Search

Found 41,691 results in 8085ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44578 high 8.6 8.6 vercel 24d ago Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
CVE-2026-44009 critical 9.8 9.8 vm2_project 24d ago vm2 has Sandbox Breakout Through Null Proto Exception
CVE-2026-44008 critical 9.8 9.8 vm2_project 24d ago vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-44007 critical 9.1 9.1 vm2_project 24d ago vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
CVE-2026-44006 critical 10.0 10.0 vm2_project 24d ago vm2 has a Sandbox Escape Vulnerability
CVE-2026-44005 critical 10.0 10.0 vm2_project 24d ago vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
CVE-2026-44004 high 7.5 7.5 vm2_project 24d ago vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
CVE-2026-44001 high 8.6 8.6 vm2_project 24d ago vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
CVE-2026-44000 high 7.2 7.2 vm2_project 24d ago vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
CVE-2026-43999 critical 9.9 9.9 vm2_project 24d ago vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
CVE-2026-43998 high 8.5 8.5 vm2_project 24d ago vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
CVE-2026-43997 critical 10.0 10.0 vm2_project 24d ago vm2 Access to Host Object Enables Sandbox Escape
CVE-2026-44575 high 7.5 7.5 vercel 24d ago Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-44574 high 8.1 8.1 vercel 24d ago Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
CVE-2026-44573 high 7.5 7.5 vercel 24d ago Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
CVE-2026-6282 high 8.1 8.1 24d ago A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to ot…
CVE-2026-6281 high 8.8 8.8 24d ago A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
CVE-2026-45740 high 7.5 7.5 protobufjs_project 24d ago protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
CVE-2026-45033 high 7.8 7.8 github 24d ago GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git r…
CVE-2026-44470 high 7.8 7.8 anthropic 24d ago The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Window…
CVE-2026-44432 high 7.5 7.5 FIX slesdebian debian python 24d ago urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) c…
CVE-2026-44295 high 8.7 8.7 protobufjs_project 24d ago protobuf.js: Code injection in pbjs static output from crafted schema names
CVE-2026-44293 high 8.8 8.8 protobufjs_project 24d ago protobuf.js: Code injection through bytes field defaults in generated toObject code
CVE-2026-44291 high 8.1 8.1 protobufjs_project 24d ago protobuf.js: Code generation gadget after prototype pollution
CVE-2026-44290 high 7.5 7.5 protobufjs_project 24d ago protobuf.js: Process-wide denial of service through unsafe option paths
CVE-2026-44289 high 7.5 7.5 protobufjs_project 24d ago protobuf.js: Denial of service through unbounded protobuf recursion
CVE-2026-43481 high 7.8 7.8 FIX slesdebian debian 24d ago In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() con…
CVE-2026-43476 high 7.8 7.8 FIX slesdebian debian 24d ago In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) in…
CVE-2026-42930 high 8.7 8.7 24d ago When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have …
CVE-2026-42924 high 8.7 8.7 24d ago An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions…
CVE-2026-42920 high 7.5 7.5 24d ago When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software …
CVE-2026-42557 critical 9.6 9.6 debian debian jupyter 24d ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlink…
CVE-2026-42409 high 7.5 7.5 24d ago When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) …
CVE-2026-42406 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running ar…
CVE-2026-42290 high 7.8 7.8 protobufjs_project 24d ago protobuf.js is Vulnerable to OS Command Injection in the CLI
CVE-2026-41957 high 8.8 8.8 24d ago An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Software versions which have reached End of Technical S…
CVE-2026-41956 high 7.5 7.5 24d ago When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached …
CVE-2026-41953 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escala…
CVE-2026-41227 high 7.5 7.5 24d ago On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to ter…
CVE-2026-41225 critical 9.1 9.1 24d ago A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note…
CVE-2026-41218 high 7.5 7.5 24d ago When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause …
CVE-2026-41217 high 7.9 7.9 24d ago A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system comman…
CVE-2026-40698 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iCont…
CVE-2026-40631 high 8.7 8.7 24d ago An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions whic…
CVE-2026-40629 high 7.5 7.5 24d ago When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Te…
CVE-2026-40618 high 7.5 7.5 24d ago When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacc…
CVE-2026-40423 high 7.5 7.5 24d ago When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technica…
CVE-2026-40067 high 7.5 7.5 24d ago When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (…
CVE-2026-40061 high 8.7 8.7 24d ago When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or…
CVE-2026-40060 high 7.5 7.5 24d ago When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End o…
CVE-2026-39459 high 7.2 7.2 24d ago A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running …
CVE-2026-39458 high 7.5 7.5 24d ago When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which…
CVE-2026-39455 high 7.5 7.5 24d ago When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file d…
CVE-2026-36741 high 7.2 7.2 24d ago U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. A…
CVE-2026-34176 high 8.7 8.7 24d ago When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a securit…
CVE-2026-32673 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher priv…
CVE-2026-32643 high 8.7 8.7 24d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running ar…
CVE-2026-20916 high 8.1 8.1 24d ago An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.  Note: Software versions which have re…
CVE-2025-28344 high 7.5 7.5 24d ago striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343 high 7.5 7.5 24d ago striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2024-55045 high 7.3 7.3 24d ago Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.
CVE-2020-37226 high 7.1 7.1 24d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37224 high 7.1 7.1 24d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37223 high 7.8 7.8 24d ago IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou…
CVE-2020-37222 high 7.2 7.2 24d ago Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi…
CVE-2020-37221 high 8.4 8.4 24d ago Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Cloc…
CVE-2020-37220 high 7.5 7.5 24d ago Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer…
CVE-2020-37219 high 7.5 7.5 24d ago Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET reques…
CVE-2020-37218 high 8.2 8.2 24d ago Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the …
CVE-2020-37168 critical 9.8 9.8 24d ago Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. A…
CVE-2026-45083 critical 9.8 9.8 24d ago The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted …
CVE-2026-45152 high 7.8 7.8 24d ago uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files u…
CVE-2026-45136 high 7.8 7.8 cnighswonger 24d ago claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directl…
CVE-2026-44798 high 7.1 7.1 networktocode 24d ago Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the cu…
CVE-2026-44797 high 8.5 8.5 networktocode 24d ago Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient…
CVE-2026-44738 high 7.7 7.7 getgrav 24d ago Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()
CVE-2026-45134 high 7.1 7.1 24d ago LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_promp…
CVE-2026-44724 high 7.8 7.8 FIX debian debian 24d ago systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active Netwo…
CVE-2026-4609 high 7.1 7.1 24d ago The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up t…
CVE-2026-37430 high 7.3 7.3 24d ago An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2026-39806 high 7.5 7.5 mtrudel 24d ago Bandit: Unauthenticated DoS via chunked request trailers in Bandit HTTP/1 decoder
CVE-2026-39803 high 7.5 7.5 mtrudel 24d ago Bandit: Unauthenticated one-shot DoS via `Transfer-Encoding: chunked`
CVE-2026-6177 high 7.2 7.2 24d ago The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elemen…
CVE-2026-42062 critical 9.8 9.8 24d ago ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authenticati…
CVE-2026-40621 critical 9.8 9.8 24d ago ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
CVE-2026-3425 high 8.8 8.8 24d ago The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This …
CVE-2026-35506 high 7.2 7.2 24d ago ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary …
CVE-2026-6276 high 7.5 7.5 FIX debian debian sleswindows windows haxxgoogle 24d ago Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the seco…
CVE-2026-5773 high 7.5 7.5 FIX debian debian sleswindows windows haxxgoogle 24d ago libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avo…
CVE-2026-4798 high 7.5 7.5 24d ago The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the use…
CVE-2024-47091 high 7.8 7.8 checkmk 25d ago Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MyS…
CVE-2026-41050 critical 9.9 9.9 25d ago Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVE-2026-25705 high 8.4 8.4 25d ago Rancher Extensions have arbitrary file access via path traversal
CVE-2026-45793 high 8.0 FIX debian debian 25d ago Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
CVE-2026-6929 high 7.5 7.5 25d ago The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including,…
CVE-2026-44612 high 7.8 7.8 25d ago Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer,…
CVE-2026-32661 critical 9.8 9.8 25d ago Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's…
CVE-2026-21020 high 7.8 7.8 25d ago Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
CVE-2025-11159 high 7.2 7.2 hitachi 25d ago Hitachi Vantara Pentaho Data Integration & Analytics of all versions contain a JDBC driver for H2 databases which is vulnerable to external script execution when a new connection is created by a data…
CVE-2026-7635 high 8.1 8.1 25d ago The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or…