Search

Found 49,600 results in 2094ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8621 high 8.8 8.8 23d ago Crabbox: authentication bypass vulnerability that allows impersonation of others by spoofing identity headers
CVE-2026-45371 high 8.0 23d ago SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
CVE-2026-44633 high 8.1 8.1 23d ago Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in …
CVE-2026-44586 high 8.3 8.3 23d ago SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML wit…
CVE-2026-44522 high 8.0 23d ago Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution
CVE-2026-27886 high 7.5 7.5 strapi 23d ago Strapi may leak sensitive data via relational filtering due to lack of query sanitization
CVE-2026-23998 high 7.5 7.5 fleetdm 23d ago Fleet has a Windows MDM management endpoint authentication bypass
CVE-2026-22599 high 7.2 7.2 strapi 23d ago Strapi Vulnerable to SQL Injection in Content Type Builder
CVE-2026-44541 high 8.0 23d ago ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
CVE-2026-45011 high 8.0 23d ago Apostrophe has stored XSS via javascript: URL in Image Widget Link
CVE-2026-45013 high 8.0 23d ago Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
CVE-2026-45012 high 8.0 23d ago Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
CVE-2026-44973 high 8.1 8.1 debian debian 23d ago Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcem…
CVE-2026-6332 high 7.5 7.5 schneider-electric 23d ago CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of …
CVE-2026-42897 high 8.1 9.6 KEV windows windows microsoft 23d ago Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42334 high 7.5 7.5 mongoosejs 23d ago Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
CVE-2025-15024 high 8.8 8.8 23d ago Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System …
CVE-2025-15023 high 8.8 8.8 23d ago Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploiting Incorrectly Conf…
CVE-2026-44827 high 8.8 8.8 huggingface 23d ago Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVE-2026-44516 high 7.6 7.6 23d ago Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
CVE-2026-44513 high 8.8 8.8 huggingface 23d ago Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVE-2026-20224 high 8.6 8.6 23d ago A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system.…
CVE-2026-44883 high 7.5 7.5 portainer 23d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-44849 high 8.8 8.8 portainer 23d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-44882 high 8.1 8.1 portainer 23d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-44850 high 8.5 8.5 portainer 23d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-44848 high 8.8 8.8 portainer 23d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-46480 high 8.0 23d ago FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
CVE-2026-46479 high 8.0 23d ago FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
CVE-2026-46478 high 8.0 23d ago FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
CVE-2026-46477 high 8.0 23d ago FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
CVE-2026-46476 high 8.0 23d ago FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
CVE-2026-46475 high 8.0 23d ago FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
CVE-2026-46444 high 8.0 23d ago FlowiseAI: Vector Store No Permission Checks
CVE-2026-45732 high 8.0 23d ago n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVE-2026-44792 high 8.0 23d ago n8n Has a Source Control Pull SQL Injection
CVE-2026-43978 high 8.0 23d ago wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
CVE-2026-44504 high 8.0 23d ago Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-44501 high 7.1 7.1 datahub 23d ago DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the…
CVE-2026-42595 high 8.6 8.6 thecodingmachine 23d ago Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
CVE-2026-42594 high 7.5 7.5 thecodingmachine 23d ago Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
CVE-2026-42591 high 8.2 8.2 thecodingmachine 23d ago Gotenberg has a Server-Side Request Forgery (SSRF) Issue
CVE-2026-42590 high 8.2 8.2 thecodingmachine 23d ago Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
CVE-2026-42283 high 7.8 7.8 devspace 23d ago DevSpace UI Server WebSocket CheckOrigin does not validate source
CVE-2026-42281 high 8.6 8.6 magicmirror 23d ago MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint
CVE-2026-43977 high 8.0 23d ago wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
CVE-2026-40893 high 8.2 8.2 thecodingmachine 23d ago Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move
CVE-2026-44375 high 7.5 7.5 23d ago Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
CVE-2026-42186 high 7.5 7.5 openbao 23d ago OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-41937 high 7.2 7.2 23d ago Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP f…
CVE-2026-41935 high 7.1 7.1 23d ago Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base::init() repeatedly invokes permission() on error handlers, causing infinite rec…
CVE-2026-24712 high 7.3 7.3 debian debian northern.tech 23d ago Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
CVE-2026-46443 high 8.0 23d ago FlowiseAI Vulnerable to Credential Data Leak
CVE-2026-46441 high 8.0 23d ago FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-46440 high 8.0 23d ago FlowiseAI Exposes Basic Auth Credentials via API
CVE-2026-42863 high 8.0 23d ago FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
CVE-2026-42862 high 8.0 23d ago FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-42861 high 8.0 23d ago FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
CVE-2026-6638 high 8.8 8.8 FIX slesdebian debianwindows windows postgresql 23d ago SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credenti…
CVE-2026-6637 high 8.8 8.8 FIX slesdebian debianwindows windows postgresql 23d ago Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if…
CVE-2026-6479 high 7.5 7.5 FIX slesdebian debianwindows windows postgresql 23d ago Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disable…
CVE-2026-6477 high 8.8 8.8 FIX slesdebian debianwindows windows postgresql 23d ago Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a cli…
CVE-2026-6476 high 7.2 7.2 FIX slesdebian debian postgresql 23d ago SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next r…
CVE-2026-6475 high 8.8 8.8 FIX slesdebian debianwindows windows postgresql 23d ago Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system accou…
CVE-2026-6473 high 8.8 8.8 FIX slesdebian debianwindows windows postgresql 23d ago Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code…
CVE-2025-15025 high 8.8 8.8 23d ago Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Ex…
CVE-2026-41249 high 8.2 8.2 23d ago CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dan…
CVE-2026-4031 high 7.5 7.5 23d ago The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db…
CVE-2026-4030 high 8.1 8.1 23d ago The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not proper…
CVE-2026-4029 high 7.5 7.5 23d ago The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the …
CVE-2025-12008 high 8.8 8.8 23d ago Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This i…
CVE-2026-8295 unknown windows windows 24d ago An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on p…
CVE-2026-8468 high 8.0 24d ago Plug: Unbounded buffer accumulation in multipart header parsing causes denial of service
CVE-2026-6514 high 7.5 7.5 24d ago The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to …
CVE-2026-6506 high 8.8 8.8 24d ago The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization …
CVE-2026-5395 high 8.2 8.2 24d ago The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,…
CVE-2026-3892 high 8.1 8.1 24d ago The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file …
CVE-2026-3718 high 7.2 7.2 24d ago The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insuffici…
CVE-2026-5396 high 8.2 8.2 24d ago The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authori…
CVE-2026-1659 high 7.5 7.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause d…
CVE-2026-1322 high 8.1 8.1 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read…
CVE-2026-1184 high 7.5 7.5 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause den…
CVE-2025-14870 high 7.5 7.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause …
CVE-2025-14869 high 7.5 7.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause …
CVE-2026-46446 high 7.1 7.1 FIX debian debian 24d ago SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
CVE-2026-46445 high 7.1 7.1 FIX debian debian 24d ago SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
CVE-2026-46419 high 7.5 7.5 24d ago Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
CVE-2026-32991 high 7.1 7.1 24d ago Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.
CVE-2026-29206 high 8.1 8.1 24d ago Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.
CVE-2026-44478 high 7.5 7.5 24d ago hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingComplete…
CVE-2026-44471 high 7.8 7.8 FIX debian debian gitoxidelabs 24d ago gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink int…
CVE-2026-44447 high 7.5 7.5 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious…
CVE-2026-44446 high 7.5 7.5 frappe 24d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would all…
CVE-2026-42463 high 8.1 8.1 fit2cloud 24d ago SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass …
CVE-2026-32993 high 8.3 8.3 24d ago Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
CVE-2026-32992 high 8.2 8.2 24d ago SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
CVE-2026-29205 high 8.6 8.6 24d ago Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
CVE-2026-8328 unknown slesdebian debianwindows windows 24d ago The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpee…
CVE-2026-45708 high 7.2 7.2 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. The next time any admin clicks Print on any order,…
CVE-2026-45229 high 8.8 8.8 24d ago Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui…