4mo ago A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/ta…
CVE-2026-2221 critical 9.8 9.8 fabian 4mo ago A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the …
CVE-2026-2220 critical 9.8 9.8 fabian 4mo ago A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation…
CVE-2026-2217 critical 9.8 9.8 admerc 4mo ago A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in s…
CVE-2026-1615 critical 9.8 9.8 sles 4mo ago jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions
CVE-2026-2212 critical 9.8 9.8 fabian 4mo ago A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulatio…