Search

Found 41,692 results in 5116ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41091 high 7.8 9.3 KEV windows windows microsoft 18d ago Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-3593 critical 9.8 9.8 FIX debian debian sleswindows windows isc 18d ago Bind vulnerabilities
CVE-2026-3039 high 7.5 7.5 FIX debian debian sleswindows windows isc 18d ago Bind vulnerabilities
CVE-2026-29518 high 7.0 7.0 FIX slesdebian debianwindows windows samba 18d ago rsync vulnerabilities
CVE-2025-11954 high 8.0 8.0 18d ago Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: The ve…
CVE-2025-31973 critical 9.8 9.8 hcltech 18d ago HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially i…
CVE-2026-22315 high 7.2 7.2 18d ago Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user data, including cleartext passwords, via the SQL ed…
CVE-2026-22314 critical 9.0 9.0 18d ago Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This…
CVE-2026-0856 high 7.8 7.8 18d ago Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Clie…
CVE-2026-9064 high 7.5 7.5 debian debian sles rhel redhat 19d ago A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated a…
CVE-2026-44933 high 7.8 7.8 sles 19d ago `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, …
CVE-2026-42960 critical 10.0 10.0 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-42959 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-42944 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-41292 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-41054 high 7.8 7.8 FIX debian debian sleswindows windows 19d ago haveged vulnerability
CVE-2026-40622 high 7.5 7.5 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-33278 critical 9.8 9.8 FIX slesdebian debianwindows windows nlnetlabs 19d ago Unbound vulnerabilities
CVE-2026-5200 high 8.8 8.8 19d ago The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. Th…
CVE-2026-46640 high 8.0 FIX debian debian 19d ago Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVE-2026-46639 high 8.0 FIX debian debian 19d ago Twig: Sandbox property and method bypass via object-destructuring assignment
CVE-2026-46633 critical 9.5 FIX debian debian 19d ago Twig: PHP code injection via `{% use %}` template name
CVE-2026-45077 high 8.0 FIX debian debian 19d ago Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
CVE-2026-45067 high 8.0 FIX debian debian 19d ago Symfony has Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
CVE-2026-45063 high 8.0 FIX debian debian 19d ago Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator
CVE-2026-24425 critical 9.9 9.9 FIX debian debian symfony 19d ago Twig: Possible sandbox bypass when using a source policy
CVE-2026-47784 high 8.1 8.1 FIX slesdebian debianwindows windows memcached 19d ago Memcached vulnerabilities
CVE-2026-47783 high 8.1 8.1 FIX slesdebian debianwindows windows memcached 19d ago Memcached vulnerabilities
CVE-2026-9057 high 8.2 8.2 19d ago A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a p…
CVE-2026-7522 high 8.8 8.8 19d ago The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for aut…
CVE-2026-9010 high 7.5 7.5 19d ago The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the u…
CVE-2026-9003 high 7.5 7.5 19d ago E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
CVE-2026-7637 critical 9.8 9.8 19d ago The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This mak…
CVE-2026-24215 high 7.5 7.5 nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to …
CVE-2026-24214 critical 9.8 9.8 nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution,…
CVE-2026-24213 critical 9.8 9.8 nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code executio…
CVE-2026-24210 high 7.5 7.5 linux-kernel nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-24209 high 7.5 7.5 linux-kernel nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-24208 high 7.5 7.5 linux-kernel nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-24207 critical 9.8 9.8 linux-kernel nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of …
CVE-2026-24206 critical 9.8 9.8 linux-kernel nvidia 19d ago NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, deni…
CVE-2026-24163 critical 9.8 9.8 nvidia 19d ago NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execut…
CVE-2026-24160 high 7.5 7.5 nvidia 19d ago NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulnerability might lead …
CVE-2026-24142 critical 9.8 9.8 nvidia 19d ago NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and i…
CVE-2025-33255 critical 9.8 9.8 nvidia 19d ago NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code executio…
CVE-2026-7467 high 8.8 8.8 19d ago The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting…
CVE-2026-7284 critical 9.8 9.8 19d ago The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due …
CVE-2026-6555 critical 9.8 9.8 19d ago The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in…
CVE-2026-6456 high 8.8 8.8 19d ago The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose compari…
CVE-2026-43618 high 8.1 8.1 FIX slesdebian debianwindows windows samba 19d ago rsync vulnerabilities
CVE-2026-3985 high 7.5 7.5 19d ago The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. T…
CVE-2026-46333 high 7.1 7.1 FIX rhel slesdebian debian google 19d ago Linux kernel vulnerabilities
CVE-2026-46300 high 7.8 8.8 EXPFIX rhel slesdebian debian awsgoogle 19d ago Linux kernel vulnerabilities
CVE-2026-43128 high 7.8 7.8 FIX rhel slesdebian debian 19d ago In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix double dma_buf_unpin in failure path In ib_umem_dmabuf_get_pinned_with_dma_device(), the call to ib_umem_dmabuf_ma…
CVE-2026-37555 high 7.5 7.5 FIX rheldebian debian sles libsndfile_project 19d ago RHSA-2026:19559: libsndfile security update (Important)
CVE-2026-31607 critical 9.8 9.8 FIX rhel slesdebian debian 19d ago In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_…
CVE-2026-31532 high 7.8 7.8 FIX rhel slesdebian debian google 19d ago In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive filters via can_rx_unregister(), but…
CVE-2026-23401 high 8.0 FIX rhel slesdebian debian google 19d ago In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE When installing an emulated MMIO SPTE, do so *after*…
CVE-2026-23204 high 7.1 7.1 FIX rocky rhel sles 19d ago Linux kernel vulnerabilities
CVE-2026-22990 high 8.0 FIX rhel slesdebian debian 19d ago Linux kernel (Azure) vulnerabilities
CVE-2026-22984 high 8.0 FIX rhel slesdebian debian 19d ago Linux kernel (Azure) vulnerabilities
CVE-2025-71116 high 8.0 FIX rhel slesdebian debian 19d ago Linux kernel (Low Latency NVIDIA) vulnerabilities
CVE-2025-68741 high 8.0 FIX rhel slesdebian debian 19d ago Linux kernel (Low Latency NVIDIA) vulnerabilities
CVE-2025-39766 high 7.8 7.8 FIX rhel slesdebian debian 19d ago Important: kernel security update
CVE-2026-8495 critical 9.8 9.8 date_ical_project 19d ago This module enables you to export entity date fields as iCal feeds. The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds. This vulnerabili…
CVE-2026-34358 high 8.1 8.1 19d ago CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on …
CVE-2026-34241 high 8.7 8.7 19d ago CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitize…
CVE-2026-34234 critical 10.0 10.0 19d ago CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Executi…
CVE-2026-39250 high 7.3 7.3 19d ago An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations.
CVE-2026-32882 high 7.1 7.1 debian debian sles 19d ago libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overla…
CVE-2026-32741 high 7.1 7.1 debian debian sles 19d ago libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mas…
CVE-2026-46417 high 8.0 19d ago @angular/platform-server: SSRF via Hostname Hijacking
CVE-2026-46415 high 8.0 19d ago Caddy Defender trusted proxy client IP bypass
CVE-2026-46412 critical 9.5 19d ago Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
CVE-2026-32740 high 8.8 8.8 debian debian sles struktur 19d ago libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write …
CVE-2026-27173 high 8.7 8.7 19d ago Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
CVE-2026-46410 high 8.0 19d ago FileBrowser Quantum: unauthenticated user share share info
CVE-2026-46374 high 8.0 19d ago SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
CVE-2026-46373 high 8.0 19d ago SQLFluff: Recursive Stack Overflow in Parser
CVE-2026-46372 high 8.5 8.5 19d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-46378 high 8.0 19d ago Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
CVE-2026-46377 high 8.0 19d ago Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
CVE-2026-45783 high 8.0 19d ago @libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
CVE-2026-46354 critical 9.5 19d ago Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CVE-2026-45805 high 8.0 19d ago PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
CVE-2026-45799 high 8.0 19d ago Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
CVE-2026-46339 critical 9.5 19d ago 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVE-2026-45695 critical 9.5 19d ago Kopia: RCE via SSH ProxyCommand Injection
CVE-2026-8073 high 7.5 7.5 19d ago The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in …
CVE-2026-33642 critical 9.8 9.8 FIX debian debian kovidgoyal 19d ago Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …
CVE-2026-8605 critical 9.8 9.8 scadabr 19d ago In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
CVE-2026-8604 high 8.8 8.8 scadabr 19d ago In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
CVE-2026-8603 critical 9.8 9.8 scadabr 19d ago In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
CVE-2026-8602 critical 9.1 9.1 scadabr 19d ago In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
CVE-2026-47107 high 8.1 8.1 19d ago Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authentica…
CVE-2026-33633 high 8.8 8.8 FIX debian debian kovidgoyal 19d ago Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash ki…
CVE-2025-61081 high 7.5 7.5 19d ago Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2026-47358 high 8.6 8.6 tenable 19d ago Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …
CVE-2026-47357 high 8.6 8.6 tenable 19d ago Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/sca…
CVE-2026-47356 high 8.6 8.6 tenable 19d ago Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when run…