Search

Found 62,236 results in 2307ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41051 medium 5.0 5.0 FIX debian debian sles 25d ago csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.
CVE-2026-2515 medium 5.3 5.3 25d ago The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' fu…
CVE-2026-3004 medium 6.4 6.4 25d ago The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute in all versions up to, and including, 24.1.11 due to insufficient input sanitiz…
CVE-2025-14767 medium 5.5 5.5 25d ago The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and inc…
CVE-2026-6965 medium 5.3 5.3 26d ago The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.9.9. This is due to the `get_course_id_by…
CVE-2026-21022 medium 5.5 5.5 26d ago Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21021 medium 6.8 6.8 26d ago Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
CVE-2026-21018 medium 6.7 6.7 26d ago Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
CVE-2026-21016 medium 5.5 5.5 26d ago Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
CVE-2026-21015 medium 5.5 5.5 26d ago Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
CVE-2025-14033 medium 5.3 5.3 26d ago The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all ver…
CVE-2026-7619 medium 6.5 6.5 26d ago The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, a…
CVE-2026-7051 medium 5.4 5.4 26d ago The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 8.9.0. This is due to a missing ownership verific…
CVE-2026-6962 medium 6.4 6.4 26d ago The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_produc…
CVE-2026-6828 medium 6.4 6.4 26d ago The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permission_message' parameter in …
CVE-2025-9989 medium 4.4 4.4 26d ago The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output esc…
CVE-2025-9988 medium 4.3 4.3 26d ago The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This mak…
CVE-2025-9987 medium 5.3 5.3 26d ago The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for …
CVE-2025-14755 medium 5.3 5.3 26d ago The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct Object Reference (IDOR) in all versions up to, and including, 4.0.1 only when …
CVE-2026-8336 medium 6.5 6.5 mongodb 26d ago After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the se…
CVE-2026-8202 medium 6.5 6.5 mongodb 26d ago Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilizatio…
CVE-2026-8200 medium 5.3 5.3 mongodb 26d ago When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted.  This is…
CVE-2026-8199 medium 6.5 6.5 mongodb 26d ago An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and …
CVE-2026-44720 medium 5.5 26d ago OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access…
CVE-2026-33985 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-31885 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-31884 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-31883 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-29775 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-28971 medium 4.3 4.3 FIX safari iosmacos macos 26d ago visionOS 26.5
CVE-2026-28958 medium 5.5 5.5 FIX ios safarimacos macos 26d ago visionOS 26.5
CVE-2026-28946 medium 6.5 6.5 FIX safarimacos macos sles 26d ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari…
CVE-2026-28942 medium 6.5 6.5 FIX safari iosmacos macos 26d ago visionOS 26.5
CVE-2026-28917 medium 4.3 4.3 FIX safari iosmacos macos 26d ago visionOS 26.5
CVE-2026-28903 medium 6.5 6.5 FIX safari iosmacos macos 26d ago visionOS 26.5
CVE-2026-28902 medium 6.5 6.5 FIX safari iosmacos macos 26d ago visionOS 26.5
CVE-2026-28901 medium 4.3 4.3 FIX safari iosmacos macos 26d ago visionOS 26.5
CVE-2026-27951 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-26986 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-25952 medium 5.5 FIX rheldebian debian sles 26d ago Moderate: freerdp security update
CVE-2026-44347 medium 6.5 6.5 warpgate_project 26d ago Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user in…
CVE-2026-44341 medium 5.3 5.3 26d ago GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. Th…
CVE-2026-44245 medium 6.1 6.1 kyverno 26d ago Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
CVE-2025-15463 medium 6.5 6.5 26d ago The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users …
CVE-2026-44652 medium 5.5 26d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44651 medium 5.5 26d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44305 medium 6.8 6.8 26d ago Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
CVE-2026-44259 medium 4.6 4.6 26d ago efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME type based on file extension, without any content sanitization or security heade…
CVE-2026-42545 medium 5.9 5.9 26d ago Granian vulnerable to DoS via WSGI response header panic
CVE-2026-41195 medium 5.0 5.0 26d ago mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker…
CVE-2026-35555 medium 6.3 6.3 26d ago PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
CVE-2026-33570 medium 5.7 5.7 26d ago PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.
CVE-2026-35504 medium 5.5 5.5 26d ago PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
CVE-2026-8052 medium 6.0 6.0 26d ago HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack
CVE-2026-6959 medium 6.0 6.0 26d ago HashiCorp Nomad vulnerable to symlink attack
CVE-2026-44874 medium 4.9 4.9 26d ago A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Succe…
CVE-2026-44873 medium 5.4 5.4 arubanetworks 26d ago A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated wh…
CVE-2026-44223 medium 6.5 6.5 vllm 26d ago vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect sh…
CVE-2026-44217 medium 5.5 26d ago sse-channel: SSE Injection via unsanitized event fields
CVE-2026-42445 medium 5.5 5.5 m2team 26d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPat…
CVE-2026-42444 medium 5.5 5.5 m2team 26d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method re…
CVE-2026-42443 medium 5.5 5.5 m2team 26d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when …
CVE-2026-42442 medium 5.5 5.5 m2team 26d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when…
CVE-2026-42355 medium 5.5 5.5 m2team 26d ago NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .…
CVE-2026-42338 medium 6.1 6.1 debian debian beaugunderson 26d ago ip-address has XSS in Address6 HTML-emitting methods
CVE-2026-34688 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34680 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…
CVE-2026-34679 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34678 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34677 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34673 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…
CVE-2026-34672 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…
CVE-2026-34671 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…
CVE-2026-34670 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34669 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34668 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34667 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…
CVE-2026-34666 medium 6.2 6.2 adobe 26d ago CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …
CVE-2026-34658 medium 4.8 4.8 adobe 26d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…
CVE-2026-34656 medium 4.3 4.3 adobe 26d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature by…
CVE-2026-34655 medium 4.8 4.8 adobe 26d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…
CVE-2026-34654 medium 5.3 5.3 adobe 26d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result i…
CVE-2026-34664 medium 6.3 6.3 adobe 26d ago Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file sy…
CVE-2026-23822 medium 5.3 5.3 26d ago A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an at…
CVE-2026-5146 medium 4.3 4.3 devolutions 26d ago Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session v…
CVE-2026-44279 medium 5.5 5.5 fortinet 26d ago A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow atta…
CVE-2026-44278 medium 5.5 5.5 fortinet 26d ago A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert at…
CVE-2026-44204 medium 6.5 6.5 26d ago Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role)…
CVE-2026-42891 medium 6.5 6.5 windows windows microsoft 26d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-42838 medium 5.4 5.4 windows windows microsoft 26d ago Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a netw…
CVE-2026-42830 medium 6.5 6.5 windows windows microsoft 26d ago Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-42541 medium 4.3 4.3 26d ago Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
CVE-2026-42303 medium 5.5 26d ago Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
CVE-2026-42177 medium 5.3 5.3 FIX debian debian 26d ago linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter i…
CVE-2026-42175 medium 6.5 6.5 26d ago requests-hardened is Vulnerable to Server-Side Request Forgery
CVE-2026-42045 medium 6.2 6.2 26d ago LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
CVE-2026-41614 medium 6.2 6.2 windows windows microsoft 26d ago Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41612 medium 5.5 5.5 windows windows microsoft 26d ago Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
CVE-2026-41610 medium 6.3 6.3 windows windows microsoft 26d ago Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-41100 medium 4.4 4.4 windows windows microsoft 26d ago Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.