Search

Found 58,591 results in 5012ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44279 medium 5.5 5.5 fortinet 26d ago A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow atta…
CVE-2026-44278 medium 5.5 5.5 fortinet 26d ago A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert at…
CVE-2026-44277 critical 9.1 9.1 fortinet 26d ago A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attack…
CVE-2026-44204 medium 6.5 6.5 26d ago Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role)…
CVE-2026-44196 critical 9.1 9.1 26d ago Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and …
CVE-2026-44183 critical 9.8 9.8 26d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.…
CVE-2026-42898 critical 9.9 9.9 windows windows microsoft 26d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42891 medium 6.5 6.5 windows windows microsoft 26d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42838 medium 5.4 5.4 windows windows microsoft 26d ago Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a netw…
CVE-2026-42833 critical 9.1 9.1 windows windows microsoft 26d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42830 medium 6.5 6.5 windows windows microsoft 26d ago Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42823 critical 9.9 9.9 windows windows microsoft 26d ago Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42541 medium 4.3 4.3 26d ago Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
CVE-2026-42303 medium 5.5 26d ago Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-42300 critical 9.5 26d ago DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
CVE-2026-42177 medium 5.3 5.3 FIX debian debian 26d ago linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter i…
CVE-2026-42175 medium 6.5 6.5 26d ago requests-hardened is Vulnerable to Server-Side Request Forgery
CVE-2026-42048 critical 9.6 9.6 langflow 26d ago Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-42045 medium 6.2 6.2 26d ago LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
CVE-2026-41614 medium 6.2 6.2 windows windows microsoft 26d ago Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41612 medium 5.5 5.5 windows windows microsoft 26d ago Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
CVE-2026-41610 medium 6.3 6.3 windows windows microsoft 26d ago Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-41103 critical 9.1 9.1 windows windows microsoft 26d ago Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira &amp; Confluence allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41100 medium 4.4 4.4 windows windows microsoft 26d ago Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-41097 medium 6.7 6.7 FIX windows windows 26d ago Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-41096 critical 9.8 9.8 FIX windows windows 26d ago Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-41089 critical 9.8 9.8 FIX windows windows 26d ago Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVE-2026-40421 medium 4.3 4.3 windows windows microsoft 26d ago Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40416 medium 4.3 4.3 windows windows microsoft 26d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-40402 critical 9.3 9.3 FIX windows windows 26d ago Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
CVE-2026-40380 medium 6.2 6.2 FIX windows windows 26d ago Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
CVE-2026-40379 critical 9.3 9.3 windows windows microsoft 26d ago Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-40374 medium 6.5 6.5 windows windows microsoft 26d ago Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2026-35440 medium 5.5 5.5 windows windows microsoft 26d ago Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-35429 medium 4.3 4.3 windows windows microsoft 26d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35423 medium 5.4 5.4 FIX windows windows 26d ago Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-35422 medium 6.5 6.5 FIX windows windows 26d ago Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
CVE-2026-35419 medium 5.5 5.5 FIX windows windows 26d ago Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-34663 medium 5.5 5.5 macos macos adobe 26d ago Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to d…
CVE-2026-34662 medium 5.5 5.5 macos macos adobe 26d ago Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerabil…
CVE-2026-34350 medium 6.5 6.5 FIX windows windows 26d ago Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-34339 medium 5.5 5.5 FIX windows windows 26d ago Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
CVE-2026-33117 critical 9.1 9.1 windows windows microsoft 26d ago The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected a…
CVE-2026-32209 medium 4.4 4.4 FIX windows windows 26d ago Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
CVE-2026-32185 medium 5.5 5.5 windows windows microsoft 26d ago Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-32175 medium 4.3 4.3 windows windows 26d ago A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to ce…
CVE-2026-32170 medium 6.7 6.7 FIX windows windows 26d ago Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-31245 medium 5.3 5.3 mem0 26d ago mem0 server lacks authentication and authorization controls for its memory creation API endpoint
CVE-2026-31244 medium 6.5 6.5 mem0 26d ago The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrar…
CVE-2026-31243 medium 6.5 6.5 mem0 26d ago The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacke…
CVE-2026-31242 critical 9.1 9.1 mem0 26d ago The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE r…
CVE-2026-31241 medium 6.5 6.5 mem0 26d ago mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
CVE-2026-31239 critical 9.8 9.8 26d ago mamba language model framework vulnerable to insecure deserialization when loading pre-trained models from HuggingFace Hub
CVE-2026-31238 critical 9.8 9.8 26d ago Ludwig framework is vulnerable to insecure deserialization in its model serving component
CVE-2026-31237 critical 9.8 9.8 26d ago Ludwig framework is vulnerable to insecure deserialization through its predict() method.
CVE-2026-31236 critical 9.8 9.8 debian debian 26d ago llm CLI tool contains a code injection vulnerability via `--functions` command-line argument
CVE-2026-31235 critical 9.8 9.8 26d ago imgaug contains an insecure deserialization vulnerability in BackgroundAugmenter class within multicore.py module
CVE-2026-31234 critical 9.8 9.8 26d ago Horovod contains an insecure deserialization vulnerability in its KVStore HTTP server component
CVE-2026-31233 critical 9.8 9.8 26d ago Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
CVE-2026-31231 critical 9.8 9.8 26d ago Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code provided by the user,…
CVE-2026-31230 critical 9.8 9.8 26d ago The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the un…
CVE-2026-31229 critical 9.8 9.8 26d ago The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights f…
CVE-2026-29204 critical 9.1 9.1 26d ago Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized ac…
CVE-2026-26083 critical 9.8 9.8 fortinet 26d ago A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, Fort…
CVE-2026-25690 medium 6.5 6.5 fortinet 26d ago An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2…
CVE-2026-21530 medium 6.7 6.7 FIX windows windows 26d ago Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2025-67604 medium 5.3 5.3 fortinet 26d ago A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions,…
CVE-2025-53870 medium 6.7 6.7 fortinet 26d ago An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versi…
CVE-2025-53680 medium 6.7 6.7 fortinet 26d ago An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5…
CVE-2026-8407 medium 4.3 4.3 devolutions 26d ago Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted re…
CVE-2026-43992 critical 9.8 9.8 26d ago JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate_contract, upload_wasm, ibc_transfer, etc.) accept…
CVE-2026-40300 medium 6.5 6.5 zulip 26d ago Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allo…
CVE-2026-25431 medium 5.3 5.3 26d ago Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.
CVE-2026-20914 medium 5.5 5.5 intel 26d ago Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…
CVE-2026-20905 medium 6.6 6.6 intel 26d ago Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…
CVE-2026-20881 medium 5.5 5.5 intel 26d ago Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authentic…
CVE-2026-20793 low 3.3 3.3 intel 26d ago Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an a…
CVE-2026-20782 medium 6.6 6.6 intel 26d ago Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenti…
CVE-2026-20771 medium 6.1 6.1 intel 26d ago Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…
CVE-2026-20717 medium 6.6 6.6 intel 26d ago Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…
CVE-2025-65719 critical 9.8 9.8 26d ago An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.
CVE-2026-42074 critical 9.8 9.8 gitlawb 26d ago OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashToo…
CVE-2026-43515 critical 9.1 9.1 FIX slesdebian debian apache 26d ago Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21,…
CVE-2026-43514 low 3.7 3.7 FIX slesdebian debian apache 26d ago Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M…
CVE-2026-43512 critical 9.8 9.8 FIX slesdebian debian apache 26d ago DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fr…
CVE-2026-41293 critical 9.8 9.8 FIX slesdebian debian apache 26d ago Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0…
CVE-2026-34187 critical 9.8 9.8 artica 26d ago Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affects Pandora FMS: from 777 through 800
CVE-2026-31228 critical 9.8 9.8 26d ago The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe ev…
CVE-2026-31226 critical 9.8 9.8 26d ago The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerabi…
CVE-2026-31220 critical 9.8 9.8 26d ago PySyft server-side arbitrary Python execution after code approval
CVE-2026-31217 critical 9.8 9.8 nebuly 26d ago The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user …
CVE-2026-31216 critical 9.1 9.1 nexent 26d ago The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentica…
CVE-2026-31215 critical 9.1 9.1 nexent 26d ago The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper aut…
CVE-2026-31214 critical 9.8 9.8 26d ago The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The s…
CVE-2026-30805 critical 9.1 9.1 artica 26d ago Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800
CVE-2023-30059 medium 5.4 5.4 26d ago An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.
CVE-2026-42073 medium 6.5 6.5 gitlawb 26d ago OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP serv…
CVE-2026-8368 medium 6.5 6.5 FIX debian debian sleswindows windows 26d ago LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …
CVE-2026-8109 medium 6.5 6.5 ivanti 26d ago An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
CVE-2026-8043 critical 9.6 9.6 ivanti 26d ago External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …