Search

Found 12,850 results in 630ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-7284 critical 9.8 9.8 15d ago The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due …
CVE-2026-6555 critical 9.8 9.8 15d ago The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in…
CVE-2026-31607 critical 9.8 9.8 FIX rhel slesdebian debian 15d ago In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_…
CVE-2026-8495 critical 9.8 9.8 date_ical_project 15d ago This module enables you to export entity date fields as iCal feeds. The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds. This vulnerabili…
CVE-2026-34234 critical 10.0 10.0 15d ago CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Executi…
CVE-2026-46412 critical 9.5 15d ago Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
CVE-2026-46354 critical 9.5 15d ago Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CVE-2026-46339 critical 9.5 15d ago 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVE-2026-45695 critical 9.5 15d ago Kopia: RCE via SSH ProxyCommand Injection
CVE-2026-33642 critical 9.8 9.8 FIX debian debian kovidgoyal 15d ago Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …
CVE-2026-8605 critical 9.8 9.8 scadabr 15d ago In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
CVE-2026-8603 critical 9.8 9.8 scadabr 15d ago In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
CVE-2026-8602 critical 9.1 9.1 scadabr 15d ago In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
CVE-2026-36829 critical 9.8 9.8 15d ago An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based …
CVE-2026-37281 critical 9.8 9.8 16d ago An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.
CVE-2026-31072 critical 9.8 9.8 debian debian sles 16d ago The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object funct…
CVE-2026-31071 critical 9.1 9.1 16d ago API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…
CVE-2026-31070 critical 9.8 9.8 16d ago The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/…
CVE-2026-30118 critical 9.8 9.8 16d ago scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers…
CVE-2026-30117 critical 9.8 9.8 16d ago scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execut…
CVE-2026-45758 critical 9.5 16d ago Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
CVE-2026-44159 critical 9.8 9.8 16d ago Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 202…
CVE-2026-2587 critical 9.6 9.6 eclipse 16d ago A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and eval…
CVE-2026-2586 critical 9.1 9.1 eclipse 16d ago An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of …
CVE-2026-45568 critical 9.5 16d ago rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
CVE-2026-46395 critical 9.5 16d ago HAXcms: Private Key Disclosure via Broken HMAC Implementation
CVE-2026-8948 critical 9.1 9.1 FIX debian debian sles mozilla 16d ago Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-47323 critical 9.8 9.8 16d ago Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFil…
CVE-2026-43633 critical 10.0 10.0 16d ago HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated rem…
CVE-2026-4883 critical 9.8 9.8 16d ago The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…
CVE-2026-43493 critical 9.8 9.8 FIX slesdebian debianwindows windows 16d ago In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that va…
CVE-2026-45434 critical 9.8 9.8 apache 16d ago Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgr…
CVE-2026-41919 critical 9.1 9.1 apache 16d ago Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…
CVE-2026-31986 critical 9.1 9.1 apache 16d ago Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVE-2026-2611 critical 9.6 9.6 lfprojects 16d ago In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests fr…
CVE-2026-4885 critical 9.8 9.8 16d ago The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…
CVE-2026-47314 critical 9.8 9.8 samsung 16d ago Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-47311 critical 9.8 9.8 samsung 16d ago Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-47310 critical 9.8 9.8 samsung 16d ago Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-7321 critical 9.6 9.6 FIX rheldebian debianalmalinux almalinux mozilla 16d ago RHSA-2026:20586: thunderbird security update (Important)
CVE-2025-68121 critical 10.0 10.0 FIX rocky rheldebian debian golanggoogle 16d ago RHSA-2026:22714: osbuild-composer security update (Important)
CVE-2025-55754 critical 9.6 9.6 FIX rhel slesdebian debian apache 16d ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Win…
CVE-2026-8838 critical 9.8 9.8 aws 16d ago amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
CVE-2026-27130 critical 9.9 9.9 16d ago Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input…
CVE-2026-25244 critical 9.8 9.8 openjsf 16d ago WebdriverIO BrowserStack Service has a Command Injection issue
CVE-2026-8836 critical 9.8 9.8 FIX debian debian 16d ago A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…
CVE-2026-45230 critical 9.1 9.1 16d ago DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…
CVE-2026-42822 critical 10.0 10.0 windows windows microsoft 16d ago Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
CVE-2023-24215 critical 9.1 9.1 16d ago Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.
CVE-2026-45697 critical 9.8 9.8 16d ago Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as …
CVE-2026-41948 critical 9.4 9.4 dify 17d ago Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficie…
CVE-2026-41947 critical 9.1 9.1 dify 17d ago Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant owners…
CVE-2026-45625 critical 9.9 9.9 17d ago Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /a…
CVE-2026-7304 critical 9.8 9.8 lmsys 17d ago SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7302 critical 9.1 9.1 lmsys 17d ago SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7301 critical 9.8 9.8 lmsys 17d ago SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-8721 critical 9.8 9.8 FIX debian debian 17d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to Sv…
CVE-2026-8507 critical 9.8 9.8 FIX debian debian 17d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info(…
CVE-2026-8757 critical 9.1 9.1 adenhq 18d ago A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Perfor…
CVE-2018-25335 critical 9.8 9.8 18d ago WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint.…
CVE-2018-25332 critical 9.8 9.8 gitbucket 18d ago GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
CVE-2018-25320 critical 9.8 9.8 18d ago ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
CVE-2026-8751 critical 9.8 9.8 h2o 18d ago A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a…
CVE-2021-47952 critical 9.8 9.8 sles 19d ago python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. …
CVE-2020-37239 critical 9.8 9.8 19d ago libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_…
CVE-2020-37228 critical 9.8 9.8 19d ago iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retr…
CVE-2026-46703 critical 9.5 19d ago Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
CVE-2026-46695 critical 9.5 19d ago BoxLite: Permission Bypass Allows Modification of Read-Only Files
CVE-2026-44566 critical 9.8 9.8 openwebui 19d ago Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
CVE-2026-8696 critical 9.8 9.8 debian debian radare 19d ago radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbi…
CVE-2026-8686 critical 9.1 9.1 freertosaws 19d ago Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users s…
CVE-2026-46364 critical 9.8 9.8 19d ago phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent h…
CVE-2026-45010 critical 9.1 9.1 19d ago phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts arbitrary user-id parameters without session bind…
CVE-2021-47965 critical 9.8 9.8 19d ago WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation.…
CVE-2026-8695 critical 9.8 9.8 debian debian radare 19d ago radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed b…
CVE-2026-44774 critical 9.9 9.9 traefik 19d ago Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
CVE-2026-44717 critical 9.8 9.8 19d ago MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitiz…
CVE-2026-41258 critical 9.1 9.1 19d ago OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange
CVE-2026-45772 critical 9.8 9.8 vercel 20d ago Turbo: Unexpected local code execution during Yarn Berry detection
CVE-2026-41553 critical 10.0 10.0 dhtmlx 20d ago PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicio…
CVE-2026-5229 critical 9.8 9.8 20d ago The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which W…
CVE-2026-8398 critical 9.8 10.0 KEV disc-soft 20d ago Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2026-45288 critical 9.8 9.8 20d ago Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generate…
CVE-2026-45787 critical 9.1 9.1 electerm_project 20d ago electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
CVE-2026-45374 critical 9.6 9.6 20d ago CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:14…
CVE-2026-45311 critical 9.6 9.6 20d ago CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user…
CVE-2026-8634 critical 9.1 9.1 20d ago Crabbox: environment variable exposure vulnerability
CVE-2026-8580 critical 9.6 9.6 FIX debian debianwindows windows google 20d ago Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-8511 critical 9.6 9.6 FIX debian debianmacos macos linux-kernel google 20d ago Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-26191 critical 9.8 9.8 fleetdm 20d ago Fleet vulnerable to OS command injection in software packages
CVE-2026-45058 critical 9.5 20d ago electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync…
CVE-2026-45375 critical 9.0 9.0 20d ago SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
CVE-2026-44670 critical 9.5 20d ago SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
CVE-2026-44592 critical 9.4 9.4 20d ago Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker with…
CVE-2026-44588 critical 9.5 20d ago SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
CVE-2026-44523 critical 10.0 10.0 20d ago Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
CVE-2026-41315 critical 9.8 9.8 midoks 20d ago mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond a…
CVE-2026-44990 critical 9.5 20d ago Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CVE-2026-46470 critical 9.1 9.1 FIX debian debian sles freedesktop 20d ago An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…
CVE-2026-44542 critical 9.1 9.1 gtsteffaniak 20d ago FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion