Search

Found 79,651 results in 2847ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-46412 critical 9.5 19d ago Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
CVE-2026-42526 medium 5.3 5.3 19d ago Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
CVE-2026-32739 medium 6.5 6.5 debian debian sles struktur 19d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 1…
CVE-2026-46354 critical 9.5 19d ago Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
CVE-2026-46342 low 2.5 19d ago Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
CVE-2026-46338 medium 5.5 19d ago Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
CVE-2026-45802 medium 5.5 19d ago FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-45796 medium 5.5 19d ago Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
CVE-2026-46357 medium 6.5 6.5 19d ago HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site crea…
CVE-2026-45785 medium 5.5 19d ago OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
CVE-2026-45784 medium 5.5 19d ago rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVE-2026-46339 critical 9.5 19d ago 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVE-2026-45695 critical 9.5 19d ago Kopia: RCE via SSH ProxyCommand Injection
CVE-2026-8096 medium 6.5 6.5 19d ago The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not p…
CVE-2026-41470 medium 5.9 5.9 sles 19d ago LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attack…
CVE-2026-34154 medium 5.3 5.3 discourse 19d ago Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain a…
CVE-2026-33741 medium 6.8 6.8 19d ago EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later…
CVE-2026-33642 critical 9.8 9.8 FIX debian debian kovidgoyal 19d ago Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …
CVE-2026-32738 medium 6.5 6.5 debian debian sles struktur 19d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer und…
CVE-2026-8605 critical 9.8 9.8 scadabr 19d ago In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
CVE-2026-8603 critical 9.8 9.8 scadabr 19d ago In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
CVE-2026-8602 critical 9.1 9.1 scadabr 19d ago In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
CVE-2026-32134 medium 5.9 5.9 19d ago NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the br…
CVE-2026-48019 unknown debian debian 19d ago Laravel CRLF injection in default email rule
CVE-2026-5511 low 2.7 2.7 tp-link 19d ago In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.  …
CVE-2026-36829 critical 9.8 9.8 19d ago An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based …
CVE-2026-36827 medium 5.4 5.4 19d ago A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters …
CVE-2026-46341 medium 5.5 19d ago Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
CVE-2026-46337 medium 5.3 5.3 wwbn 19d ago AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
CVE-2026-8706 medium 6.5 6.5 sles mozilla 19d ago Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…
CVE-2026-37281 critical 9.8 9.8 19d ago An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.
CVE-2026-31072 critical 9.8 9.8 debian debian sles 19d ago APScheduler's JSONSerializer and CBORSerializer are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
CVE-2026-31071 critical 9.1 9.1 19d ago API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…
CVE-2026-31070 critical 9.8 9.8 19d ago The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/…
CVE-2026-30118 critical 9.8 9.8 19d ago scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers…
CVE-2026-30117 critical 9.8 9.8 19d ago scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execut…
CVE-2026-45739 medium 4.3 4.3 strawberry 19d ago Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser U…
CVE-2026-45737 medium 5.5 19d ago Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
CVE-2026-45712 medium 5.5 19d ago Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVE-2026-45711 medium 5.5 19d ago Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
CVE-2026-45709 medium 5.5 19d ago Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
CVE-2026-45692 medium 5.5 19d ago Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
CVE-2026-45670 medium 5.5 19d ago Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
CVE-2026-45669 medium 5.5 19d ago Nuxt: Reflected XSS in `navigateTo()` external redirect
CVE-2026-45758 critical 9.6 9.6 19d ago Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. …
CVE-2026-45581 medium 5.5 19d ago fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
CVE-2026-45557 medium 5.8 5.8 19d ago Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network tr…
CVE-2026-44159 critical 9.8 9.8 19d ago Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 202…
CVE-2026-34883 medium 5.3 5.3 19d ago An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate priv…
CVE-2026-2587 critical 9.6 9.6 eclipse 19d ago GlassFish's gadget handler is vulnerable to RCE
CVE-2026-2586 critical 9.1 9.1 eclipse 19d ago GlassFish's Administration Console is Vulnerable to RCE
CVE-2026-45568 critical 9.5 19d ago rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
CVE-2026-46395 critical 9.5 19d ago HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementat…
CVE-2026-46496 medium 5.5 19d ago HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the `<video-p…
CVE-2026-45409 medium 5.5 slesdebian debian 19d ago Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prio…
CVE-2026-8971 medium 6.5 6.5 FIX debian debian sles mozilla 19d ago Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8951 medium 6.5 6.5 FIX debian debian sles mozilla 19d ago Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.
CVE-2026-8948 critical 9.1 9.1 FIX debian debian sles mozilla 19d ago Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-47323 critical 9.8 9.8 apache 19d ago Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
CVE-2026-43633 critical 10.0 10.0 19d ago HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated rem…
CVE-2026-23557 medium 6.5 6.5 slesdebian debian 19d ago Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will hap…
CVE-2025-40904 medium 5.4 5.4 nozominetworks 19d ago A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malici…
CVE-2025-40903 medium 4.8 4.8 nozominetworks 19d ago A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileg…
CVE-2025-40902 medium 4.8 4.8 nozominetworks 19d ago A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a mal…
CVE-2025-40901 medium 4.8 4.8 nozominetworks 19d ago A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges ca…
CVE-2025-40900 medium 4.6 4.6 nozominetworks 19d ago An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a mal…
CVE-2025-14575 unknown sleswindows windows 19d ago An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted syste…
CVE-2026-4883 critical 9.8 9.8 19d ago The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…
CVE-2026-7860 unknown 19d ago Vaadin Build Plugins is Affected by a Possible Information Disclosure Vulnerability
CVE-2026-4630 medium 6.8 6.8 redhat 19d ago A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtai…
CVE-2026-45442 medium 4.3 4.3 19d ago Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.…
CVE-2026-43493 critical 9.8 9.8 FIX slesdebian debianwindows windows 19d ago In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that va…
CVE-2026-43492 unknown FIX slesdebian debianwindows windows 19d ago In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() …
CVE-2026-43491 unknown FIX slesdebian debianwindows windows 19d ago In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added …
CVE-2026-37982 medium 6.8 6.8 redhat 19d ago Keycloak: Unauthorized account takeover via WebAuthn token replay
CVE-2026-37981 medium 4.3 4.3 redhat 19d ago A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) r…
CVE-2026-37979 medium 6.5 6.5 redhat 19d ago Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass
CVE-2026-37978 medium 4.9 4.9 redhat 19d ago Keycloak: Information Disclosure via evaluate-scopes Admin API
CVE-2026-8726 unknown 19d ago SQL Injection in extension "News system" (news)
CVE-2026-45434 critical 9.8 9.8 apache 20d ago Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgr…
CVE-2026-45187 medium 6.5 6.5 apache 20d ago Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVE-2026-41919 critical 9.1 9.1 apache 20d ago Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…
CVE-2026-35086 medium 6.5 6.5 apache 20d ago Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers…
CVE-2026-31986 critical 9.1 9.1 apache 20d ago Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVE-2026-31906 medium 6.1 6.1 apache 20d ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…
CVE-2026-31388 medium 5.3 5.3 apache 20d ago Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixe…
CVE-2026-31387 medium 5.3 5.3 apache 20d ago Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVE-2026-31380 medium 6.5 6.5 apache 20d ago Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06…
CVE-2026-31379 medium 6.1 6.1 apache 20d ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of…
CVE-2026-31378 medium 6.5 6.5 apache 20d ago Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVE-2026-2611 critical 9.6 9.6 lfprojects 20d ago MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
CVE-2026-29220 medium 6.5 6.5 apache 20d ago Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to v…
CVE-2026-29207 medium 6.5 6.5 apache 20d ago Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24…
CVE-2026-44408 medium 6.3 6.3 20d ago There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  modify configuration through the interface.
CVE-2022-49033 unknown FIX slesdebian debianubuntu ubuntu 20d ago Linux kernel vulnerabilities
CVE-2026-8922 medium 5.4 5.4 redhat 20d ago Keycloak: Revoked Tokens Can Remain Active When Both Realm-Level and Client-Level `notBefore` Revocation Policies are Configured
CVE-2026-4885 critical 9.8 9.8 20d ago The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…
CVE-2026-47314 critical 9.8 9.8 samsung 20d ago Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
CVE-2026-8830 medium 4.3 4.3 redhat 20d ago Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation
CVE-2026-8814 medium 5.3 5.3 20d ago ExifReader is vulnerable to denial of service via unbounded decompression of image metadata