Search

Found 66,632 results in 3873ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44970 low 2.5 24d ago dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
CVE-2026-44969 low 2.5 24d ago dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
CVE-2026-44968 medium 5.5 24d ago dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
CVE-2026-46469 medium 5.5 5.5 FIX debian debian slesubuntu ubuntu freedesktop 24d ago GStreamer Good Plugins vulnerabilities
CVE-2026-44544 medium 5.5 debian debian 24d ago gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted …
CVE-2026-44520 medium 5.7 5.7 24d ago docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
CVE-2026-44283 medium 4.3 4.3 FIX debian debian sleswindows windows etcd 24d ago etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
CVE-2026-42572 medium 6.5 6.5 hatchet 24d ago Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
CVE-2026-41888 medium 6.5 6.5 debian debian sles distribution 24d ago Distribution's tag deletion bypasses `storage.delete.enabled` configuration
CVE-2026-6923 low 3.8 3.8 24d ago A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
CVE-2026-45448 medium 4.3 4.3 24d ago CWE-601 URL redirection to untrusted site ('open redirect')
CVE-2026-44514 medium 6.5 6.5 24d ago Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated users
CVE-2026-44348 low 2.5 2.5 FIX debian debian sles 24d ago PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFin…
CVE-2026-20210 medium 5.4 5.4 24d ago A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform …
CVE-2026-20209 medium 5.4 5.4 24d ago A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low …
CVE-2025-62317 low 2.6 2.6 24d ago HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary syst…
CVE-2025-62316 low 2.3 2.3 24d ago HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based securi…
CVE-2025-62313 medium 5.4 5.4 24d ago HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized …
CVE-2025-62312 low 3.0 3.0 24d ago HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse,…
CVE-2025-62311 medium 4.3 4.3 24d ago HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized a…
CVE-2025-62310 medium 5.4 5.4 24d ago HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized …
CVE-2025-62309 low 2.6 2.6 24d ago HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to…
CVE-2025-62308 medium 5.1 5.1 24d ago HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details,…
CVE-2025-62305 medium 5.1 5.1 24d ago HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allo…
CVE-2026-44898 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 24d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used a…
CVE-2026-45292 medium 5.3 5.3 24d ago opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggag…
CVE-2026-44884 medium 6.5 6.5 portainer 24d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-44885 medium 5.5 5.5 portainer 24d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-45076 low 2.7 2.7 FIX debian debian element 24d ago Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full h…
CVE-2026-45078 medium 5.5 5.5 FIX debian debian element 24d ago Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing o…
CVE-2026-44722 medium 5.5 24d ago pyzipper has an encryption bypass for small files encrypted using it
CVE-2026-42597 medium 5.9 5.9 thecodingmachine 24d ago Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
CVE-2026-42593 medium 5.3 5.3 thecodingmachine 24d ago Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
CVE-2026-42592 medium 5.3 5.3 thecodingmachine 24d ago Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
CVE-2026-42159 medium 5.4 5.4 flowsint 24d ago Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, whic…
CVE-2026-42853 medium 5.5 24d ago @apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
CVE-2026-44374 medium 4.3 4.3 linuxfoundation 24d ago Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permissi…
CVE-2026-44308 medium 5.5 24d ago Spring Cloud AWS missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications
CVE-2026-41933 medium 5.3 5.3 24d ago Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking pro…
CVE-2026-41932 medium 6.1 6.1 24d ago Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name fiel…
CVE-2026-24711 medium 5.3 5.3 northern.tech 24d ago Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
CVE-2026-24710 medium 6.1 6.1 northern.tech 24d ago Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
CVE-2026-21730 medium 6.1 6.1 verint 24d ago Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and p…
CVE-2025-69443 medium 6.3 6.3 24d ago Remote Code Execution in coleam00 Archon 0.1.0. A crafted HTML page, when accessed by a victim, can execute commands, run prompts on behalf of the user, control the Archon UI features, and steal all …
CVE-2026-6575 medium 4.3 4.3 FIX slesdebian debianubuntu ubuntu postgresql 24d ago PostgreSQL vulnerabilities
CVE-2026-6478 medium 6.5 6.5 FIX slesdebian debianwindows windows postgresql 24d ago PostgreSQL vulnerabilities
CVE-2026-6474 medium 4.3 4.3 FIX slesdebian debianwindows windows postgresql 24d ago PostgreSQL vulnerabilities
CVE-2026-6472 medium 5.4 5.4 FIX slesdebian debianwindows windows postgresql 24d ago PostgreSQL vulnerabilities
CVE-2026-6008 medium 6.8 6.8 24d ago Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. …
CVE-2026-43644 medium 6.1 6.1 stefanprodan 24d ago podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without …
CVE-2026-45205 medium 5.3 5.3 FIX debian debian sles apache 24d ago Apache Commons Configuration: StackOverflowError for YAML input with cycles
CVE-2026-8295 unknown windows windows 24d ago An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on p…
CVE-2026-6504 medium 6.4 6.4 24d ago The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 1.7.1058 due to insuffic…
CVE-2026-6206 medium 5.3 5.3 24d ago The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restri…
CVE-2026-6174 medium 6.4 6.4 24d ago The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and ou…
CVE-2026-6145 medium 5.3 5.3 24d ago The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relyi…
CVE-2026-6670 medium 6.5 6.5 24d ago The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the 'sub_dir' and 'media_items' parameters. This is due to insufficient validation …
CVE-2026-6252 medium 6.4 6.4 24d ago The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute in all versions up to, and including, 1.5.2 due to insufficient input sanitiza…
CVE-2026-6225 medium 6.5 6.5 24d ago The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'project_search' parameter in all versions u…
CVE-2026-5365 medium 4.3 4.3 24d ago The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() funct…
CVE-2026-5193 medium 6.5 6.5 24d ago The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insu…
CVE-2026-3694 medium 6.4 6.4 24d ago The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the bt_bb_button shortcode in all versions up to, and including, 5.6.8. This is due…
CVE-2026-8280 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause den…
CVE-2026-8144 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with projec…
CVE-2026-7481 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer…
CVE-2026-7471 low 3.5 3.5 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control o…
CVE-2026-7377 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allow…
CVE-2026-6883 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merg…
CVE-2026-6417 medium 6.1 6.1 24d ago The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failed_orders' parameter in all versions up to, and including, 1.4.0 due to insufficient…
CVE-2026-6335 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in ano…
CVE-2026-6073 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arb…
CVE-2026-6063 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authent…
CVE-2026-5243 medium 6.4 6.4 24d ago The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` …
CVE-2026-4527 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to creat…
CVE-2026-4524 medium 6.5 6.5 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access…
CVE-2026-3829 medium 5.4 5.4 24d ago The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks…
CVE-2026-3607 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with develo…
CVE-2026-3160 medium 5.8 5.8 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jir…
CVE-2026-3074 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to downlo…
CVE-2026-3073 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with develo…
CVE-2026-2900 low 2.7 2.7 gitlab 24d ago GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention w…
CVE-2026-1338 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with devel…
CVE-2025-15345 medium 6.1 6.1 24d ago The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.2…
CVE-2025-13874 medium 4.3 4.3 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest …
CVE-2025-12669 medium 5.4 5.4 gitlab 24d ago GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject …
CVE-2026-7648 medium 4.3 4.3 24d ago The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. …
CVE-2026-7525 medium 4.3 4.3 24d ago The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying tha…
CVE-2026-5361 medium 6.4 6.4 24d ago The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in th…
CVE-2026-5486 medium 6.5 6.5 25d ago The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.…
CVE-2026-44919 medium 4.3 4.3 FIX debian debian 25d ago In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
CVE-2026-41281 medium 4.8 4.8 25d ago Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify commun…
CVE-2026-44448 medium 6.5 6.5 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyo…
CVE-2026-44445 medium 6.5 6.5 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enab…
CVE-2026-44441 medium 4.3 4.3 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making…
CVE-2026-44440 medium 5.7 5.7 frappe 25d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on …
CVE-2026-44437 medium 6.1 6.1 angular 25d ago The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix he…
CVE-2026-44426 medium 6.5 6.5 shellhub 25d ago ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
CVE-2026-44425 medium 5.4 5.4 shellhub 25d ago ShellHub has crash-DoS via field injection in filter and sort-by parameters
CVE-2026-44424 medium 6.5 6.5 shellhub 25d ago ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
CVE-2026-44423 medium 6.5 6.5 shellhub 25d ago ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data