Search

Found 33,076 results in 4664ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-53681 high 7.2 7.2 fortinet 25d ago An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5,…
CVE-2025-46311 high 7.5 7.5 FIX macos macos 25d ago An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able to access sensitiv…
CVE-2026-5089 high 7.3 7.3 FIX debian debian 25d ago YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. Whe…
CVE-2026-43993 high 8.2 8.2 25d ago JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify called fetch() on agent-supplied URLs without validating scheme, port, or reso…
CVE-2026-43991 high 8.4 8.4 25d ago JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin-shell's command-safety check could be bypassed by adversarial argument constru…
CVE-2026-43990 high 8.4 8.4 25d ago JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument…
CVE-2026-43989 high 8.5 8.5 25d ago JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes the path resolved t…
CVE-2026-20793 low 3.3 3.3 intel 25d ago Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an a…
CVE-2026-43514 low 3.7 3.7 FIX slesdebian debian apache 25d ago Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M…
CVE-2026-43513 high 7.5 7.5 FIX slesdebian debian apache 25d ago Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 …
CVE-2026-42498 high 7.3 7.3 FIX slesdebian debian apache 25d ago Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1…
CVE-2026-41284 high 7.5 7.5 FIX slesdebian debian apache 25d ago Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 t…
CVE-2026-31224 high 8.8 8.8 snorkel 25d ago Snorkel MultitaskClassifier.load uses an unsafe torch.load
CVE-2026-31223 high 8.8 8.8 snorkel 25d ago Snorkel BaseLabeler.load uses an unsafe pickle.load
CVE-2026-31219 high 8.8 8.8 25d ago The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CW…
CVE-2026-31218 high 8.8 8.8 25d ago The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CW…
CVE-2026-30810 high 8.8 8.8 artica 25d ago Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30808 high 8.1 8.1 artica 25d ago Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
CVE-2026-30807 high 8.8 8.8 artica 25d ago Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
CVE-2023-27753 high 8.0 8.0 25d ago An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2026-8111 high 8.8 8.8 ivanti 25d ago SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
CVE-2026-8110 high 7.8 7.8 ivanti 25d ago Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
CVE-2026-8051 high 7.2 7.2 ivanti 25d ago OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2026-7432 high 7.0 7.0 ivanti 25d ago A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
CVE-2026-43983 high 8.1 8.1 pocket-id 25d ago Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh …
CVE-2026-43939 high 7.3 7.3 25d ago YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
CVE-2026-43938 high 8.1 8.1 25d ago YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
CVE-2026-43937 high 8.8 8.8 25d ago YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
CVE-2026-42260 high 8.2 8.2 25d ago open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
CVE-2026-32687 high 7.8 7.8 elixir-ecto 25d ago Postgrex: Channel-name SQL injection in `Postgrex.Notifications.listen/3`
CVE-2026-8390 high 7.3 7.3 FIX debian debian mozilla 25d ago Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-8389 high 8.8 8.8 FIX debian debian mozilla 25d ago JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-35071 high 8.2 8.2 dell 25d ago Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability. A high privileged attack…
CVE-2025-12659 high 7.8 7.8 25d ago Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-45218 high 7.7 7.7 26d ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a t…
CVE-2026-45214 high 8.5 8.5 26d ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Blind SQL Injection.This issue affects Xp…
CVE-2026-45213 high 7.6 7.6 26d ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a thro…
CVE-2026-45211 high 8.5 8.5 26d ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affe…
CVE-2026-42742 high 8.5 8.5 26d ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views…
CVE-2026-42741 high 8.5 8.5 26d ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend v…
CVE-2026-41713 high 8.2 8.2 vmware 26d ago Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
CVE-2026-41712 high 7.5 7.5 vmware 26d ago Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
CVE-2026-32684 low 2.9 2.9 26d ago The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information.
CVE-2026-2465 high 8.8 8.8 26d ago Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affect…
CVE-2026-8162 high 7.5 7.5 FIX debian debian pillarjs 26d ago multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
CVE-2026-8161 high 7.5 7.5 FIX debian debian pillarjs 26d ago multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
CVE-2026-8159 high 7.5 7.5 FIX debian debian pillarjs 26d ago multiparty vulnerable to ReDoS via filename parsing
CVE-2026-6001 high 8.8 8.8 26d ago Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042.
CVE-2026-44412 high 7.8 7.8 26d ago A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted PAR f…
CVE-2026-44411 high 7.8 7.8 26d ago A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR f…
CVE-2026-33893 high 7.5 7.5 siemens 26d ago A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All …
CVE-2026-27662 high 7.7 7.7 26d ago Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security mechanisms are in place. This could allow an unauthenticated attacker to gain…
CVE-2026-25789 high 7.1 7.1 26d ago Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file…
CVE-2026-22925 high 7.5 7.5 26d ago A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This cou…
CVE-2025-40947 high 7.5 7.5 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2025-40946 high 8.3 8.3 26d ago A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All version…
CVE-2025-40833 high 7.5 7.5 26d ago The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker to cause denial of service condition. A manual res…
CVE-2026-6690 high 7.2 7.2 26d ago The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the …
CVE-2026-39432 high 8.2 8.2 26d ago Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.
CVE-2026-2993 high 7.5 7.5 26d ago The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and …
CVE-2026-1185 high 8.8 8.8 26d ago A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if …
CVE-2026-0804 high 7.3 7.3 26d ago An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axi…
CVE-2026-0802 high 7.3 7.3 26d ago An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis d…
CVE-2026-0541 high 7.3 7.3 26d ago ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited …
CVE-2026-41872 high 7.4 7.4 26d ago "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notific…
CVE-2026-41530 low 3.3 3.3 26d ago The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation fe…
CVE-2026-7287 high 7.5 7.5 26d ago ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100…
CVE-2026-7256 high 8.8 8.8 26d ago ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operat…
CVE-2026-45430 high 7.1 7.1 26d ago The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
CVE-2026-40131 low 3.4 3.4 26d ago SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploi…
CVE-2026-34259 high 8.2 8.2 26d ago Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbi…
CVE-2026-45393 high 7.8 7.8 26d ago A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorrect default permissions on the Windows installer's…
CVE-2026-45392 high 8.7 8.7 26d ago DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a craf…
CVE-2026-45391 high 7.8 7.8 26d ago A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary commands in the context of the Cribl Edge service account.
CVE-2026-45362 low 3.2 3.2 26d ago Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
CVE-2026-8346 high 8.8 8.8 26d ago A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The at…
CVE-2026-4887 high 7.1 7.1 FIX rheldebian debian sles gimp 26d ago Important: gimp security update
CVE-2026-43284 high 8.8 9.8 EXPFIX rhel slesdebian debian awsgoogle 26d ago Important: kernel security update
CVE-2026-42559 high 8.8 8.8 26d ago rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
CVE-2026-4154 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4153 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4152 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4151 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-4150 high 8.0 FIX rheldebian debian sles 26d ago Important: gimp security update
CVE-2026-8345 high 8.8 8.8 26d ago A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the …
CVE-2026-43913 high 8.1 8.1 dani-garcia 26d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flo…
CVE-2026-43912 high 8.7 8.7 dani-garcia 26d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as grou…
CVE-2026-43911 high 8.1 8.1 dani-garcia 26d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (pass…
CVE-2026-34963 high 7.8 7.8 pengutronix 26d ago barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithm…
CVE-2026-8344 high 8.8 8.8 26d ago A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command in…
CVE-2026-43897 high 8.0 26d ago link-preview-js vulnerable to IPv6 and internal loopback attacks
CVE-2026-43893 high 8.2 8.2 26d ago exiftool-vendored vulnerable to argument injection via newline characters in tag names
CVE-2026-43890 high 7.7 7.7 26d ago Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/subscriptions/subscriptions.ts exhibits a broken aut…
CVE-2026-43888 high 8.7 8.7 26d ago Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by passing a full filesystem path through trimFileAndEx…
CVE-2026-43887 high 7.3 7.3 26d ago Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other users; however, the backend does not validate or san…
CVE-2026-43886 high 8.2 8.2 26d ago Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing t…
CVE-2026-42564 high 8.2 8.2 26d ago jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is jo…
CVE-2026-42188 low 2.4 2.4 26d ago Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
CVE-2026-42046 high 7.8 7.8 FIX debian debian sles 26d ago libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-boun…
CVE-2026-34961 high 7.7 7.7 pengutronix 26d ago barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.…