Search

Found 58,590 results in 2547ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-11024 critical 9.8 9.8 24d ago Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. Th…
CVE-2026-6512 critical 9.1 9.1 24d ago The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized t…
CVE-2026-6504 medium 6.4 6.4 24d ago The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insuffic…
CVE-2026-6206 medium 5.3 5.3 24d ago The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restri…
CVE-2026-6174 medium 6.4 6.4 24d ago The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and ou…
CVE-2026-6145 medium 5.3 5.3 24d ago The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relyi…
CVE-2026-6670 medium 6.5 6.5 24d ago The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the 'sub_dir' and 'media_items' parameters. This is due to insufficient validation …
CVE-2026-6510 critical 9.8 9.8 24d ago The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capa…
CVE-2026-6271 critical 9.8 9.8 24d ago The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This m…
CVE-2026-6252 medium 6.4 6.4 24d ago The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute in all versions up to, and including, 1.5.2 due to insufficient input sanitiza…
CVE-2026-6225 medium 6.5 6.5 24d ago The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions u…
CVE-2026-5365 medium 4.3 4.3 24d ago The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() funct…
CVE-2026-5193 medium 6.5 6.5 24d ago The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insu…
CVE-2026-3694 medium 6.4 6.4 24d ago The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the bt_bb_button shortcode in all versions up to, and including, 5.6.8. This is due…
CVE-2026-8280 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause den…
CVE-2026-8181 critical 9.8 9.8 24d ago The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to inc…
CVE-2026-8144 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with projec…
CVE-2026-7481 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer…
CVE-2026-7471 low 3.5 3.5 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control o…
CVE-2026-7377 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allow…
CVE-2026-6883 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merg…
CVE-2026-6417 medium 6.1 6.1 24d ago The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failed_orders' parameter in all versions up to, and including, 1.4.0 due to insufficient…
CVE-2026-6335 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in ano…
CVE-2026-6073 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arb…
CVE-2026-6063 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authent…
CVE-2026-5243 medium 6.4 6.4 24d ago The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` …
CVE-2026-4527 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to creat…
CVE-2026-4524 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access…
CVE-2026-3829 medium 5.4 5.4 24d ago The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks…
CVE-2026-3607 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with develo…
CVE-2026-3160 medium 5.8 5.8 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jir…
CVE-2026-3074 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to downlo…
CVE-2026-3073 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with develo…
CVE-2026-2900 low 2.7 2.7 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention w…
CVE-2026-1338 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with devel…
CVE-2025-15345 medium 6.1 6.1 24d ago The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.2…
CVE-2025-13874 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest …
CVE-2025-12669 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject …
CVE-2026-7648 medium 4.3 4.3 24d ago The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. …
CVE-2026-7525 medium 4.3 4.3 24d ago The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying tha…
CVE-2026-5361 medium 6.4 6.4 24d ago The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in th…
CVE-2026-5486 medium 6.5 6.5 24d ago The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.…
CVE-2026-44919 medium 4.3 4.3 FIX debian debian 24d ago In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
CVE-2026-41281 medium 4.8 4.8 24d ago Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify commun…
CVE-2026-8500 critical 9.8 9.8 24d ago Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated o…
CVE-2026-45158 critical 9.1 9.1 opnsense 24d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell scrip…
CVE-2026-44448 medium 6.5 6.5 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyo…
CVE-2026-44445 medium 6.5 6.5 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enab…
CVE-2026-44442 critical 9.9 9.9 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permi…
CVE-2026-44441 medium 4.3 4.3 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making…
CVE-2026-44440 medium 5.7 5.7 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on …
CVE-2026-44437 medium 6.1 6.1 angular 24d ago The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix he…
CVE-2026-44426 medium 6.5 6.5 shellhub 24d ago ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
CVE-2026-44425 medium 5.4 5.4 shellhub 24d ago ShellHub has crash-DoS via field injection in filter and sort-by parameters
CVE-2026-44424 medium 6.5 6.5 shellhub 24d ago ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
CVE-2026-44423 medium 6.5 6.5 shellhub 24d ago ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
CVE-2026-44195 medium 6.5 6.5 opnsense 24d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication fa…
CVE-2026-44194 critical 9.1 9.1 opnsense 24d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileg…
CVE-2026-44193 critical 9.1 9.1 opnsense 24d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. T…
CVE-2026-45714 critical 9.1 9.1 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Inv…
CVE-2026-45228 medium 5.4 5.4 24d ago Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without…
CVE-2026-45054 medium 4.9 4.9 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-con…
CVE-2026-45053 critical 9.1 9.1 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The end…
CVE-2026-44381 medium 5.3 5.3 misp 24d ago MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow …
CVE-2026-44379 medium 5.3 5.3 misp 24d ago MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or mo…
CVE-2026-44377 critical 9.1 9.1 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and …
CVE-2026-44376 medium 6.1 7.1 EXP 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.p…
CVE-2026-44373 medium 5.3 5.3 nitro 24d ago Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward…
CVE-2026-44372 medium 6.1 6.1 nitro 24d ago Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after…
CVE-2026-44368 medium 5.5 24d ago pyquorum: Timing side‑channel in mul_mod
CVE-2026-39428 medium 4.8 4.8 24d ago CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can inject malicious …
CVE-2025-27852 medium 5.0 5.0 garmin 24d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary Jav…
CVE-2025-27851 critical 9.3 9.3 garmin 24d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including…
CVE-2026-44364 critical 9.5 24d ago misp-modules website - Missing CSRF protection in the website home blueprint
CVE-2026-44363 medium 5.5 24d ago misp-modules has nsafe remote resource fetching in expansion
CVE-2026-44351 critical 9.1 9.1 24d ago fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
CVE-2026-33381 medium 5.9 5.9 sles 24d ago When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.
CVE-2026-33380 medium 6.3 6.3 sles 24d ago A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vul…
CVE-2026-33378 medium 6.5 6.5 sles grafana 24d ago Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the …
CVE-2026-28383 medium 6.5 6.5 sles grafana 24d ago A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-me…
CVE-2026-28380 medium 6.5 6.5 sles grafana 24d ago Any Editor could delete any snapshot, even if they have no access to read or write them.
CVE-2026-28379 medium 6.5 6.5 sles grafana 24d ago A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete ser…
CVE-2026-28376 medium 6.5 6.5 sles grafana 24d ago The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated us…
CVE-2026-28374 medium 4.3 4.3 sles grafana 24d ago Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
CVE-2026-8496 medium 6.1 6.1 FIX debian debian 24d ago A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated S…
CVE-2026-42584 critical 9.1 9.1 slesdebian debian netty 24d ago Netty has HttpClientCodec response desynchronization
CVE-2026-42581 critical 9.8 9.8 slesdebian debian netty 24d ago Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVE-2026-42580 medium 6.5 6.5 slesdebian debian netty 24d ago Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
CVE-2026-42579 critical 9.1 9.1 slesdebian debian netty 24d ago Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
CVE-2026-42032 critical 9.1 9.1 okfn 24d ago CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2026-42031 critical 9.8 9.8 okfn 24d ago CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-41255 medium 6.1 6.1 okfn 24d ago CKAN has CSRF exemption primed by anonymous requests
CVE-2026-33585 low 3.8 3.8 24d ago Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session.…
CVE-2026-33584 medium 5.3 5.3 24d ago Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Sym…
CVE-2026-30904 medium 4.3 4.3 zoom 24d ago Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information via physical access.
CVE-2026-22677 medium 6.5 6.5 24d ago Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted session with an…
CVE-2026-0257 critical 9.1 10.0 KEV paloaltonetworks 24d ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2026-45411 critical 9.8 9.8 vm2_project 24d ago vm2 Has a Sandbox Breakout Using Async Generator
CVE-2026-44582 low 3.7 3.7 vercel 24d ago Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44581 medium 4.7 4.7 vercel 24d ago Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces