Search

Found 62,670 results in 2991ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-46522 high 9.0 EXPFIX debian debian 19d ago ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
CVE-2026-46520 high 8.0 FIX debian debian 19d ago ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
CVE-2026-45367 high 8.0 19d ago HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2026-45553 high 7.5 7.5 19d ago NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI …
CVE-2026-45686 high 7.5 7.5 sles opentelemetry 19d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcac…
CVE-2026-45685 high 7.5 7.5 sles opentelemetry 20d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught …
CVE-2026-47092 high 7.8 7.8 jarrodwatts 20d ago Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…
CVE-2026-45245 high 7.4 7.4 steipete 20d ago Summarize's hover summary feature allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links
CVE-2026-45680 high 7.5 7.5 sles opentelemetry 20d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once pe…
CVE-2026-8836 critical 9.8 9.8 FIX debian debian 20d ago A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…
CVE-2026-45242 high 7.1 7.1 steipete 20d ago Summarize contains a path traversal vulnerability
CVE-2026-45495 high 8.8 8.8 windows windows microsoft 20d ago Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-45230 critical 9.1 9.1 20d ago DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…
CVE-2026-42822 critical 10.0 10.0 windows windows microsoft 20d ago Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-29963 high 7.5 7.5 hsclabs 20d ago HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without …
CVE-2026-29962 high 7.5 7.5 hsclabs 20d ago HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controll…
CVE-2023-24215 critical 9.1 9.1 20d ago Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.
CVE-2026-45678 high 7.5 7.5 sles opentelemetry 20d ago OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a vali…
CVE-2026-42306 high 8.0 20d ago Docker: Race condition in docker cp allows bind mount redirection to host path
CVE-2026-45727 high 8.0 20d ago CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path componen…
CVE-2026-41567 high 7.2 7.2 sles 20d ago Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/arc…
CVE-2026-45707 high 8.1 8.1 n8n-mcp 20d ago n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that th…
CVE-2026-45697 critical 9.8 9.8 20d ago Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as …
CVE-2026-45327 high 8.2 8.2 20d ago TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the …
CVE-2026-45829 unknown 20d ago ChromaDB Python project has a pre-authentication code injection vulnerability
CVE-2026-41085 high 8.8 8.8 20d ago Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrato…
CVE-2026-45325 high 8.0 20d ago @tmlmobilidade/utils has prototype pollution in its setValueAtPath
CVE-2026-45302 high 8.2 8.2 20d ago parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nes…
CVE-2026-45300 high 7.4 7.4 debian debian 20d ago The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch pri…
CVE-2026-46385 high 8.0 20d ago iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state ins…
CVE-2026-45270 high 8.0 20d ago CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
CVE-2026-46384 high 8.0 20d ago iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before …
CVE-2026-45149 high 7.5 7.5 debian debian juliangruber 20d ago The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large num…
CVE-2025-57282 high 8.8 8.8 20d ago ngrok is Vulnerable to Command Injection
CVE-2025-56352 high 7.5 7.5 20d ago In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length C…
CVE-2026-41949 high 7.5 7.5 dify 20d ago Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document acros…
CVE-2026-41948 critical 9.4 9.4 dify 20d ago Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficie…
CVE-2026-41947 critical 9.1 9.1 dify 20d ago Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant owners…
CVE-2026-39079 high 7.5 7.5 20d ago An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBas…
CVE-2026-26462 high 7.3 7.3 20d ago Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation…
CVE-2026-46724 unknown 20d ago TYPO3-EXT-SA-2026-011: Path Traversal in extension "Faceted Search" (ke_search)
CVE-2026-46722 unknown 20d ago TYPO3-EXT-SA-2026-011: XML External Entity Injection in extension "Faceted Search" (ke_search)
CVE-2026-45627 high 8.2 8.2 20d ago Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query param…
CVE-2026-45625 critical 9.9 9.9 20d ago Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /a…
CVE-2026-45135 high 8.0 20d ago Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-46510 high 8.2 8.2 20d ago form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, …
CVE-2026-42009 high 7.5 7.5 FIX debian debian sleswindows windows 20d ago RHSA-2026:20612: gnutls security update (Important)
CVE-2026-7304 critical 9.8 9.8 lmsys 20d ago SGLang: Unauthenticated RCE via --enable-custom-logit-processor
CVE-2026-7302 critical 9.1 9.1 lmsys 20d ago SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
CVE-2026-7301 critical 9.8 9.8 lmsys 20d ago SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
CVE-2026-7498 high 8.8 8.8 20d ago Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored…
CVE-2026-6347 high 7.6 7.6 mattermost 20d ago Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin
CVE-2026-6346 high 8.7 8.7 mattermost 20d ago Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation
CVE-2026-8788 high 7.3 7.3 20d ago Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sour…
CVE-2026-6495 high 7.1 7.1 20d ago The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again…
CVE-2026-6381 high 7.5 7.5 20d ago The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
CVE-2026-6379 high 8.6 8.6 20d ago The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection at…
CVE-2026-3220 high 8.8 8.8 20d ago The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Script…
CVE-2026-8785 high 7.3 7.3 20d ago A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Param…
CVE-2026-8776 high 8.8 8.8 20d ago A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulati…
CVE-2026-8775 high 8.8 8.8 20d ago A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TP…
CVE-2026-8771 high 7.3 7.3 20d ago org.linlinjava:litemall-wx-api has an Injection issue
CVE-2026-45363 high 8.0 20d ago ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
CVE-2026-42945 high 8.1 8.1 FIX rhel slesdebian debian 20d ago RHSA-2026:18041: nginx:1.24 security update (Critical)
CVE-2026-41316 high 8.1 8.1 FIX rhel slesdebian debian google 20d ago Important: ruby:4.0 security update
CVE-2026-33416 high 8.0 FIX rheldebian debian sles 20d ago Important: thunderbird security update
CVE-2026-8768 high 7.3 7.3 vercel 20d ago A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils.…
CVE-2026-8767 high 7.5 7.5 vercel 20d ago A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manip…
CVE-2026-8764 high 7.2 7.2 20d ago A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffe…
CVE-2026-8721 critical 9.8 9.8 FIX debian debian 21d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to Sv…
CVE-2026-8507 critical 9.8 9.8 FIX debian debian 21d ago Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info(…
CVE-2026-46720 high 8.2 8.2 21d ago Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources c…
CVE-2026-8759 high 7.3 7.3 21d ago Beetl's SpELFunction extension function has an expression injection risk
CVE-2026-8758 high 7.3 7.3 21d ago A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lea…
CVE-2026-8757 critical 9.1 9.1 adenhq 21d ago A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Perfor…
CVE-2026-8756 high 7.3 7.3 21d ago A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_config of the file webui_preprocess.py of the comp…
CVE-2026-8755 high 7.3 7.3 21d ago A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of the file hiyoriUI.py of the component Model Handl…
CVE-2018-25339 high 8.2 8.2 21d ago Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the…
CVE-2018-25338 high 8.2 8.2 21d ago Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit th…
CVE-2018-25335 critical 9.8 9.8 21d ago WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint.…
CVE-2018-25333 high 8.2 8.2 21d ago Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the …
CVE-2018-25332 critical 9.8 9.8 gitbucket 21d ago GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
CVE-2018-25330 high 8.2 8.2 21d ago Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. At…
CVE-2018-25329 high 7.5 7.5 21d ago WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attack…
CVE-2018-25328 high 8.4 8.4 21d ago VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craf…
CVE-2018-25326 high 7.5 7.5 21d ago Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parame…
CVE-2018-25325 high 7.5 7.5 21d ago Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX …
CVE-2018-25323 high 8.4 8.4 21d ago Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payl…
CVE-2018-25322 high 8.4 8.4 21d ago Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can…
CVE-2018-25320 critical 9.8 9.8 21d ago ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
CVE-2018-25319 high 7.1 7.1 21d ago Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Att…
CVE-2026-8751 critical 9.8 9.8 h2o 21d ago A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a…
CVE-2026-8750 high 7.5 7.5 h2o 21d ago A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFi…
CVE-2026-8734 high 7.3 7.3 21d ago A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interface. This manipulatio…
CVE-2026-8719 high 8.8 8.8 21d ago The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in t…
CVE-2026-8725 high 7.3 7.3 21d ago A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation cau…
CVE-2026-8724 high 7.2 7.2 dataease 21d ago A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results …
CVE-2026-46728 high 8.2 8.2 slesdebian debian 21d ago Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
CVE-2021-47980 high 7.1 7.1 22d ago Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log i…
CVE-2021-47979 high 8.8 8.8 22d ago WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers …