Search

Found 49,657 results in 1801ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8328 unknown slesdebian debianwindows windows 24d ago The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpee…
CVE-2026-45708 high 7.2 7.2 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. The next time any admin clicks Print on any order,…
CVE-2026-45229 high 8.8 8.8 24d ago Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui…
CVE-2026-45055 high 8.1 8.1 24d ago CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded …
CVE-2026-44380 high 7.2 7.2 misp 24d ago MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organ…
CVE-2026-42602 high 8.1 8.1 opentelemetry 24d ago azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access toke…
CVE-2026-42561 high 7.5 7.5 slesdebian debian 24d ago Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data…
CVE-2026-42304 high 7.5 7.5 FIX slesdebian debianwindows windows twisted 24d ago Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exha…
CVE-2026-39358 high 7.2 7.2 24d ago CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_ad…
CVE-2026-21821 high 8.3 8.3 24d ago The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expo…
CVE-2025-27853 high 7.3 7.3 garmin 24d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser…
CVE-2025-27850 high 7.5 7.5 garmin 24d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links…
CVE-2026-33377 high 7.1 7.1 sles grafana 24d ago An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
CVE-2026-33376 high 7.4 7.4 sles grafana 24d ago When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128…
CVE-2026-8466 high 8.0 debian debianwindows windows 25d ago Cowboy: Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy
CVE-2026-44248 high 7.5 7.5 slesdebian debian netty 25d ago Netty MQTT: Resource exhaustion in MqttDecoder
CVE-2026-43970 high 8.0 debian debianwindows windows 25d ago Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion. cow_spdy:inflate/2 in cowlib…
CVE-2026-42587 high 7.5 7.5 slesdebian debian nettygoogle 25d ago Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
CVE-2026-42586 high 7.1 7.1 slesdebian debian netty 25d ago Netty Redis Codec Encoder has a CRLF Injection Issue
CVE-2026-42585 high 7.5 7.5 slesdebian debian netty 25d ago Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
CVE-2026-42583 high 7.5 7.5 slesdebian debian netty 25d ago Netty Lz4FrameDecoder is vulnerable to resource exhaustion
CVE-2026-42582 high 7.5 7.5 slesdebian debian netty 25d ago Netty HTTP/3 QPACK literal unbounded allocation
CVE-2026-42578 high 7.5 7.5 slesdebian debian netty 25d ago Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)
CVE-2026-42577 high 7.5 7.5 debian debian netty 25d ago Netty epoll transport denial of service via RST on half-closed TCP connection
CVE-2026-41132 high 7.4 7.4 okfn 25d ago CKAN has no certificate validation on STMP connection
CVE-2026-33583 high 8.7 8.7 25d ago Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Ag…
CVE-2026-30906 high 7.8 7.8 zoom 25d ago Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
CVE-2026-30905 high 7.8 7.8 zoom 25d ago External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via loca…
CVE-2026-45109 high 7.5 7.5 vercel 25d ago Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
CVE-2026-44579 high 7.5 7.5 vercel 25d ago Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
CVE-2026-44578 high 8.6 8.6 vercel 25d ago Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
CVE-2026-44004 high 7.5 7.5 vm2_project 25d ago vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
CVE-2026-44001 high 8.6 8.6 vm2_project 25d ago vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
CVE-2026-44000 high 7.2 7.2 vm2_project 25d ago vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
CVE-2026-43998 high 8.5 8.5 vm2_project 25d ago vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
CVE-2026-44575 high 7.5 7.5 vercel 25d ago Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-44574 high 8.1 8.1 vercel 25d ago Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
CVE-2026-44573 high 7.5 7.5 vercel 25d ago Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
CVE-2026-6282 high 8.1 8.1 25d ago A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to ot…
CVE-2026-6281 high 8.8 8.8 25d ago A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
CVE-2026-45740 high 7.5 7.5 protobufjs_project 25d ago protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
CVE-2026-45033 high 7.8 7.8 github 25d ago GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git r…
CVE-2026-44470 high 7.8 7.8 anthropic 25d ago The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Window…
CVE-2026-44432 high 7.5 7.5 FIX slesdebian debian python 25d ago urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) c…
CVE-2026-44295 high 8.7 8.7 protobufjs_project 25d ago protobuf.js: Code injection in pbjs static output from crafted schema names
CVE-2026-44293 high 8.8 8.8 protobufjs_project 25d ago protobuf.js: Code injection through bytes field defaults in generated toObject code
CVE-2026-44291 high 8.1 8.1 protobufjs_project 25d ago protobuf.js: Code generation gadget after prototype pollution
CVE-2026-44290 high 7.5 7.5 protobufjs_project 25d ago protobuf.js: Process-wide denial of service through unsafe option paths
CVE-2026-44289 high 7.5 7.5 protobufjs_project 25d ago protobuf.js: Denial of service through unbounded protobuf recursion
CVE-2026-43489 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: liveupdate: luo_file: remember retrieve() status LUO keeps track of successful retrieve attempts on a LUO file. It does so to av…
CVE-2026-43488 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Prevent interrupt storm on host controller error (HCE) The xHCI controller reports a Host Controller Error (HCE) in UA…
CVE-2026-43487 unknown FIX slesdebian debian google 25d ago In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Disable LPM on ST1000DM010-2EP102 According to a user report, the ST1000DM010-2EP102 has problems with LPM, cau…
CVE-2026-43486 unknown FIX slesdebian debian google 25d ago In the Linux kernel, the following vulnerability has been resolved: arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults contpte_ptep_set_access_flags() compared the gathered ptep…
CVE-2026-43485 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: nouveau/gsp: drop WARN_ON in ACPI probes These WARN_ONs seem to trigger a lot, and we don't seem to have a plan to fix them, so j…
CVE-2026-43484 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid bitfield RMW for claim/retune flags Move claimed and retune control flags out of the bitfield word to avoid unre…
CVE-2026-43483 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated Explicitly set/clear CR8 write interception when AVIC is (d…
CVE-2026-43482 unknown FIX slesdebian debian google 25d ago In the Linux kernel, the following vulnerability has been resolved: sched_ext: Disable preemption between scx_claim_exit() and kicking helper work scx_claim_exit() atomically sets exit_kind, which …
CVE-2026-43481 high 7.8 7.8 FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() con…
CVE-2026-43480 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the r…
CVE-2026-43479 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect Remove redundant netif_napi_del() call from disconnect path.…
CVE-2026-43478 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: rt1011: Use component to get the dapm context in spk_mode_put The correct helper to use in rt1011_recv_spk_mode_put…
CVE-2026-43477 unknown FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: Configure VRR timings after enabling TRANS_DDI_FUNC_CTL Apparently ICL may hang with an MCE if we write TRANS_VRR_V…
CVE-2026-43476 high 7.8 7.8 FIX slesdebian debian 25d ago In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) in…
CVE-2026-42930 high 8.7 8.7 25d ago When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have …
CVE-2026-42924 high 8.7 8.7 25d ago An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions…
CVE-2026-42920 high 7.5 7.5 25d ago When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software …
CVE-2026-42409 high 7.5 7.5 25d ago When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) …
CVE-2026-42406 high 8.7 8.7 25d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running ar…
CVE-2026-42290 high 7.8 7.8 protobufjs_project 25d ago protobuf.js is Vulnerable to OS Command Injection in the CLI
CVE-2026-41957 high 8.8 8.8 25d ago An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Software versions which have reached End of Technical S…
CVE-2026-41956 high 7.5 7.5 25d ago When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached …
CVE-2026-41953 high 8.7 8.7 25d ago A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escala…
CVE-2026-41227 high 7.5 7.5 25d ago On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to ter…
CVE-2026-41218 high 7.5 7.5 25d ago When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause …
CVE-2026-41217 high 7.9 7.9 25d ago A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system comman…
CVE-2026-40698 high 8.7 8.7 25d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iCont…
CVE-2026-40631 high 8.7 8.7 25d ago An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions whic…
CVE-2026-40629 high 7.5 7.5 25d ago When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Te…
CVE-2026-40618 high 7.5 7.5 25d ago When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacc…
CVE-2026-40423 high 7.5 7.5 25d ago When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technica…
CVE-2026-40067 high 7.5 7.5 25d ago When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (…
CVE-2026-40061 high 8.7 8.7 25d ago When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or…
CVE-2026-40060 high 7.5 7.5 25d ago When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End o…
CVE-2026-39459 high 7.2 7.2 25d ago A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running …
CVE-2026-39458 high 7.5 7.5 25d ago When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which…
CVE-2026-39455 high 7.5 7.5 25d ago When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file d…
CVE-2026-36741 high 7.2 7.2 25d ago U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. A…
CVE-2026-34176 high 8.7 8.7 25d ago When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a securit…
CVE-2026-32673 high 8.7 8.7 25d ago A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher priv…
CVE-2026-32643 high 8.7 8.7 25d ago A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running ar…
CVE-2026-20916 high 8.1 8.1 25d ago An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.  Note: Software versions which have re…
CVE-2025-28344 high 7.5 7.5 25d ago striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
CVE-2025-28343 high 7.5 7.5 25d ago striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
CVE-2024-55045 high 7.3 7.3 25d ago Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.
CVE-2020-37226 high 7.1 7.1 25d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37224 high 7.1 7.1 25d ago Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
CVE-2020-37223 high 7.8 7.8 25d ago IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou…
CVE-2020-37222 high 7.2 7.2 25d ago Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi…
CVE-2020-37221 high 8.4 8.4 25d ago Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Cloc…
CVE-2020-37220 high 7.5 7.5 25d ago Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer…