Search

Found 28,684 results in 1268ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-28872 high 7.5 7.5 FIX iosmacos macos 28d ago iOS 26.4 and iPadOS 26.4
CVE-2026-28848 high 7.5 7.5 FIX macos macos 28d ago A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination.
CVE-2026-28846 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28840 high 7.8 7.8 FIX macos macos 28d ago macOS Tahoe 26.4
CVE-2025-43524 high 8.8 8.8 FIX macos macos 28d ago An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
CVE-2026-8177 high 7.5 7.5 FIX debian debian sleswindows windows 28d ago XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UT…
CVE-2026-45180 high 7.5 7.5 28d ago Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on ano…
CVE-2022-50944 high 8.8 8.8 28d ago Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can up…
CVE-2021-47949 high 8.8 8.8 28d ago CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager con…
CVE-2021-47945 high 7.8 7.8 28d ago Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attacke…
CVE-2021-47944 high 7.5 7.5 28d ago memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a p…
CVE-2021-47943 high 8.8 8.8 28d ago TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functio…
CVE-2021-47941 high 8.2 8.2 28d ago WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap co…
CVE-2021-47939 high 8.8 8.8 28d ago Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into mod…
CVE-2021-47938 high 8.8 8.8 28d ago ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code…
CVE-2021-47937 high 8.8 8.8 28d ago e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Att…
CVE-2021-47935 high 8.8 8.8 sentry 28d ago Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log e…
CVE-2021-47930 high 8.2 8.2 28d ago Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can …
CVE-2021-47928 high 8.2 8.2 28d ago Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id paramete…
CVE-2026-8234 high 8.8 8.8 28d ago A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument se…
CVE-2026-45186 high 7.5 7.5 FIX debian debian sleswindows windows libexpat_project 28d ago RHSA-2026:23230: expat security update (Important)
CVE-2026-7263 high 7.5 7.5 FIX slesdebian debian php 28d ago In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML docu…
CVE-2026-8230 high 8.8 8.8 28d ago A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command…
CVE-2026-8229 high 8.8 8.8 28d ago A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypTy…
CVE-2026-8228 high 8.8 8.8 28d ago A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/…
CVE-2026-8227 high 8.8 8.8 28d ago A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be init…
CVE-2026-8226 high 7.5 7.5 open5gs 28d ago A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in…
CVE-2026-8225 high 7.5 7.5 open5gs 28d ago A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation …
CVE-2026-7568 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the cur…
CVE-2026-7262 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which check…
CVE-2026-7258 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On…
CVE-2026-8224 high 7.5 7.5 open5gs 28d ago A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of …
CVE-2026-8223 high 7.5 7.5 open5gs 28d ago A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation result…
CVE-2026-8222 high 7.5 7.5 open5gs 28d ago A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function pcf_nbsf_management_handle_register of the file src/pcf/nbsf-handler.c of the component sm-policies Endpoint. Such mani…
CVE-2026-8216 high 7.3 7.3 29d ago A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Java RMI Session Management. …
CVE-2026-42575 high 7.5 7.5 29d ago apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
CVE-2026-42574 high 7.5 7.5 29d ago apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
CVE-2026-42562 high 8.3 8.3 29d ago Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self-escalate to administrator by submitting admin=true in PUT /api.php/v1/use…
CVE-2026-41893 high 7.5 7.5 signalk 29d ago Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)
CVE-2026-8192 high 8.8 8.8 29d ago A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/…
CVE-2026-8191 high 8.8 8.8 29d ago A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os …
CVE-2026-8190 high 8.8 8.8 29d ago A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwa…
CVE-2026-8189 high 8.8 8.8 29d ago A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Au…
CVE-2026-8188 high 8.8 8.8 29d ago A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/Encryp…
CVE-2026-8186 high 7.5 7.5 open5gs 29d ago A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of the component NF. Performing a manipulation resul…
CVE-2026-8187 high 7.5 7.5 open5gs 29d ago A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption…
CVE-2026-3828 high 7.2 7.2 29d ago Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can e…
CVE-2026-42311 high 7.8 7.8 FIX debian debian python 29d ago Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
CVE-2026-42461 high 7.5 7.5 getarcane 29d ago Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)
CVE-2026-42301 high 7.8 7.8 29d ago pyp2spec is Vulnerable to Code Injection
CVE-2026-42297 high 8.3 8.3 argoproj 29d ago Argo has Missing Authorization in its Sync ConfigMap Provider
CVE-2026-42296 high 8.1 8.1 argoproj 29d ago Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
CVE-2026-42294 high 7.5 7.5 argoproj 29d ago Argo Vulnerable to Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
CVE-2026-6666 high 7.5 7.5 FIX debian debianwindows windows pgbouncer 1mo ago A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
CVE-2026-6664 high 7.5 7.5 FIX debian debianwindows windows pgbouncer 1mo ago An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malforme…
CVE-2026-41705 high 8.6 8.6 vmware 1mo ago Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
CVE-2026-44833 high 7.1 7.1 snipeitapp 1mo ago Snipe-IT has an open redirect vulnerability
CVE-2026-42452 high 8.1 8.1 1mo ago Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled…
CVE-2026-42352 high 8.6 8.6 1mo ago pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
CVE-2026-42351 high 7.5 7.5 1mo ago pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
CVE-2026-42345 high 7.7 7.7 1mo ago FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a full…
CVE-2026-42339 high 7.1 7.1 newapi 1mo ago QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0
CVE-2026-41432 high 8.2 8.2 newapi 1mo ago New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
CVE-2023-49316 high 8.0 FIX debian debian 1mo ago Phpseclib needs guardrails on large binaryfield integers
CVE-2026-44567 high 7.3 7.3 openwebui 1mo ago Open WebUI has Improper Authorization Control
CVE-2026-44832 high 8.8 8.8 snipeitapp 1mo ago Snipe-IT has Privilege Escalation via API Permissions Assignment
CVE-2026-41486 high 8.8 8.8 anyscale 1mo ago Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVE-2026-44247 high 7.4 7.4 linuxfoundation 1mo ago Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluste…
CVE-2026-7807 high 8.8 8.8 smartertools 1mo ago SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json fi…
CVE-2026-42189 high 7.5 7.5 russh_projectwarpgate_project 1mo ago russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
CVE-2026-44552 high 8.7 8.7 openwebui 1mo ago Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVE-2026-44553 high 8.1 8.1 openwebui 1mo ago Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVE-2026-8178 high 8.1 8.1 aws 1mo ago Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
CVE-2026-29203 high 8.8 8.8 1mo ago A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege es…
CVE-2026-29202 high 8.8 8.8 1mo ago Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
CVE-2026-29201 high 8.6 8.6 1mo ago Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.
CVE-2024-27355 high 8.0 FIX debian debian 1mo ago phpseclib guardrails needed on OID length
CVE-2026-6659 high 7.5 7.5 debian debian 1mo ago Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
CVE-2026-44499 high 8.0 1mo ago Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
CVE-2026-43967 high 7.5 7.5 absinthe-graphql 1mo ago Absinthe: Quadratic fragment-name uniqueness check
CVE-2026-42793 high 7.5 7.5 absinthe-graphql 1mo ago Absinthe: Unbounded atom creation from parsed directive name
CVE-2026-42353 high 8.2 8.2 1mo ago i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters
CVE-2026-41886 high 7.5 7.5 1mo ago locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor
CVE-2026-41883 high 8.1 8.1 1mo ago OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
CVE-2026-41693 high 8.2 8.2 1mo ago i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
CVE-2026-41690 high 8.6 8.6 1mo ago i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters
CVE-2026-41683 high 8.6 8.6 1mo ago i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
CVE-2026-34354 high 7.4 7.4 1mo ago Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directo…
CVE-2026-29975 high 7.5 7.5 1mo ago lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic incorrectly identifies escaped quote characters by o…
CVE-2026-29974 high 7.5 7.5 1mo ago An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a caller-provided buffer without a size parameter. Applications using minmea_scan o…
CVE-2026-29972 high 8.2 8.2 1mo ago nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the librar…
CVE-2026-44498 high 7.5 7.5 zfnd 1mo ago Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
CVE-2026-43469 high 7.5 7.5 FIX slesdebian debian linux-kernel google 1mo ago In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decrement re_receiving on the early exit paths In the event that rpcrdma_post_recvs() fails to create a work request (d…
CVE-2026-43466 high 8.2 8.2 FIX slesdebian debian linux-kernel google 1mo ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery In case of a TX error CQE, a recovery flow is triggered, mlx5e_reset_txqs…
CVE-2026-43464 high 7.5 7.5 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ XDP multi-buf programs can modify the layout of the XDP buffer when …
CVE-2026-43462 high 7.5 7.5 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: net: spacemit: Fix error handling in emac_tx_mem_map() The DMA mappings were leaked on mapping error. Free them with the existing…
CVE-2026-43461 high 7.8 7.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: spi: amlogic: spifc-a4: Fix DMA mapping error handling Fix three bugs in aml_sfc_dma_buffer_setup() error paths: 1. Unnecessary g…
CVE-2026-43460 high 7.8 7.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: spi: rockchip-sfc: Fix double-free in remove() callback The driver uses devm_spi_register_controller() for registration, which au…
CVE-2026-43459 high 7.3 7.3 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: flush delayed work before removing DAIs and widgets When a sound card is unbound while a PCM stream is open, a us…
CVE-2026-43458 high 7.8 7.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: serial: caif: hold tty->link reference in ldisc_open and ser_release A reproducer triggers a KASAN slab-use-after-free in pty_wri…