Search

Found 38,471 results in 2536ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-5652 critical 9.0 9.0 craftycontrol 2mo ago An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permiss…
CVE-2026-40279 low 3.7 3.7 bacnetstack 2mo ago BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacnet/bacint.c reconstructs a 32-bit signed integer from four APDU bytes …
CVE-2026-32613 unknown 2mo ago Spinnaker: RCE via expression parsing due to unrestricted context handling
CVE-2026-32604 unknown 2mo ago Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
CVE-2026-6783 unknown FIX debian debian 2mo ago Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6782 unknown FIX debian debian 2mo ago Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6781 unknown FIX debian debian 2mo ago Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6778 unknown FIX debian debian 2mo ago Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6777 unknown FIX debian debian 2mo ago Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6775 unknown FIX debian debian 2mo ago Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6774 unknown FIX debian debian 2mo ago Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6773 unknown FIX debian debian 2mo ago Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6768 unknown FIX debian debian 2mo ago Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6755 unknown FIX debian debian 2mo ago Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-31369 low 3.2 3.2 2mo ago PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability
CVE-2026-5965 critical 9.8 9.8 2mo ago NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-6257 critical 9.1 9.1 2mo ago Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to r…
CVE-2026-32311 critical 9.8 9.8 flowsint 2mo ago Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to ma…
CVE-2026-6651 low 2.4 2.4 2mo ago A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item N…
CVE-2026-33558 unknown 2mo ago Apache Kafka exposes sensitive information in its DEBUG logs
CVE-2026-33557 unknown 2mo ago Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
CVE-2026-5760 critical 9.8 9.8 lmsys 2mo ago SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered usin…
CVE-2026-6648 low 3.5 3.5 2mo ago A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripti…
CVE-2026-6633 low 3.5 3.5 2mo ago A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Exte…
CVE-2026-5958 unknown FIX slesdebian debianubuntu ubuntu google 2mo ago sed vulnerability
CVE-2026-6624 low 2.4 2.4 2mo ago A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipula…
CVE-2026-6622 low 2.4 2.4 2mo ago A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulati…
CVE-2026-6619 low 3.5 3.5 2mo ago A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePrevie…
CVE-2026-5964 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-5963 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-6644 critical 9.1 9.1 2mo ago A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary co…
CVE-2026-6611 low 3.1 3.1 2mo ago A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulatio…
CVE-2024-7083 low 3.5 3.5 2mo ago The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks…
CVE-2026-6610 low 3.7 3.7 2mo ago A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipula…
CVE-2026-6600 low 3.5 3.5 2mo ago A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of …
CVE-2026-6597 low 2.7 2.7 2mo ago A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flo…
CVE-2026-6593 low 3.5 3.5 2mo ago A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cros…
CVE-2026-6592 low 3.5 3.5 2mo ago A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulatio…
CVE-2026-20133 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
CVE-2026-20128 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential fil…
CVE-2026-20122 unknown 1.5 KEV 2mo ago Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulne…
CVE-2025-48700 unknown 1.5 KEV 2mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to una…
CVE-2025-32975 unknown 1.5 KEV 2mo ago Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
CVE-2025-2749 unknown 1.5 KEV 2mo ago Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
CVE-2024-27199 unknown 1.5 KEV 2mo ago JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2023-27351 unknown 1.5 KEV 2mo ago PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
CVE-2026-6570 low 2.7 2.7 2mo ago A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argum…
CVE-2026-32690 unknown 2mo ago Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
CVE-2026-30912 unknown 2mo ago Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
CVE-2026-40324 critical 9.1 9.1 2mo ago ChilliCream GraphQL Platform: Utf8GraphQLParser Stack Overflow via Deeply Nested GraphQL Documents
CVE-2026-5720 critical 9.1 9.1 FIX debian debian miniupnp_project 2mo ago miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPActio…
CVE-2026-40351 critical 9.8 9.8 fastgpt 2mo ago FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attac…
CVE-2026-40258 critical 9.1 9.1 2mo ago gramps-webapi: Zip Slip Path Traversal in Media Archive Import
CVE-2026-29013 critical 9.8 9.8 FIX debian debian libcoap 2mo ago libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which i…
CVE-2026-23500 critical 9.1 9.1 dolibarr 2mo ago Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
CVE-2026-35546 critical 9.8 9.8 2mo ago Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
CVE-2026-40525 critical 9.1 9.1 volcengine 2mo ago OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
CVE-2026-40518 critical 9.1 9.1 bytedance 2mo ago ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attacker…
CVE-2026-40458 unknown 2mo ago PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2026-27769 low 2.5 2mo ago Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
CVE-2026-6493 low 3.5 3.5 2mo ago A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx of the component…
CVE-2026-6486 low 3.5 3.5 2mo ago A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manip…
CVE-2025-15625 critical 9.8 9.8 sparxsystems 2mo ago Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
CVE-2026-41242 critical 9.5 2mo ago Arbitrary code execution in protobufjs
CVE-2026-40611 unknown FIX debian debian 2mo ago Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A ma…
CVE-2026-41245 unknown 2mo ago Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
CVE-2026-30778 unknown 2mo ago SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information
CVE-2026-5426 critical 9.1 9.1 2mo ago Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot…
CVE-2026-33804 critical 9.1 9.1 fastify 2mo ago @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
CVE-2026-6270 critical 9.1 9.1 fastify 2mo ago @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CVE-2026-31843 critical 9.8 9.8 2mo ago goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
CVE-2026-6350 critical 9.8 9.8 2mo ago MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
CVE-2026-6349 critical 9.8 9.8 2mo ago The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-40505 low 3.3 3.3 FIX debian debian artifex 2mo ago MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious…
CVE-2026-40504 critical 9.8 9.8 2mo ago Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string li…
CVE-2026-40959 critical 9.3 9.3 FIX slesdebian debianubuntu ubuntu 2mo ago Luanti vulnerabilities
CVE-2026-32179 critical 9.5 2mo ago MsQuic has a Remote Elevation of Privilege Vulnerability
CVE-2026-33808 critical 9.1 9.1 fastify 2mo ago Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-…
CVE-2026-33807 critical 9.1 9.1 fastify 2mo ago @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is register…
CVE-2026-6312 low 3.1 3.1 FIX debian debian linux-kernelmacos macos google 2mo ago Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML p…
CVE-2026-6296 critical 9.6 9.6 FIX debian debian linux-kernelmacos macos google 2mo ago Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-40478 unknown 2mo ago Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
CVE-2026-40477 unknown 2mo ago Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-40347 unknown FIX slesdebian debian 2mo ago Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
CVE-2026-40882 unknown 2mo ago OpenRemote has XXE in Velbus Asset Import
CVE-2026-6313 unknown FIX debian debian 2mo ago Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. …
CVE-2026-5598 unknown FIX debian debian sles 2mo ago Bouncy Castle Has Covert Timing Channel Vulnerability
CVE-2026-5588 unknown debian debian sles google 2mo ago Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
CVE-2026-3505 unknown debian debian sles 2mo ago Bouncy Castle Uncontrolled Resource Consumption vulnerability
CVE-2026-0636 unknown debian debian sles 2mo ago Bouncy Castle has an LDAP injection
CVE-2026-40104 unknown 2mo ago XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVE-2026-40105 unknown 2mo ago XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
CVE-2026-39842 unknown 2mo ago Expression Injection in OpenRemote
CVE-2026-33414 unknown FIX debian debian 2mo ago Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the…
CVE-2026-39907 critical 10.0 10.0 unisys 2mo ago Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's L…
CVE-2026-39906 critical 10.0 10.0 unisys 2mo ago Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hash…
CVE-2026-40683 unknown FIX debian debian 2mo ago OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
CVE-2026-40176 unknown FIX debian debian sles 2mo ago Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs she…
CVE-2026-40261 unknown FIX debian debian sles 2mo ago Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source…
CVE-2026-40312 unknown FIX debian debian sles 2mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malico…