Search

Found 58,594 results in 2404ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-8368 medium 6.5 6.5 FIX debian debian sleswindows windows 26d ago LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before …
CVE-2026-8109 medium 6.5 6.5 ivanti 26d ago An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
CVE-2026-8043 critical 9.6 9.6 ivanti 26d ago External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to …
CVE-2026-7431 medium 4.4 4.4 ivanti 26d ago An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…
CVE-2026-5061 medium 4.7 4.7 26d ago The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) …
CVE-2025-70842 medium 5.4 5.4 26d ago A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containin…
CVE-2026-45091 critical 9.1 9.1 26d ago sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
CVE-2026-43930 medium 5.9 5.9 parseplatform 26d ago parse-server: MFA SMS one-time password accepted twice under concurrent login
CVE-2026-42006 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 26d ago An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left op…
CVE-2026-40638 medium 6.7 6.7 dell 26d ago Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this v…
CVE-2026-40020 medium 4.3 4.3 FIX debian debian sles dovecotopen-xchange 26d ago Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is lim…
CVE-2026-40016 medium 6.5 6.5 FIX debian debian sles dovecotopen-xchange 26d ago Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to deg…
CVE-2026-33603 medium 5.3 5.3 FIX debian debian sles dovecotopen-xchange 26d ago Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the c…
CVE-2026-27851 critical 9.1 9.1 FIX debian debian sles dovecotopen-xchange 26d ago When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP …
CVE-2026-45215 medium 5.3 5.3 26d ago Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.
CVE-2026-45212 medium 5.3 5.3 26d ago Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset …
CVE-2026-45210 medium 5.4 5.4 26d ago Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broadstreet Ads: from n/a thr…
CVE-2026-32684 low 2.9 2.9 26d ago The application does not impose strict enough restrictions on directory access permissions, posing a risk that other malicious applications could obtain sensitive information.
CVE-2026-6813 medium 4.4 4.4 26d ago The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output esca…
CVE-2026-6800 medium 4.4 4.4 26d ago The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escapi…
CVE-2026-41551 critical 9.1 9.1 26d ago A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote …
CVE-2026-41125 medium 6.0 6.0 26d ago A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions), bluepla…
CVE-2026-33862 medium 6.1 6.1 siemens 26d ago A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All …
CVE-2026-25787 critical 9.1 9.1 26d ago Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authenticated attacker w…
CVE-2026-25786 critical 9.1 9.1 26d ago Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is author…
CVE-2026-22924 critical 9.1 9.1 26d ago A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion…
CVE-2026-1934 medium 4.3 4.3 26d ago The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the s…
CVE-2025-6577 critical 9.8 9.8 26d ago Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection. This iss…
CVE-2025-40949 critical 9.1 9.1 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2025-40948 medium 6.8 6.8 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2024-54017 medium 5.3 5.3 26d ago A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V11.0), SIPROTEC 5 6…
CVE-2026-7661 medium 6.4 6.4 26d ago The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitiza…
CVE-2026-7659 medium 6.4 6.4 26d ago The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, and including, 1.2. This is due to insufficient inp…
CVE-2026-7626 medium 5.3 5.3 26d ago The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_payment_redirect() function placing the merchant's slek_…
CVE-2026-7616 medium 4.3 4.3 26d ago The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the zawgyi_admin…
CVE-2026-7562 medium 4.3 4.3 26d ago The WP-Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.3. This is due to the absence of a nonce field in the admin settings form a…
CVE-2026-7561 medium 6.1 6.1 26d ago The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on a fu…
CVE-2026-7464 medium 6.1 6.1 26d ago The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.2. This is due to insufficient inp…
CVE-2026-7437 medium 6.1 6.1 26d ago The AzonPost plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `editpos_hidden` parameter in all versions up to, and including, 1.3. This is due to insufficient input sanit…
CVE-2026-7050 medium 4.3 4.3 26d ago The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. This is due to the plugin not properly verifying that a user is authorized to perf…
CVE-2026-6932 medium 4.3 4.3 26d ago The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.0.1. This is due to missing nonce verification on the settings u…
CVE-2026-6913 medium 6.4 6.4 26d ago The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…
CVE-2026-6808 medium 6.1 6.1 26d ago The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input …
CVE-2026-6710 medium 4.3 4.3 26d ago The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the Skysa…
CVE-2026-6709 medium 4.3 4.3 26d ago The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce…
CVE-2026-6708 medium 5.3 5.3 26d ago The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability che…
CVE-2026-6663 medium 4.8 4.8 26d ago The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints…
CVE-2026-6402 medium 6.5 6.5 sleswindows windows webpack.js 26d ago webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVE-2026-6256 medium 6.4 6.4 26d ago The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficie…
CVE-2026-6247 medium 6.4 6.4 26d ago The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due…
CVE-2026-6237 medium 6.4 6.4 26d ago The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient inp…
CVE-2026-5715 medium 6.4 6.4 26d ago The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, and including, 1.0.6 due to insuffic…
CVE-2026-5693 medium 5.3 5.3 26d ago The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking(…
CVE-2026-5340 medium 6.4 6.4 26d ago The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up to, and including, 9.1 due to insufficient input …
CVE-2026-5028 medium 6.5 6.5 26d ago The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and includ…
CVE-2026-4920 medium 6.4 6.4 26d ago The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization …
CVE-2026-4859 medium 6.4 6.4 26d ago The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up to, and including, 1.0.0 du…
CVE-2026-4301 medium 4.3 4.3 26d ago The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler la…
CVE-2026-3604 medium 4.9 4.9 26d ago The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficien…
CVE-2026-2300 medium 6.4 6.4 26d ago The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. This is due to the use of regex-base…
CVE-2026-1681 medium 6.1 6.1 26d ago Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the d…
CVE-2026-41530 low 3.3 3.3 26d ago The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability. When the affected product is configured with the automatic folder creation fe…
CVE-2026-7257 medium 4.4 4.4 26d ago ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker …
CVE-2026-7255 medium 6.5 6.5 26d ago ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could a…
CVE-2026-40137 medium 6.1 6.1 26d ago SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially e…
CVE-2026-40136 medium 4.3 4.3 26d ago SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromis…
CVE-2026-40135 medium 6.5 6.5 sap 26d ago An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially c…
CVE-2026-40134 medium 4.3 4.3 26d ago Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operatio…
CVE-2026-40133 medium 6.3 6.3 26d ago Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact o…
CVE-2026-40132 medium 5.4 5.4 26d ago Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unaut…
CVE-2026-40131 low 3.4 3.4 26d ago SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploi…
CVE-2026-40129 medium 4.3 4.3 26d ago Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processe…
CVE-2026-34263 critical 9.6 9.6 26d ago Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to hi…
CVE-2026-34260 critical 9.6 9.6 26d ago SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. The applica…
CVE-2026-34258 medium 4.7 4.7 26d ago SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicki…
CVE-2026-27682 medium 6.1 6.1 sap 26d ago Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that …
CVE-2026-0502 medium 5.4 5.4 26d ago Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This ha…
CVE-2026-45362 low 3.2 3.2 26d ago Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
CVE-2026-8349 medium 4.3 4.3 26d ago omec-project amf crashes when processing malformed LocationReports
CVE-2026-45321 critical 9.6 10.0 KEV tanstackmistralantoinebcx 26d ago TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
CVE-2026-43914 critical 9.8 9.8 dani-garcia 27d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is …
CVE-2026-43900 critical 9.3 9.3 27d ago DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepanc…
CVE-2026-43899 critical 9.6 9.6 27d ago DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerabl…
CVE-2026-42554 medium 6.1 6.1 gofiber 27d ago Fiber vulnerable to XSS in AutoFormat Content Negotiation
CVE-2026-34962 medium 5.5 5.5 pengutronix 27d ago barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directo…
CVE-2026-7010 medium 6.5 6.5 FIX debian debian 27d ago HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host t…
CVE-2026-44695 medium 6.5 6.5 getoutline 27d ago Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A…
CVE-2026-43889 medium 6.5 6.5 27d ago Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simultaneously and, when published=false, only verifie…
CVE-2026-42600 medium 4.9 4.9 minio 27d ago MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
CVE-2026-42188 low 2.4 2.4 27d ago Geyser Vulnerable to Server-Side Request Forgery (SSRF) via Player Head Texture URL in Geyser
CVE-2026-34960 medium 6.5 6.5 pengutronix 27d ago barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within …
CVE-2026-28967 medium 4.9 4.9 FIX macos macos ios 27d ago iOS 18.7.7 and iPadOS 18.7.7
CVE-2026-28910 low 3.3 3.3 FIX macos macos 27d ago macOS Tahoe 26.4
CVE-2026-28830 medium 4.7 4.7 FIX macos macos 27d ago macOS Tahoe 26.4
CVE-2026-20696 medium 5.5 5.5 FIX macos macos 27d ago macOS Tahoe 26.4
CVE-2026-8320 medium 4.7 4.7 27d ago A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of …
CVE-2026-8319 medium 5.3 5.3 27d ago aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function
CVE-2026-6146 medium 5.3 5.3 27d ago Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data d…
CVE-2026-45026 medium 6.8 6.8 27d ago WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …
CVE-2026-45025 medium 6.8 6.8 27d ago WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …