Search

Found 54,189 results in 2495ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-29775 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-28971 medium 4.3 4.3 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28958 medium 5.5 5.5 FIX ios safarimacos macos 25d ago visionOS 26.5
CVE-2026-28946 medium 6.5 6.5 FIX safarimacos macos sles 25d ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari…
CVE-2026-28942 medium 6.5 6.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28917 medium 4.3 4.3 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28903 medium 6.5 6.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28902 medium 6.5 6.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28901 medium 4.3 4.3 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-27951 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-26986 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-25952 medium 5.5 FIX rheldebian debian sles 25d ago Moderate: freerdp security update
CVE-2026-44547 critical 9.6 9.6 25d ago ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/publ…
CVE-2026-44347 medium 6.5 6.5 warpgate_project 25d ago Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user in…
CVE-2026-44341 medium 5.3 5.3 25d ago GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. Th…
CVE-2026-44245 medium 6.1 6.1 kyverno 25d ago Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
CVE-2026-42288 critical 10.0 10.0 25d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard …
CVE-2026-41901 critical 9.0 9.0 25d ago Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
CVE-2025-15463 medium 6.5 6.5 25d ago The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users …
CVE-2026-44652 medium 5.5 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44651 medium 5.5 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44650 critical 9.1 9.1 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44649 critical 9.8 9.8 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44593 critical 9.5 25d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ulti…
CVE-2026-44305 medium 6.8 6.8 25d ago Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
CVE-2026-44259 medium 4.6 4.6 25d ago efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security heade…
CVE-2026-44015 critical 9.9 9.9 nginxui 25d ago Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
CVE-2026-43948 critical 9.9 9.9 25d ago wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVE-2026-42854 critical 9.8 9.8 espressif 25d ago arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a …
CVE-2026-42545 medium 5.9 5.9 25d ago Granian vulnerable to DoS via WSGI response header panic
CVE-2026-41195 medium 5.0 5.0 25d ago mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker…
CVE-2026-35555 medium 6.3 6.3 25d ago PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
CVE-2026-33570 medium 5.7 5.7 25d ago PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.
CVE-2026-35504 medium 5.5 5.5 25d ago PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
CVE-2026-8052 medium 6.0 6.0 25d ago HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack
CVE-2026-6959 medium 6.0 6.0 25d ago HashiCorp Nomad vulnerable to symlink attack
CVE-2026-45185 critical 9.8 9.8 FIX debian debian sles exim 25d ago Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a C…
CVE-2026-44874 medium 4.9 4.9 25d ago A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Succe…
CVE-2026-44873 medium 5.4 5.4 arubanetworks 25d ago A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated wh…
CVE-2026-44225 critical 9.3 9.3 25d ago Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the …
CVE-2026-44223 medium 6.5 6.5 vllm 25d ago vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect sh…
CVE-2026-44221 critical 9.0 9.0 25d ago ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
CVE-2026-44217 medium 5.5 25d ago sse-channel: SSE Injection via unsanitized event fields
CVE-2026-42889 critical 9.1 9.1 25d ago Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured…
CVE-2026-42445 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPat…
CVE-2026-42444 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method re…
CVE-2026-42443 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when …
CVE-2026-42442 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when…
CVE-2026-42355 medium 5.5 5.5 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .…
CVE-2026-42338 medium 6.1 6.1 debian debian beaugunderson 25d ago ip-address has XSS in Address6 HTML-emitting methods
CVE-2026-34688 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34680 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…
CVE-2026-34679 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34678 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34677 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34673 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34672 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…
CVE-2026-34671 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…
CVE-2026-34670 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34669 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34668 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34667 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…
CVE-2026-34666 medium 6.2 6.2 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34658 medium 4.8 4.8 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…
CVE-2026-34656 medium 4.3 4.3 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature by…
CVE-2026-34655 medium 4.8 4.8 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…
CVE-2026-34654 medium 5.3 5.3 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result i…
CVE-2026-34664 medium 6.3 6.3 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file sy…
CVE-2026-34660 critical 9.3 9.3 adobe 25d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An …
CVE-2026-34659 critical 9.6 9.6 adobe 25d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current …
CVE-2026-23822 medium 5.3 5.3 25d ago A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…
CVE-2026-5146 medium 4.3 4.3 devolutions 25d ago Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session v…
CVE-2026-44343 critical 9.8 9.8 wgdashboard 25d ago WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file sys…
CVE-2026-44279 medium 5.5 5.5 fortinet 25d ago A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow atta…
CVE-2026-44278 medium 5.5 5.5 fortinet 25d ago A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert at…
CVE-2026-44277 critical 9.1 9.1 fortinet 25d ago A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attack…
CVE-2026-44204 medium 6.5 6.5 25d ago Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role)…
CVE-2026-44196 critical 9.1 9.1 25d ago Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and …
CVE-2026-44183 critical 9.8 9.8 25d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.…
CVE-2026-42898 critical 9.9 9.9 windows windows microsoft 25d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42891 medium 6.5 6.5 windows windows microsoft 25d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42838 medium 5.4 5.4 windows windows microsoft 25d ago Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a netw…
CVE-2026-42833 critical 9.1 9.1 windows windows microsoft 25d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42830 medium 6.5 6.5 windows windows microsoft 25d ago Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42823 critical 9.9 9.9 windows windows microsoft 25d ago Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42541 medium 4.3 4.3 25d ago Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
CVE-2026-42303 medium 5.5 25d ago Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-42300 critical 9.5 25d ago DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
CVE-2026-42177 medium 5.3 5.3 FIX debian debian 25d ago linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter i…
CVE-2026-42175 medium 6.5 6.5 25d ago requests-hardened is Vulnerable to Server-Side Request Forgery
CVE-2026-42048 critical 9.6 9.6 langflow 25d ago Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-42045 medium 6.2 6.2 25d ago LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
CVE-2026-41614 medium 6.2 6.2 windows windows microsoft 25d ago Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41612 medium 5.5 5.5 windows windows microsoft 25d ago Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
CVE-2026-41610 medium 6.3 6.3 windows windows microsoft 25d ago Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-41103 critical 9.1 9.1 windows windows microsoft 25d ago Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira &amp; Confluence allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41100 medium 4.4 4.4 windows windows microsoft 25d ago Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-41097 medium 6.7 6.7 FIX windows windows 25d ago Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-41096 critical 9.8 9.8 FIX windows windows 25d ago Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-41089 critical 9.8 9.8 FIX windows windows 25d ago Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.