Search

Found 33,075 results in 1513ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44594 high 7.5 7.5 25d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in…
CVE-2026-45227 high 8.8 8.8 25d ago Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspec…
CVE-2026-45226 high 7.1 7.1 25d ago Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without pro…
CVE-2026-45225 high 7.6 7.6 25d ago Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted…
CVE-2026-44871 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
CVE-2026-44302 high 7.5 7.5 25d ago Snappier has an infinite loop during SnappyStream decompression with malformed framed input
CVE-2026-44301 high 8.1 8.1 FIX debian debian gohugo 25d ago Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools with…
CVE-2026-44296 high 7.5 7.5 FIX debian debian 25d ago Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). Whe…
CVE-2026-44260 high 8.1 8.1 25d ago efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk en…
CVE-2026-44242 low 3.7 3.7 25d ago Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
CVE-2026-44241 high 7.5 7.5 25d ago Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header
CVE-2026-42855 high 7.5 7.5 espressif 25d ago arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp…
CVE-2026-42544 high 7.5 7.5 25d ago Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
CVE-2026-42268 high 7.5 7.5 FIX slesdebian debian owasp 25d ago ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused …
CVE-2026-26289 high 8.2 8.2 25d ago PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions …
CVE-2026-44403 high 7.2 8.2 EXP wftpserver 25d ago Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code…
CVE-2026-44246 high 7.2 7.2 dkfz 25d ago nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable…
CVE-2026-44240 high 7.5 7.5 FIX debian debian 25d ago basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVE-2026-44232 high 8.0 25d ago dssrf: every IPv6 category bypasses is_url_safe
CVE-2026-44224 high 8.8 8.8 requarks 25d ago Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation o…
CVE-2025-65088 high 7.8 7.8 ashlar 25d ago An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information o…
CVE-2025-65087 high 7.8 7.8 ashlar 25d ago An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information o…
CVE-2025-65086 high 7.8 7.8 ashlar 25d ago An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary cod…
CVE-2026-7474 high 8.8 8.8 25d ago HashiCorp Nomad vulnerable to a path traversal
CVE-2026-44872 high 7.2 7.2 arubanetworks 25d ago A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arb…
CVE-2026-44870 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
CVE-2026-44869 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44868 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44867 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44866 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44865 high 7.2 7.2 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44864 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44863 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44862 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44861 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44860 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44859 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44858 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44857 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44856 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44855 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44854 high 7.2 7.2 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arb…
CVE-2026-44853 high 7.2 7.2 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arb…
CVE-2026-44852 high 7.2 7.2 arubanetworks 25d ago An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authentica…
CVE-2026-44222 high 7.5 7.5 vllm 25d ago vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44220 low 3.2 3.2 25d ago ciguard: discover_pipeline_files follows symlinks out of scan root
CVE-2026-44219 low 3.7 3.7 25d ago ciguard: SCA HTTP client reads response body without size cap
CVE-2026-44218 low 3.0 3.0 25d ago ciguard: Container image runs as root (no USER directive)
CVE-2026-44215 high 7.1 7.1 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is …
CVE-2026-42446 high 7.1 7.1 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerability is triggered …
CVE-2026-42191 high 7.8 7.8 opentelemetry 25d ago OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-34690 high 7.8 7.8 macos macos adobe 25d ago After Effects versions 26.0, 25.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…
CVE-2026-34686 high 8.7 8.7 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-pr…
CVE-2026-34685 low 3.4 3.4 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier [NEEDS REVIEW: impact mismatch — ticket says 'Arbitrary file system write', CIA triad derives 'Sec…
CVE-2026-34665 high 7.5 7.5 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34653 high 8.7 8.7 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') …
CVE-2026-34652 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result i…
CVE-2026-34651 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34650 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34649 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34648 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34647 high 7.4 7.4 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security…
CVE-2026-34646 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature b…
CVE-2026-34645 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature b…
CVE-2026-23827 high 7.5 7.5 arubanetworks 25d ago A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful …
CVE-2026-23826 high 7.5 7.5 arubanetworks 25d ago A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to …
CVE-2026-23825 high 7.5 7.5 arubanetworks 25d ago Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network mess…
CVE-2026-23824 high 7.5 7.5 arubanetworks 25d ago Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network mess…
CVE-2026-8431 high 7.2 7.2 25d ago An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.  This issue affe…
CVE-2026-8430 high 8.1 8.1 FIX debian debian 25d ago SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the co…
CVE-2026-8429 high 8.8 8.8 FIX debian debian 25d ago SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploi…
CVE-2026-34684 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34683 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34682 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34681 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-23823 high 7.2 7.2 25d ago A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacke…
CVE-2026-23821 high 7.2 7.2 25d ago A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Su…
CVE-2026-23820 high 7.2 7.2 25d ago A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environme…
CVE-2026-23819 high 8.8 8.8 25d ago A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim…
CVE-2026-31225 high 8.8 8.8 25d ago Superduper: Remote code execution via unsafe eval in superduper query parsing
CVE-2026-31222 high 8.8 8.8 snorkel 25d ago Snorkel Trainer.load uses an unsafe torch.load
CVE-2026-31221 high 7.8 7.8 lightningai 25d ago PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CVE-2026-44184 high 8.0 8.0 25d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy refl…
CVE-2026-44166 high 7.6 7.6 pocketbase 25d ago PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
CVE-2026-43929 high 8.2 8.2 25d ago ssrfcheck Vulnerable to Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
CVE-2026-43892 high 8.8 8.8 25d ago AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed i…
CVE-2026-43891 high 7.5 7.5 webtechnologies 25d ago changedetection.io has an Arbitrary Local File Read via a crafted backup restore
CVE-2026-42896 high 7.8 7.8 FIX windows windows 25d ago Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42893 high 7.4 7.4 windows windows microsoft 25d ago Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-42832 high 7.7 7.7 windows windows microsoft 25d ago Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831 high 7.8 7.8 windows windows microsoft 25d ago Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-42825 high 7.0 7.0 FIX windows windows 25d ago Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-42348 high 7.5 7.5 opentelemetry 25d ago OpAMP client reads unbounded HTTP response bodies
CVE-2026-42141 high 7.7 7.7 25d ago Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerabi…
CVE-2026-41895 high 7.5 7.5 webtechnologies 25d ago changedetection.io project has an XXE vulnerability
CVE-2026-41613 high 8.8 8.8 windows windows microsoft 25d ago Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41611 high 7.8 7.8 windows windows microsoft 25d ago Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVE-2026-41109 high 8.8 8.8 windows windows microsoft 25d ago Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…
CVE-2026-41107 high 7.4 7.4 windows windows microsoft 25d ago External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-41102 high 7.1 7.1 windows windows microsoft 25d ago Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.