Search

Found 38,387 results in 1949ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-28893 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28892 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28891 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28890 unknown xcode 3mo ago Xcode 26.4
CVE-2026-28889 unknown xcode 3mo ago Xcode 26.4
CVE-2026-28888 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28881 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28875 unknown ios 3mo ago iOS 26.4 and iPadOS 26.4
CVE-2026-28874 unknown ios 3mo ago iOS 26.4 and iPadOS 26.4
CVE-2026-28862 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28858 unknown ios 3mo ago iOS 26.4 and iPadOS 26.4
CVE-2026-28856 unknown ios watchos apple 3mo ago visionOS 26.4
CVE-2026-28845 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28844 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28842 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28841 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28839 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28837 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28835 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28834 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28832 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28831 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28829 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28828 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28827 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28825 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28824 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28823 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28822 unknown iosmacos macos watchos 3mo ago visionOS 26.4
CVE-2026-28821 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28820 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-28818 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28817 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-28816 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20701 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20699 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20698 unknown tvos iosmacos macos 3mo ago visionOS 26.4
CVE-2026-20697 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20695 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20694 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20693 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20692 unknown macos macos ios 3mo ago macOS Sonoma 14.8.5
CVE-2026-20688 unknown macos macos ios apple 3mo ago visionOS 26.4
CVE-2026-20660 unknown macos macos 3mo ago macOS Sequoia 15.7.5
CVE-2026-20651 unknown macos macos 3mo ago macOS Sequoia 15.7.5
CVE-2026-20639 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20633 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2026-20632 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-20631 unknown macos macos 3mo ago macOS Tahoe 26.4
CVE-2026-20607 unknown macos macos 3mo ago macOS Sonoma 14.8.5
CVE-2025-59775 unknown FIX debian debianmacos macos 3mo ago Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to potentially leak NTLM hashes to a malicious server …
CVE-2026-33430 unknown 3mo ago Briefcase: Windows MSI Installer Privilege Escalation via Insecure Directory Permissions
CVE-2026-4595 low 2.4 2.4 3mo ago A vulnerability was determined in code-projects Exam Form Submission 1.0. This vulnerability affects unknown code of the file /admin/update_s6.php. Executing a manipulation of the argument sname can …
CVE-2026-4590 low 3.1 3.1 3mo ago A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the compo…
CVE-2026-4588 low 3.7 3.7 3mo ago A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-le…
CVE-2026-31851 critical 9.8 9.8 3mo ago Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authent…
CVE-2026-31848 critical 9.8 9.8 3mo ago Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential data combined with a static suffix. Because the e…
CVE-2026-4633 unknown 3mo ago Keycloak's identity-first login flow exposes user information
CVE-2026-4584 low 3.1 3.1 3mo ago A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Cardholder Data Handler. Executing a manipulation can lead to cleartext transmissi…
CVE-2026-4581 critical 9.8 9.8 code-projects 3mo ago A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the ar…
CVE-2026-4628 unknown 3mo ago Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
CVE-2026-4580 critical 9.8 9.8 code-projects 3mo ago A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulati…
CVE-2026-4579 critical 9.8 9.8 code-projects 3mo ago A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the ar…
CVE-2026-4578 low 2.4 2.4 3mo ago A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_s3.php. Executing a manipulation of the argument sname …
CVE-2026-4577 low 2.4 2.4 3mo ago A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname resu…
CVE-2026-4601 critical 9.1 9.1 jsrsasign_project 3mo ago jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction
CVE-2026-4600 critical 9.1 9.1 jsrsasign_project 3mo ago jsrsasign: DSA signatures or X.509 certificates can be forged via DSA domain-parameter validation in KJUR.crypto.DSA.setPublic
CVE-2026-4576 low 2.4 2.4 3mo ago A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /admin/update_s5.php. Such manipulation of the argument sname leads to cross site…
CVE-2026-4575 low 2.4 2.4 3mo ago A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site…
CVE-2026-33168 low 2.5 FIX slesdebian debian 3mo ago Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in…
CVE-2026-33167 low 2.5 FIX slesdebian debian 3mo ago Rails has a possible XSS vulnerability in its Action Pack debug exceptions
CVE-2026-4115 low 3.7 3.7 FIX debian debian putty 3mo ago A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verific…
CVE-2026-4541 low 2.5 2.5 FIX debian debian 3mo ago A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulat…
CVE-2026-4539 low 3.3 3.3 slesdebian debian 3mo ago A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular e…
CVE-2026-29796 critical 9.8 9.8 igl 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-25192 critical 9.8 9.8 ctek 3mo ago WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can co…
CVE-2026-33497 unknown 3mo ago langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2026-33413 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call …
CVE-2026-33484 unknown 3mo ago langflow has Unauthenticated IDOR on Image Downloads
CVE-2026-33343 unknown FIX debian debian sles 3mo ago etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use n…
CVE-2026-4499 critical 9.8 9.8 3mo ago A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can lead to os command injection. The attack may be laun…
CVE-2026-4497 critical 9.8 9.8 3mo ago A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command in…
CVE-2026-4495 low 3.5 3.5 3mo ago A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results i…
CVE-2026-4494 low 3.5 3.5 3mo ago A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross s…
CVE-2026-4477 low 3.1 3.1 3mo ago A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function of the component WPA/WPS. Executing a manipulation can lead to use of hard-code…
CVE-2026-4473 critical 9.8 9.8 unguardable 3mo ago A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argume…
CVE-2026-4472 critical 9.8 9.8 adonesevangelista 3mo ago A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulatio…
CVE-2026-4471 critical 9.8 9.8 adonesevangelista 3mo ago A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argume…
CVE-2026-4470 critical 9.8 9.8 adonesevangelista 3mo ago A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_edit_menu.php. Performing a …
CVE-2026-4469 critical 9.8 9.8 adonesevangelista 3mo ago A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such …
CVE-2026-33017 critical 9.8 10.0 KEV langflow 3mo ago Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
CVE-2026-22737 unknown debian debian 3mo ago Spring Framework Improper Path Limitation with Script View Templates
CVE-2026-22735 unknown debian debian 3mo ago Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-22733 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
CVE-2026-22732 unknown 3mo ago Spring Security HTTP Headers Are not Written Under Some Conditions
CVE-2026-22731 unknown 3mo ago Spring Boot has an Authentication Bypass under Actuator Health groups paths
CVE-2025-43520 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel …
CVE-2025-43510 unknown 1.5 KEV 3mo ago Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CVE-2026-4159 low 3.3 3.3 FIX debian debian wolfssl 3mo ago 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_Decode…
CVE-2026-3548 critical 9.8 9.8 FIX debian debian wolfssl 3mo ago Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when improperly storing the CRL number as a hexadecimal string…