Search

Found 41,691 results in 6651ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8201 high 8.8 8.8 mongodb 25d ago A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability req…
CVE-2026-8053 high 8.8 8.8 mongodb 25d ago An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issu…
CVE-2026-6888 high 7.2 7.2 25d ago Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to acc…
CVE-2026-44697 high 8.6 8.6 25d ago Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any p…
CVE-2026-44672 critical 9.5 25d ago mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dyna…
CVE-2026-43660 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-43658 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-40164 high 7.5 7.5 FIX rheldebian debian sles 25d ago Important: jq security update
CVE-2026-39979 high 8.0 FIX rheldebian debian sles 25d ago Important: jq security update
CVE-2026-28962 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28955 high 8.8 8.8 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28953 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28947 high 8.8 8.8 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28944 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28913 high 7.5 7.5 FIX safari iosmacos macos 25d ago watchOS 26.5
CVE-2026-28907 high 8.1 8.1 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28905 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28904 high 7.5 7.5 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-28883 high 7.5 7.5 FIX ios safarimacos macos 25d ago visionOS 26.5
CVE-2026-28847 high 8.8 8.8 FIX safari iosmacos macos 25d ago visionOS 26.5
CVE-2026-8108 high 7.8 7.8 25d ago The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
CVE-2026-5371 high 7.1 7.1 25d ago The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability…
CVE-2026-44548 high 8.1 8.1 25d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDele…
CVE-2026-44547 critical 9.6 9.6 25d ago ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/publ…
CVE-2026-43685 high 7.2 7.2 claris 25d ago A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input in the External OD…
CVE-2026-43680 high 7.2 7.2 claris 25d ago A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and execute arbitrary operat…
CVE-2026-42289 high 8.8 8.8 25d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token valid…
CVE-2026-42288 critical 10.0 10.0 25d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard …
CVE-2026-41901 critical 9.0 9.0 25d ago Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
CVE-2026-1250 high 7.5 7.5 25d ago The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.10.11 due to insuf…
CVE-2026-44660 high 7.5 7.5 debian debian ultrajson_project 25d ago UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an excepti…
CVE-2026-44650 critical 9.1 9.1 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44649 critical 9.8 9.8 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44648 high 7.5 7.5 25d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44594 high 7.5 7.5 25d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the browser field in…
CVE-2026-44593 critical 9.5 25d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ulti…
CVE-2026-45227 high 8.8 8.8 25d ago Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspec…
CVE-2026-45226 high 7.1 7.1 25d ago Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without pro…
CVE-2026-45225 high 7.6 7.6 25d ago Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted…
CVE-2026-44871 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
CVE-2026-44302 high 7.5 7.5 25d ago Snappier has an infinite loop during SnappyStream decompression with malformed framed input
CVE-2026-44301 high 8.1 8.1 FIX debian debian gohugo 25d ago Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools with…
CVE-2026-44296 high 7.5 7.5 FIX debian debian 25d ago Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). Whe…
CVE-2026-44260 high 8.1 8.1 25d ago efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk en…
CVE-2026-44241 high 7.5 7.5 25d ago Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header
CVE-2026-44015 critical 9.9 9.9 nginxui 25d ago Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
CVE-2026-43948 critical 9.9 9.9 25d ago wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVE-2026-42855 high 7.5 7.5 espressif 25d ago arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp…
CVE-2026-42854 critical 9.8 9.8 espressif 25d ago arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a …
CVE-2026-42544 high 7.5 7.5 25d ago Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
CVE-2026-42268 high 7.5 7.5 FIX slesdebian debian owasp 25d ago ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused …
CVE-2026-26289 high 8.2 8.2 25d ago PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions …
CVE-2026-44403 high 7.2 8.2 EXP wftpserver 25d ago Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code…
CVE-2026-44246 high 7.2 7.2 dkfz 25d ago nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable…
CVE-2026-44240 high 7.5 7.5 FIX debian debian 25d ago basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
CVE-2026-44232 high 8.0 25d ago dssrf: every IPv6 category bypasses is_url_safe
CVE-2026-44224 high 8.8 8.8 requarks 25d ago Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation o…
CVE-2025-65088 high 7.8 7.8 ashlar 25d ago An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information o…
CVE-2025-65087 high 7.8 7.8 ashlar 25d ago An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information o…
CVE-2025-65086 high 7.8 7.8 ashlar 25d ago An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary cod…
CVE-2026-7474 high 8.8 8.8 25d ago HashiCorp Nomad vulnerable to a path traversal
CVE-2026-45185 critical 9.8 9.8 FIX debian debian sles exim 25d ago Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a C…
CVE-2026-44872 high 7.2 7.2 arubanetworks 25d ago A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arb…
CVE-2026-44870 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
CVE-2026-44869 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44868 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44867 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44866 high 8.8 8.8 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44865 high 7.2 7.2 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
CVE-2026-44864 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44863 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44862 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44861 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44860 high 7.2 7.2 arubanetworks 25d ago SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with adm…
CVE-2026-44859 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44858 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44857 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44856 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44855 high 7.2 7.2 arubanetworks 25d ago Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authent…
CVE-2026-44854 high 7.2 7.2 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arb…
CVE-2026-44853 high 7.2 7.2 arubanetworks 25d ago Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arb…
CVE-2026-44852 high 7.2 7.2 arubanetworks 25d ago An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authentica…
CVE-2026-44225 critical 9.3 9.3 25d ago Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the …
CVE-2026-44222 high 7.5 7.5 vllm 25d ago vLLM Vulnerable to Remote DoS via Special-Token Placeholders
CVE-2026-44221 critical 9.0 9.0 25d ago ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
CVE-2026-44215 high 7.1 7.1 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is …
CVE-2026-42889 critical 9.1 9.1 25d ago Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured…
CVE-2026-42446 high 7.1 7.1 m2team 25d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerability is triggered …
CVE-2026-42191 high 7.8 7.8 opentelemetry 25d ago OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
CVE-2026-34690 high 7.8 7.8 macos macos adobe 25d ago After Effects versions 26.0, 25.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…
CVE-2026-34686 high 8.7 8.7 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-pr…
CVE-2026-34665 high 7.5 7.5 adobe 25d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34653 high 8.7 8.7 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') …
CVE-2026-34652 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result i…
CVE-2026-34651 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34650 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34649 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34648 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application …
CVE-2026-34647 high 7.4 7.4 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security…
CVE-2026-34646 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature b…