Search

Found 58,591 results in 2491ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44581 medium 4.7 4.7 vercel 25d ago Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
CVE-2026-44580 medium 6.1 6.1 vercel 25d ago Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
CVE-2026-44009 critical 9.8 9.8 vm2_project 25d ago vm2 has Sandbox Breakout Through Null Proto Exception
CVE-2026-44008 critical 9.8 9.8 vm2_project 25d ago vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-44007 critical 9.1 9.1 vm2_project 25d ago vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
CVE-2026-44006 critical 10.0 10.0 vm2_project 25d ago vm2 has a Sandbox Escape Vulnerability
CVE-2026-44005 critical 10.0 10.0 vm2_project 25d ago vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
CVE-2026-44003 medium 5.8 5.8 vm2_project 25d ago vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
CVE-2026-44002 medium 5.8 5.8 vm2_project 25d ago vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
CVE-2026-43999 critical 9.9 9.9 vm2_project 25d ago vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
CVE-2026-43997 critical 10.0 10.0 vm2_project 25d ago vm2 Access to Host Object Enables Sandbox Escape
CVE-2026-44577 medium 5.9 5.9 vercel 25d ago Next.js has a Denial of Service in the Image Optimization API
CVE-2026-44576 medium 5.4 5.4 vercel 25d ago Next.js vulnerable to cache poisoning in React Server Component responses
CVE-2026-2695 medium 6.3 6.3 25d ago A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users…
CVE-2024-48519 medium 6.2 6.2 25d ago Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRo…
CVE-2026-8367 medium 4.8 4.8 debian debian 25d ago aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be ab…
CVE-2026-45028 medium 6.1 6.1 astro 25d ago Astro: Server island encrypted parameters vulnerable to cross-component replay
CVE-2026-44665 medium 6.1 6.1 25d ago fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
CVE-2026-44664 medium 6.1 6.1 25d ago fast-xml-builder Comment Value regex can be bypassed
CVE-2026-44572 medium 5.9 5.9 vercel 25d ago Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-44479 medium 5.5 5.5 vercel 25d ago Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), comma…
CVE-2026-44467 medium 6.8 6.8 anthropic 25d ago The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development fea…
CVE-2026-44459 low 3.8 3.8 hono 25d ago Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-44458 medium 4.3 4.3 hono 25d ago Hono has CSS Declaration Injection via Style Object Values in JSX SSR
CVE-2026-44457 medium 5.3 5.3 hono 25d ago Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
CVE-2026-44456 medium 6.5 6.5 hono 25d ago Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
CVE-2026-44455 medium 6.1 6.1 hono 25d ago hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
CVE-2026-44431 medium 5.3 5.3 slesdebian debianwindows windows pythongoogle 25d ago urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fa…
CVE-2026-44294 medium 5.3 5.3 protobufjs_project 25d ago protobuf.js: Denial of service from crafted field names in generated code
CVE-2026-44292 medium 5.3 5.3 protobufjs_project 25d ago protobuf.js: Prototype injection in generated message constructors
CVE-2026-44288 medium 5.3 5.3 protobufjs_project 25d ago protobufjs has overlong UTF-8 decoding
CVE-2026-42946 medium 6.5 6.5 FIX slesdebian debianwindows windows 25d ago A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured…
CVE-2026-42937 medium 6.5 6.5 25d ago Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attack…
CVE-2026-42934 medium 4.8 4.8 FIX slesdebian debianwindows windows 25d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives ar…
CVE-2026-42926 medium 5.8 5.8 FIX slesdebian debian 25d ago When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the…
CVE-2026-42919 medium 6.7 6.7 25d ago A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a secur…
CVE-2026-42781 medium 6.5 6.5 25d ago When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utiliz…
CVE-2026-42780 medium 4.9 4.9 25d ago A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software …
CVE-2026-42557 critical 9.6 9.6 debian debian jupyter 25d ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlink…
CVE-2026-42408 medium 4.4 4.4 25d ago When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Soft…
CVE-2026-42063 medium 4.9 4.9 25d ago A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files.  Note: Software versions which have reached…
CVE-2026-42058 medium 4.3 4.3 25d ago An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names.  Note: Software versions which have reached End of Technic…
CVE-2026-41959 medium 6.5 6.5 25d ago Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated…
CVE-2026-41954 medium 4.9 4.9 25d ago Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator rol…
CVE-2026-41225 critical 9.1 9.1 25d ago A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note…
CVE-2026-41219 medium 6.5 6.5 25d ago An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which ha…
CVE-2026-40703 medium 5.4 5.4 25d ago A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not eval…
CVE-2026-40701 medium 4.8 4.8 FIX slesdebian debianwindows windows 25d ago NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or…
CVE-2026-40699 medium 6.5 6.5 25d ago A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information.  Note: Software ver…
CVE-2026-40462 medium 6.5 6.5 25d ago Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information.  Note: Softwa…
CVE-2026-40460 medium 6.5 6.5 FIX slesdebian debianwindows windows 25d ago When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limi…
CVE-2026-40435 medium 5.3 5.3 25d ago When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Su…
CVE-2026-36742 medium 6.8 6.8 25d ago Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).
CVE-2026-36738 medium 6.8 6.8 25d ago U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control me…
CVE-2026-35062 medium 6.5 6.5 25d ago An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-34019 medium 5.3 5.3 25d ago When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD pack…
CVE-2026-31156 medium 6.5 6.5 25d ago A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path …
CVE-2026-28758 medium 4.4 4.4 25d ago When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is als…
CVE-2026-24464 medium 6.8 6.8 25d ago When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cros…
CVE-2025-32425 medium 5.5 5.5 agpt 25d ago AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. In AutoGPT, the execution process is recorded to the c…
CVE-2025-29338 medium 5.6 5.6 25d ago NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_para parameter in the woal_init_module_param function.
CVE-2024-51395 medium 6.2 6.2 25d ago Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio…
CVE-2024-51394 medium 5.5 5.5 25d ago Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp c…
CVE-2020-37225 medium 6.4 6.4 25d ago Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in…
CVE-2020-37217 medium 4.3 4.3 25d ago Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts by tricking authenticated administrators into visiting malicious pages. Attack…
CVE-2020-37174 medium 5.5 5.5 25d ago WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design …
CVE-2020-37169 medium 5.5 5.5 25d ago WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-u…
CVE-2020-37168 critical 9.8 9.8 25d ago Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. A…
CVE-2026-45083 critical 9.8 9.8 25d ago The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted …
CVE-2026-44796 medium 6.5 6.5 networktocode 25d ago Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to a…
CVE-2026-44794 medium 5.4 5.4 networktocode 25d ago Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to referen…
CVE-2026-44740 medium 6.5 6.5 debian debian sles 25d ago Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loo…
CVE-2026-8463 medium 5.3 5.3 FIX debian debian leont 25d ago Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the…
CVE-2026-4608 medium 6.5 6.5 25d ago The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insuffic…
CVE-2026-4607 medium 4.3 4.3 25d ago The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properl…
CVE-2026-37429 medium 6.5 6.5 25d ago qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vulnerability allows attackers to access sensitive dat…
CVE-2026-37428 medium 6.5 6.5 25d ago qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive dat…
CVE-2026-42961 medium 4.3 4.3 25d ago ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to…
CVE-2026-42950 medium 4.3 4.3 25d ago ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may be…
CVE-2026-42948 medium 4.8 4.8 25d ago Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another adminis…
CVE-2026-42062 critical 9.8 9.8 25d ago ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authenticati…
CVE-2026-40621 critical 9.8 9.8 25d ago ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
CVE-2026-3426 medium 4.3 4.3 25d ago The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all …
CVE-2026-25107 medium 6.5 6.5 25d ago ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of…
CVE-2026-7168 medium 5.3 5.3 FIX debian debian sleswindows windows haxxgoogle 25d ago Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reu…
CVE-2026-7009 medium 5.3 5.3 FIX debian debian sles haxxgoogle 25d ago When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and inste…
CVE-2026-6429 medium 5.3 5.3 FIX debian debian sleswindows windows haxxgoogle 25d ago When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
CVE-2026-6253 medium 5.9 5.9 FIX debian debian sleswindows windows haxxgoogle 25d ago curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for differ…
CVE-2026-5545 medium 6.5 6.5 FIX debian debian sleswindows windows haxxgoogle 25d ago libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a …
CVE-2026-4873 medium 5.9 5.9 FIX debian debian sleswindows windows haxxgoogle 25d ago A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SM…
CVE-2026-4782 medium 6.5 6.5 25d ago The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of…
CVE-2026-41051 medium 5.0 5.0 FIX debian debian sles 25d ago csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
CVE-2026-2515 medium 5.3 5.3 25d ago The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' fu…
CVE-2026-41050 critical 9.9 9.9 25d ago Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVE-2026-3004 medium 6.4 6.4 25d ago The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute in all versions up to, and including, 24.1.11 due to insufficient input sanitiz…
CVE-2025-14767 medium 5.5 5.5 25d ago The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and inc…
CVE-2026-6965 medium 5.3 5.3 25d ago The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.9.9. This is due to the `get_course_id_by…
CVE-2026-32661 critical 9.8 9.8 25d ago Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's…
CVE-2026-21022 medium 5.5 5.5 25d ago Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21021 medium 6.8 6.8 25d ago Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.