Search

Found 33,076 results in 1452ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-2614 high 7.5 7.5 lfprojects 26d ago MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2026-41489 high 8.8 8.8 26d ago Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by s…
CVE-2026-37630 high 7.3 7.3 FIX debian debian 26d ago An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
CVE-2026-28910 low 3.3 3.3 FIX macos macos 26d ago macOS Tahoe 26.4
CVE-2026-28860 high 7.5 7.5 FIX macos macos ios tvos 26d ago visionOS 26.4
CVE-2026-8321 high 7.3 7.3 26d ago A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. P…
CVE-2026-42874 low 3.7 3.7 26d ago Microdot has HTTP response splitting in Response.set_cookie()
CVE-2026-36734 high 8.8 8.8 26d ago EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient…
CVE-2022-4988 high 7.3 7.3 26d ago Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…
CVE-2026-44657 high 8.0 26d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execu…
CVE-2026-44655 high 8.0 26d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator acces…
CVE-2026-42071 high 8.0 26d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to…
CVE-2026-40607 high 8.0 26d ago MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
CVE-2026-40597 high 8.0 26d ago MantisBT has a Content Security Policy bypass via attachments
CVE-2026-40596 high 8.0 26d ago MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
CVE-2026-39850 high 7.4 7.4 26d ago Yii 2: Local file inclusion via view parameter name collision
CVE-2026-34463 high 8.0 26d ago MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
CVE-2026-7790 high 7.5 7.5 debian debianwindows windows ninenines 26d ago Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number …
CVE-2026-45224 high 7.1 7.1 26d ago Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolution
CVE-2026-45223 high 8.8 8.8 26d ago Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin …
CVE-2026-43969 low 3.2 3.2 FIX debian debianwindows windows ninenines 26d ago cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-2393 high 7.1 7.1 lfprojects 26d ago MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-7818 high 7.8 7.8 sles pgadmin 26d ago pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
CVE-2026-31253 high 7.3 7.3 26d ago flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism
CVE-2026-5172 high 7.3 7.3 FIX debian debian sleswindows windows 26d ago A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advanc…
CVE-2026-45006 high 8.8 8.8 openclaw 26d ago OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration…
CVE-2026-45004 high 7.8 7.8 openclaw 26d ago OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
CVE-2026-45001 high 7.1 7.1 openclaw 26d ago OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox p…
CVE-2026-44996 low 3.7 3.7 openclaw 26d ago OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence ag…
CVE-2026-44995 high 7.3 7.3 openclaw 26d ago OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
CVE-2026-44658 low 2.4 2.4 26d ago Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same r…
CVE-2026-44413 high 7.5 7.5 jetbrains 26d ago In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-43640 high 8.1 8.1 bitwarden 26d ago Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management …
CVE-2026-42856 high 8.0 26d ago Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
CVE-2026-42313 high 8.3 8.3 pyload-ng_project 26d ago pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …
CVE-2026-41431 high 8.0 8.0 26d ago Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Fi…
CVE-2026-3609 high 7.8 7.8 wellbia 26d ago Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cr…
CVE-2026-38568 high 8.1 8.1 26d ago HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve …
CVE-2026-38566 high 8.1 8.1 26d ago HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission …
CVE-2026-36983 high 7.3 7.3 26d ago D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.
CVE-2026-36962 high 7.3 7.3 26d ago SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution…
CVE-2026-34094 low 3.8 3.8 FIX debian debian mediawiki 26d ago Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-30635 high 8.1 8.1 26d ago automagik-genie has a command injection vulnerability
CVE-2026-42603 high 8.8 8.8 26d ago OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_ta…
CVE-2026-42349 high 8.1 8.1 clerk 26d ago Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other…
CVE-2026-33362 high 8.6 8.6 26d ago In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded an…
CVE-2026-33361 high 7.5 7.5 26d ago In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversi…
CVE-2026-33359 high 7.5 7.5 26d ago In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforce…
CVE-2026-33357 high 7.5 7.5 26d ago In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearic…
CVE-2026-33356 high 7.7 7.7 26d ago In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. …
CVE-2026-31254 high 7.3 7.3 26d ago The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python …
CVE-2026-31251 high 7.3 7.3 26d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads…
CVE-2026-31250 high 7.3 7.3 26d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads…
CVE-2026-31249 high 7.3 7.3 26d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script l…
CVE-2026-31248 high 7.5 7.5 26d ago Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-7819 high 8.1 8.1 sles pgadmin 26d ago pgAdmin 4 File Manager has symbolic-link path traversal
CVE-2026-7816 high 8.8 8.8 sles pgadmin 26d ago pgAdmin 4: OS command injection vulnerability in Import/Export query export
CVE-2026-7815 high 8.8 8.8 sles pgadmin 26d ago SQL injection vulnerability in pgAdmin 4 Maintenance Tool
CVE-2026-34092 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue…
CVE-2026-34091 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34090 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.
CVE-2026-34088 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34087 high 7.5 7.5 FIX debian debian mediawiki 26d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-31247 high 7.5 7.5 26d ago Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2025-65418 high 7.5 7.5 26d ago docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
CVE-2025-61314 high 7.3 7.3 26d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in…
CVE-2025-61313 high 7.3 7.3 26d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascrip…
CVE-2025-61312 high 7.3 7.3 26d ago A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in …
CVE-2025-61311 high 7.3 7.3 26d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in t…
CVE-2026-44543 high 8.7 8.7 26d ago Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in …
CVE-2026-44521 high 8.8 8.8 26d ago elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…
CVE-2026-45017 high 7.5 7.5 jg-rp 27d ago Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search pa…
CVE-2026-44345 high 8.8 8.8 bentoml 27d ago BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
CVE-2026-44338 high 7.3 7.3 praison 27d ago PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-4802 high 8.0 8.0 FIX debian debian rhel sles 27d ago A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links i…
CVE-2025-9973 high 7.2 7.2 wso2 27d ago Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations.…
CVE-2025-10470 high 8.6 8.6 wso2 27d ago The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerabilit…
CVE-2026-41951 high 7.2 7.2 27d ago Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
CVE-2026-40636 high 7.8 7.8 dell 27d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could p…
CVE-2026-32658 high 8.8 8.8 dell 27d ago Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …
CVE-2025-8325 high 8.8 8.8 wso2 27d ago The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This…
CVE-2025-8154 high 7.5 7.5 wso2 27d ago In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses…
CVE-2025-10908 high 7.3 7.3 wso2 27d ago Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security …
CVE-2026-43500 high 7.8 8.8 EXPFIX slesdebian debian linux-kernel 27d ago In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and th…
CVE-2026-8276 low 3.7 3.7 debian debian sles 27d ago bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go
CVE-2026-8275 low 3.7 3.7 debian debian 27d ago bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
CVE-2026-6433 high 7.3 7.3 27d ago The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execut…
CVE-2026-8273 high 7.2 7.2 27d ago A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation caus…
CVE-2026-8272 high 7.2 7.2 27d ago A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os comma…
CVE-2026-8271 high 7.2 7.2 27d ago A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the f…
CVE-2026-8265 high 7.2 7.2 27d ago A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the…
CVE-2026-8264 high 8.8 8.8 27d ago A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation …
CVE-2026-8262 low 2.4 2.4 27d ago A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack ma…
CVE-2026-8260 high 8.8 8.8 27d ago A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipu…
CVE-2026-8259 high 7.2 7.2 27d ago A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip lea…
CVE-2026-8256 low 2.4 2.4 27d ago A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scriptin…
CVE-2026-8255 low 2.4 2.4 27d ago A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack c…
CVE-2026-8254 low 2.4 2.4 27d ago A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross si…
CVE-2026-8253 low 2.4 2.4 27d ago A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross …
CVE-2026-43668 high 7.5 7.5 FIX iosmacos macos tvos 27d ago visionOS 26.5