Search

Found 69,853 results in 2756ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-5740 high 7.5 7.5 mattermost 15d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unaut…
CVE-2026-5308 high 7.5 7.5 mattermost 15d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a den…
CVE-2026-4646 medium 4.3 4.3 mattermost 15d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to cr…
CVE-2026-4635 medium 5.3 5.3 mattermost 15d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to c…
CVE-2026-3636 medium 4.3 4.3 mattermost 15d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allow…
CVE-2026-3473 high 7.1 7.1 mattermost 15d ago Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and down…
CVE-2026-9011 high 7.5 7.5 15d ago The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly…
CVE-2026-8692 medium 4.3 4.3 15d ago The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.1. This is due …
CVE-2026-8684 medium 5.3 5.3 15d ago The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is aut…
CVE-2026-8679 high 7.5 7.5 15d ago The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to temp…
CVE-2026-8381 medium 5.4 5.4 15d ago A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an a…
CVE-2026-7798 medium 5.4 5.4 15d ago The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions…
CVE-2026-7636 medium 4.3 4.3 15d ago The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. …
CVE-2026-7615 medium 4.3 4.3 15d ago The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widge…
CVE-2026-5072 medium 6.5 6.5 16d ago A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potential system crashes. An attacker sends a crafted PTP_MSG_MANAGEMENT message to se…
CVE-2026-9104 medium 6.4 6.4 16d ago The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output esc…
CVE-2026-9018 high 8.8 8.8 16d ago The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` …
CVE-2026-7509 medium 6.4 6.4 16d ago The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` attributes in all versions up to, and including, 4.0.…
CVE-2026-7249 medium 4.3 4.3 16d ago The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()`…
CVE-2026-6864 medium 6.1 6.1 16d ago The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.7 due to insufficient input sani…
CVE-2026-4070 medium 4.3 4.3 16d ago The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_manage() fun…
CVE-2026-44409 high 7.5 7.5 zte 16d ago There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the r…
CVE-2026-3481 medium 6.1 6.1 16d ago The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input saniti…
CVE-2026-2518 medium 4.3 4.3 16d ago The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' fun…
CVE-2026-4834 high 7.5 7.5 16d ago The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplie…
CVE-2026-46598 medium 5.3 5.3 FIX debian debian sleswindows windows golang 16d ago For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.
CVE-2026-46597 high 7.5 7.5 FIX debian debian sleswindows windows golang 16d ago An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVE-2026-39835 medium 5.3 5.3 FIX debian debian sleswindows windows golang 16d ago SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an…
CVE-2026-39829 high 7.5 7.5 FIX debian debian sleswindows windows golang 16d ago The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumptio…
CVE-2026-39828 medium 6.3 6.3 FIX debian debian sleswindows windows golang 16d ago When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as forc…
CVE-2026-39827 medium 6.5 6.5 FIX debian debian sleswindows windows golang 16d ago An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.…
CVE-2026-34911 high 7.7 7.7 16d ago A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat…
CVE-2026-46701 high 8.0 16d ago Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
CVE-2026-8435 medium 6.5 6.5 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4…
CVE-2026-8434 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4…
CVE-2026-8433 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score…
CVE-2026-8432 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score o…
CVE-2026-8427 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a…
CVE-2026-8416 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CV…
CVE-2026-8415 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVS…
CVE-2026-8414 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 scor…
CVE-2026-8413 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
CVE-2026-8412 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
CVE-2026-8411 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
CVE-2026-8410 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.…
CVE-2026-8409 high 8.8 8.8 concretecms 16d ago Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
CVE-2026-8337 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present on the site. An unau…
CVE-2026-8327 medium 4.3 4.3 concretecms 16d ago Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo…
CVE-2026-8245 medium 5.4 5.4 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL fi…
CVE-2026-8240 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configured summary template, revealing the existence of private, draft, and restricted …
CVE-2026-8239 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms existence and returns rating score for any message by ID. The Concrete CMS security …
CVE-2026-8238 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enume…
CVE-2026-8237 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns the full content of any conversation message. An unauthenticated attacker can enu…
CVE-2026-8236 medium 4.3 4.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system/dialogs/file/usage/{fID} accepts an integer file ID in the URL and returns int…
CVE-2026-8139 medium 5.4 5.4 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExternal bypasses being sanitized. The Concrete CMS security team gave this vulnera…
CVE-2026-7890 medium 6.4 6.4 concretecms 16d ago In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation enabling redirect-to-internal bypasses.  The Concrete CM…
CVE-2026-7887 medium 6.4 6.4 concretecms 16d ago For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 (suspended, banned, terminated employee) can still authenticate via OAuth and r…
CVE-2026-7886 medium 4.3 4.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lead to file permission bypass. The `AddMessage` and `UpdateMessage` conversation …
CVE-2026-7882 medium 4.3 4.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and procee…
CVE-2026-7881 medium 4.3 4.3 concretecms 16d ago Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via the exEntryID parameter. This IDOR leads to unauthorized access to all Express…
CVE-2026-7879 medium 5.3 5.3 concretecms 16d ago In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php allows unauthorized file access since downloading permission-restricted files bypa…
CVE-2026-5091 medium 5.1 5.1 FIX debian debian 16d ago Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess…
CVE-2026-4929 medium 5.4 5.4 simple_hierarchical_select_project 16d ago Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_fie…
CVE-2026-4093 medium 5.4 5.4 taxonomy_term_reference_tree_widget_project 16d ago In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token di…
CVE-2026-22678 medium 5.4 5.4 webmin 16d ago Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attack…
CVE-2026-46681 high 8.0 16d ago @nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
CVE-2026-46680 high 8.0 16d ago containerd user ID handling bypass allows runAsNonRoot evasion
CVE-2026-46679 high 8.0 16d ago js-libp2p: Memory DoS via subscription flood of unique topics
CVE-2026-46678 medium 5.5 16d ago Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
CVE-2026-46671 medium 5.5 16d ago Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
CVE-2026-46645 medium 5.5 16d ago SQLAdmin: Authorization Bypass on `ajax_lookup`
CVE-2026-46625 high 8.0 16d ago JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
CVE-2026-8428 high 8.8 8.8 concretecms 16d ago Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashb…
CVE-2026-8426 high 8.8 8.8 concretecms 16d ago Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package ret…
CVE-2026-8421 high 8.8 8.8 concretecms 16d ago Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticate…
CVE-2026-8417 high 8.8 8.8 concretecms 16d ago Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/da…
CVE-2026-8350 high 8.8 8.8 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access …
CVE-2026-8205 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being…
CVE-2026-8204 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot…
CVE-2026-8203 medium 5.4 5.4 concretecms 16d ago Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that execute…
CVE-2026-8197 medium 4.8 4.8 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation he…
CVE-2026-8140 medium 6.5 6.5 concretecms 16d ago Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dash…
CVE-2026-8135 high 7.2 7.2 concretecms 16d ago Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add …
CVE-2026-8134 high 7.2 7.2 concretecms 16d ago Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue a…
CVE-2026-6826 medium 5.3 5.3 concretecms 16d ago Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the usage controller.  Any unauthenticated visitor can request /ccm/system/dialogs…
CVE-2026-47102 high 8.8 8.8 litellm 16d ago LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restri…
CVE-2026-47101 high 8.8 8.8 litellm 16d ago LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored with…
CVE-2026-46673 high 8.0 16d ago Unbounded 32-bit allocation
CVE-2026-46609 medium 5.5 16d ago Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
CVE-2026-46556 medium 5.5 16d ago FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
CVE-2026-46552 medium 5.5 16d ago NocoDB: Shared-base link access can invite arbitrary users as persistent base members
CVE-2026-46551 medium 5.5 16d ago NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
CVE-2026-46550 medium 5.5 16d ago NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
CVE-2026-46548 medium 5.5 16d ago NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
CVE-2026-46547 medium 5.5 16d ago NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
CVE-2026-46519 high 8.0 16d ago MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
CVE-2026-46654 high 8.0 16d ago Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
CVE-2026-46643 high 8.0 16d ago Snappy: Binary path is never shell-escaped due to an inverted is_executable check
CVE-2026-46683 medium 5.5 16d ago Snappy : SSRF and local file read via the xsl-style-sheet option
CVE-2026-46618 medium 5.5 16d ago Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables