Search

Found 82,866 results in 3930ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-48694 high 8.1 8.1 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK vari…
CVE-2026-46624 critical 9.9 9.9 twenty 11d ago Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. I…
CVE-2026-44749 medium 4.3 4.3 11d ago The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leadi…
CVE-2026-44730 high 7.2 7.2 citeum 11d ago OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd
CVE-2026-44706 high 8.5 8.5 11d ago Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type da…
CVE-2026-44669 high 8.7 8.7 11d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview f…
CVE-2026-24195 high 7.1 7.1 11d ago NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-4051 high 7.2 7.2 ibm 11d ago IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.
CVE-2026-9568 medium 5.0 5.0 11d ago A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. Th…
CVE-2026-44728 high 8.2 8.2 slesdebian debian babel 11d ago Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…
CVE-2026-44668 critical 9.8 9.8 11d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invo…
CVE-2026-44667 high 8.7 8.7 11d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification …
CVE-2026-9560 high 7.8 7.8 openvpn 11d ago Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
CVE-2026-41164 medium 4.4 4.4 11d ago nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token
CVE-2026-9170 critical 9.8 9.8 ibm 11d ago IBM HTTP Server 8.5, and 9.0
CVE-2025-33221 medium 4.4 4.4 11d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of…
CVE-2026-24201 medium 5.8 5.8 11d ago NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering…
CVE-2026-24200 high 7.0 7.0 11d ago NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to den…
CVE-2026-24194 high 7.8 7.8 11d ago NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead t…
CVE-2026-24191 high 7.8 7.8 11d ago NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service,…
CVE-2026-24190 high 7.8 7.8 11d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability mi…
CVE-2026-24193 high 7.8 7.8 11d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, …
CVE-2026-24196 high 7.1 7.1 11d ago NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information dis…
CVE-2026-8633 critical 9.8 9.8 ibm 11d ago IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code executi…
CVE-2026-24197 medium 6.5 6.5 11d ago NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lea…
CVE-2026-24199 medium 4.7 4.7 nvidia 11d ago NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of…
CVE-2026-24198 medium 5.6 5.6 11d ago NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive informati…
CVE-2026-9565 medium 6.3 6.3 11d ago A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handle…
CVE-2026-9562 high 7.3 7.3 11d ago A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such mani…
CVE-2026-8852 high 7.5 7.5 linux-kernel ibm 11d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
CVE-2026-8850 high 7.5 7.5 linux-kernel ibm 11d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
CVE-2026-48902 critical 9.8 9.8 joomla 11d ago The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
CVE-2026-48901 high 7.5 7.5 joomla 11d ago The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48864 high 7.8 7.8 debian debian sles rhel opensuseredhat 11d ago A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca…
CVE-2026-48697 high 7.4 7.4 debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl…
CVE-2026-48693 medium 5.5 5.5 debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp l…
CVE-2026-48691 critical 9.8 9.8 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attr…
CVE-2026-48690 high 7.1 7.1 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memor…
CVE-2026-48126 high 8.2 8.2 11d ago Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request…
CVE-2026-47728 medium 4.3 4.3 11d ago Bugsink: Project scoping missing in sourcemap and debug-file lookup
CVE-2026-46431 medium 4.3 4.3 11d ago Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVE-2026-46430 medium 4.3 4.3 11d ago Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVE-2026-45728 high 7.5 7.5 11d ago Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-45721 critical 9.0 9.0 11d ago Algernon: handler.lua discovery walks parent directories above the server root
CVE-2026-44723 critical 9.9 9.9 vowpalwabbit 11d ago Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate …
CVE-2026-44680 high 7.6 8.6 EXP 11d ago MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys
CVE-2026-44314 medium 4.3 4.3 traccar 11d ago Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and th…
CVE-2026-24182 medium 6.5 6.5 11d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-35222 critical 9.8 9.8 joomla 11d ago Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-30894 medium 6.1 6.1 joomla 11d ago Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-24212 critical 9.8 9.8 linux-kernel nvidia 11d ago NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalatio…
CVE-2026-24162 high 7.8 7.8 linux-kernel nvidia 11d ago NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code exec…
CVE-2025-36221 high 7.5 7.5 ibm 11d ago IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the inst…
CVE-2025-36220 critical 9.8 9.8 ibm 11d ago IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, …
CVE-2025-36145 medium 5.3 5.3 ibm 11d ago IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
CVE-2025-14290 medium 5.4 5.4 ibm 11d ago IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). Th…
CVE-2025-13755 medium 5.5 5.5 ibm 11d ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local …
CVE-2026-8620 high 7.5 7.5 ibm 11d ago IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggl…
CVE-2026-24192 high 7.8 7.8 11d ago NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this v…
CVE-2026-24187 high 8.8 8.8 11d ago NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of priv…
CVE-2026-44707 medium 6.8 6.8 11d ago Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enf…
CVE-2026-7454 high 7.8 7.8 autodesk 11d ago A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…
CVE-2026-7452 high 7.8 7.8 autodesk 11d ago A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…
CVE-2026-7451 high 7.8 7.8 autodesk 11d ago A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data co…
CVE-2026-9566 medium 4.3 4.3 11d ago A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipul…
CVE-2026-8855 high 8.1 8.1 linux-kernel ibm 11d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
CVE-2026-8856 critical 9.1 9.1 linux-kernel ibm 11d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
CVE-2026-44729 high 8.7 8.7 twenty 11d ago Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any…
CVE-2026-35221 critical 9.8 9.8 joomla 11d ago Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
CVE-2026-48903 medium 6.1 6.1 joomla 11d ago Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48896 high 7.5 7.5 joomla 11d ago Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-35220 medium 4.3 4.3 joomla 11d ago Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-40383 critical 9.8 9.8 joomla 11d ago An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-40384 high 7.5 7.5 joomla 11d ago An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
CVE-2026-48905 medium 6.1 6.1 joomla 11d ago Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48897 high 7.5 7.5 joomla 11d ago Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-25901 medium 6.1 6.1 joomla 11d ago Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-48899 critical 9.8 9.8 joomla 11d ago An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48900 medium 4.3 4.3 joomla 11d ago An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-35223 critical 9.8 9.8 joomla 11d ago An improper access check allows unauthorized access to com_config webservice endpoints.
CVE-2026-25900 medium 6.1 6.1 joomla 11d ago Lack of output escaping leads to a XSS vector in the feed modules.
CVE-2026-48904 critical 9.8 9.8 joomla 11d ago An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-30895 medium 6.1 6.1 joomla 11d ago Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVE-2026-48898 critical 9.8 9.8 joomla 11d ago An improper access check allows privilege escalation through the com_users batch task.
CVE-2025-66407 medium 5.5 11d ago Weblate has a Server-Side Request Forgery issue
CVE-2026-48692 high 8.1 8.1 debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.c…
CVE-2026-48688 high 7.5 7.5 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains …
CVE-2026-48686 critical 9.8 9.8 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() …
CVE-2026-48685 medium 6.5 6.5 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_…
CVE-2026-48684 medium 6.5 6.5 FIX debian debian pavel-odintsov 11d ago FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.…
CVE-2026-48683 medium 6.5 6.5 FIX debian debian 11d ago FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template bra…
CVE-2026-43936 medium 4.3 4.3 11d ago e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "M…
CVE-2026-43935 high 8.1 8.1 11d ago e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset l…
CVE-2026-43934 medium 6.5 6.5 11d ago e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by othe…
CVE-2026-40564 medium 6.5 6.5 apache 11d ago Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so th…
CVE-2026-38587 medium 4.3 4.3 11d ago An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-l…
CVE-2026-25112 high 7.8 7.8 11d ago A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
CVE-2026-44502 medium 4.3 4.3 11d ago Bunsink has an SSRF bypass in `validate_webhook_url`
CVE-2025-36126 high 7.6 7.6 ibm 11d ago IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows…
CVE-2025-36148 medium 6.1 6.1 ibm 11d ago IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allo…