Search

Found 41,691 results in 4481ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-34645 high 7.5 7.5 adobe 25d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature b…
CVE-2026-23827 high 7.5 7.5 arubanetworks 25d ago A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful …
CVE-2026-23826 high 7.5 7.5 arubanetworks 25d ago A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to …
CVE-2026-23825 high 7.5 7.5 arubanetworks 25d ago Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network mess…
CVE-2026-23824 high 7.5 7.5 arubanetworks 25d ago Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network mess…
CVE-2026-8431 high 7.2 7.2 25d ago An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.  This issue affe…
CVE-2026-8430 high 8.1 8.1 FIX debian debian 25d ago SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the co…
CVE-2026-8429 high 8.8 8.8 FIX debian debian 25d ago SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploi…
CVE-2026-34684 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34683 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34682 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34681 high 7.8 7.8 adobe 25d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
CVE-2026-34660 critical 9.3 9.3 adobe 25d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An …
CVE-2026-34659 critical 9.6 9.6 adobe 25d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current …
CVE-2026-23823 high 7.2 7.2 25d ago A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacke…
CVE-2026-23821 high 7.2 7.2 25d ago A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Su…
CVE-2026-23820 high 7.2 7.2 25d ago A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environme…
CVE-2026-23819 high 8.8 8.8 25d ago A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim…
CVE-2026-31225 high 8.8 8.8 25d ago Superduper: Remote code execution via unsafe eval in superduper query parsing
CVE-2026-31222 high 8.8 8.8 snorkel 25d ago Snorkel Trainer.load uses an unsafe torch.load
CVE-2026-31221 high 7.8 7.8 lightningai 25d ago PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CVE-2026-44343 critical 9.8 9.8 wgdashboard 25d ago WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file sys…
CVE-2026-44277 critical 9.1 9.1 fortinet 25d ago A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attack…
CVE-2026-44196 critical 9.1 9.1 25d ago Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and …
CVE-2026-44184 high 8.0 8.0 25d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy refl…
CVE-2026-44183 critical 9.8 9.8 25d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.…
CVE-2026-44166 high 7.6 7.6 pocketbase 25d ago PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
CVE-2026-43929 high 8.2 8.2 25d ago ssrfcheck Vulnerable to Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
CVE-2026-43892 high 8.8 8.8 25d ago AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed i…
CVE-2026-43891 high 7.5 7.5 webtechnologies 25d ago changedetection.io has an Arbitrary Local File Read via a crafted backup restore
CVE-2026-42898 critical 9.9 9.9 windows windows microsoft 25d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42896 high 7.8 7.8 FIX windows windows 25d ago Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42893 high 7.4 7.4 windows windows microsoft 25d ago Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-42833 critical 9.1 9.1 windows windows microsoft 25d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42832 high 7.7 7.7 windows windows microsoft 25d ago Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831 high 7.8 7.8 windows windows microsoft 25d ago Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-42825 high 7.0 7.0 FIX windows windows 25d ago Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-42823 critical 9.9 9.9 windows windows microsoft 25d ago Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42348 high 7.5 7.5 opentelemetry 25d ago OpAMP client reads unbounded HTTP response bodies
CVE-2026-42300 critical 9.5 25d ago DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
CVE-2026-42141 high 7.7 7.7 25d ago Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerabi…
CVE-2026-42048 critical 9.6 9.6 langflow 25d ago Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-41895 high 7.5 7.5 webtechnologies 25d ago changedetection.io project has an XXE vulnerability
CVE-2026-41613 high 8.8 8.8 windows windows microsoft 25d ago Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41611 high 7.8 7.8 windows windows microsoft 25d ago Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVE-2026-41109 high 8.8 8.8 windows windows microsoft 25d ago Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…
CVE-2026-41107 high 7.4 7.4 windows windows microsoft 25d ago External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-41103 critical 9.1 9.1 windows windows microsoft 25d ago Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41102 high 7.1 7.1 windows windows microsoft 25d ago Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
CVE-2026-41101 high 7.1 7.1 windows windows microsoft 25d ago Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
CVE-2026-41096 critical 9.8 9.8 FIX windows windows 25d ago Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-41095 high 7.8 7.8 FIX windows windows 25d ago Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
CVE-2026-41094 high 8.8 8.8 windows windows microsoft 25d ago Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
CVE-2026-41089 critical 9.8 9.8 FIX windows windows 25d ago Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVE-2026-41088 high 7.8 7.8 FIX windows windows 25d ago Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-41086 high 8.8 8.8 windows windows microsoft 25d ago Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-40420 high 8.8 8.8 windows windows microsoft 25d ago Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40419 high 7.8 7.8 windows windows microsoft 25d ago Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418 high 7.8 7.8 windows windows microsoft 25d ago Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40417 high 7.8 7.8 windows windows microsoft 25d ago Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
CVE-2026-40415 high 8.1 8.1 FIX windows windows 25d ago Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
CVE-2026-40414 high 7.4 7.4 FIX windows windows 25d ago Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40413 high 7.4 7.4 FIX windows windows 25d ago Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40410 high 7.0 7.0 FIX windows windows 25d ago Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-40408 high 7.8 7.8 FIX windows windows 25d ago Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-40407 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-40406 high 7.5 7.5 FIX windows windows 25d ago Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.
CVE-2026-40405 high 7.5 7.5 FIX windows windows 25d ago Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CVE-2026-40403 high 8.8 8.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
CVE-2026-40402 critical 9.3 9.3 FIX windows windows 25d ago Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
CVE-2026-40401 high 7.1 7.1 FIX windows windows 25d ago Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40399 high 7.8 7.8 FIX windows windows 25d ago Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-40398 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
CVE-2026-40397 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-40382 high 7.8 7.8 FIX windows windows 25d ago Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-40381 high 7.8 7.8 windows windows microsoft 25d ago Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-40379 critical 9.3 9.3 windows windows microsoft 25d ago Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-40377 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
CVE-2026-40370 high 8.8 8.8 windows windows 25d ago External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-40369 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40368 high 8.0 8.0 windows windows microsoft 25d ago Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-40367 high 8.4 8.4 windows windows microsoft 25d ago Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366 high 8.4 8.4 windows windows microsoft 25d ago Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40365 high 8.8 8.8 windows windows microsoft 25d ago Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-40364 high 8.4 8.4 windows windows microsoft 25d ago Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40363 high 8.4 8.4 windows windows microsoft 25d ago Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362 high 7.8 7.8 windows windows microsoft 25d ago Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361 high 8.4 8.4 windows windows microsoft 25d ago Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360 high 7.8 7.8 windows windows microsoft 25d ago Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359 high 7.8 7.8 windows windows microsoft 25d ago Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358 high 8.4 8.4 windows windows microsoft 25d ago Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40357 high 8.8 8.8 windows windows microsoft 25d ago Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-35439 high 8.8 8.8 windows windows microsoft 25d ago Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-35438 high 8.3 8.3 windows windows microsoft 25d ago Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-35436 high 8.8 8.8 windows windows microsoft 25d ago Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-35433 high 7.3 7.3 windows windows 25d ago Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-35424 high 7.5 7.5 FIX windows windows 25d ago Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
CVE-2026-35421 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
CVE-2026-35420 high 7.8 7.8 FIX windows windows 25d ago Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-35418 high 7.8 7.8 FIX windows windows 25d ago Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.