Search

Found 41,694 results in 6423ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-4988 high 7.3 7.3 26d ago Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…
CVE-2026-44657 high 8.0 27d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execu…
CVE-2026-44655 high 8.0 27d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator acces…
CVE-2026-43898 critical 10.0 10.0 nyariv 27d ago SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That ca…
CVE-2026-42071 high 8.0 27d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to…
CVE-2026-40607 high 8.0 27d ago MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
CVE-2026-40597 high 8.0 27d ago MantisBT has a Content Security Policy bypass via attachments
CVE-2026-40596 high 8.0 27d ago MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
CVE-2026-39850 high 7.4 7.4 27d ago Yii 2: Local file inclusion via view parameter name collision
CVE-2026-34463 high 8.0 27d ago MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
CVE-2026-7790 high 7.5 7.5 debian debianwindows windows ninenines 27d ago Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number …
CVE-2026-45224 high 7.1 7.1 27d ago Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolution
CVE-2026-45223 high 8.8 8.8 27d ago Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin …
CVE-2026-42864 critical 9.9 9.9 27d ago FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
CVE-2026-2393 high 7.1 7.1 lfprojects 27d ago MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-7818 high 7.8 7.8 sles pgadmin 27d ago pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
CVE-2026-31253 high 7.3 7.3 27d ago flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism
CVE-2026-8305 critical 9.8 9.8 openclaw 27d ago A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component blueb…
CVE-2026-7210 critical 9.8 9.8 slesdebian debianwindows windows libexpat_projectpython 27d ago `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this…
CVE-2026-5172 high 7.3 7.3 FIX debian debian sleswindows windows 27d ago A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advanc…
CVE-2026-45006 high 8.8 8.8 openclaw 27d ago OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration…
CVE-2026-45004 high 7.8 7.8 openclaw 27d ago OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
CVE-2026-45001 high 7.1 7.1 openclaw 27d ago OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox p…
CVE-2026-44995 high 7.3 7.3 openclaw 27d ago OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
CVE-2026-44413 high 7.5 7.5 jetbrains 27d ago In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-43995 critical 9.8 9.8 flowiseai 27d ago Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
CVE-2026-43640 high 8.1 8.1 bitwarden 27d ago Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management …
CVE-2026-43639 critical 9.1 9.1 bitwarden 27d ago Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{provide…
CVE-2026-42858 critical 9.9 9.9 openedx 27d ago Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply …
CVE-2026-42856 high 8.0 27d ago Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
CVE-2026-42313 high 8.3 8.3 pyload-ng_project 27d ago pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …
CVE-2026-41431 high 8.0 8.0 27d ago Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Fi…
CVE-2026-3609 high 7.8 7.8 wellbia 27d ago Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cr…
CVE-2026-38568 high 8.1 8.1 27d ago HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve …
CVE-2026-38567 critical 9.8 9.8 27d ago HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker c…
CVE-2026-38566 high 8.1 8.1 27d ago HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission …
CVE-2026-36983 high 7.3 7.3 27d ago D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.
CVE-2026-36962 high 7.3 7.3 27d ago SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution…
CVE-2026-30635 high 8.1 8.1 27d ago automagik-genie has a command injection vulnerability
CVE-2026-27478 critical 9.5 27d ago Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
CVE-2026-42603 high 8.8 8.8 27d ago OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_ta…
CVE-2026-42349 high 8.1 8.1 clerk 27d ago Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other…
CVE-2026-33362 high 8.6 8.6 27d ago In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded an…
CVE-2026-33361 high 7.5 7.5 27d ago In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversi…
CVE-2026-33359 high 7.5 7.5 27d ago In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforce…
CVE-2026-33357 high 7.5 7.5 27d ago In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearic…
CVE-2026-33356 high 7.7 7.7 27d ago In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. …
CVE-2026-31254 high 7.3 7.3 27d ago The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python …
CVE-2026-31251 high 7.3 7.3 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads…
CVE-2026-31250 high 7.3 7.3 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads…
CVE-2026-31249 high 7.3 7.3 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script l…
CVE-2026-31248 high 7.5 7.5 27d ago Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-7819 high 8.1 8.1 sles pgadmin 27d ago pgAdmin 4 File Manager has symbolic-link path traversal
CVE-2026-7816 high 8.8 8.8 sles pgadmin 27d ago pgAdmin 4: OS command injection vulnerability in Import/Export query export
CVE-2026-7815 high 8.8 8.8 sles pgadmin 27d ago SQL injection vulnerability in pgAdmin 4 Maintenance Tool
CVE-2026-7813 critical 9.9 9.9 sles pgadmin 27d ago pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules
CVE-2026-44643 critical 10.0 10.0 peerigon 27d ago Angular Expressions - Remote Code Execution using filters
CVE-2026-34092 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Skin/Skin.Php. This issue…
CVE-2026-34091 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34090 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.
CVE-2026-34088 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34087 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-31247 high 7.5 7.5 27d ago Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2025-65418 high 7.5 7.5 27d ago docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
CVE-2025-61314 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in…
CVE-2025-61313 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascrip…
CVE-2025-61312 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in …
CVE-2025-61311 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in t…
CVE-2026-44543 high 8.7 8.7 27d ago Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in …
CVE-2026-44521 high 8.8 8.8 27d ago elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…
CVE-2026-44477 critical 9.9 9.9 linuxfoundation 27d ago CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as t…
CVE-2026-45017 high 7.5 7.5 jg-rp 27d ago Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search pa…
CVE-2026-44345 high 8.8 8.8 bentoml 27d ago BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
CVE-2026-44338 high 7.3 7.3 praison 27d ago PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-4802 high 8.0 8.0 FIX debian debian rhel sles 27d ago A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links i…
CVE-2025-9973 high 7.2 7.2 wso2 27d ago Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations.…
CVE-2025-10470 high 8.6 8.6 wso2 27d ago The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerabilit…
CVE-2026-41951 high 7.2 7.2 27d ago Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
CVE-2026-40636 high 7.8 7.8 dell 27d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could p…
CVE-2026-35157 critical 9.8 9.8 dell 27d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthentic…
CVE-2026-32658 high 8.8 8.8 dell 27d ago Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …
CVE-2025-8325 high 8.8 8.8 wso2 27d ago The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This…
CVE-2025-8154 high 7.5 7.5 wso2 27d ago In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses…
CVE-2025-10908 high 7.3 7.3 wso2 27d ago Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security …
CVE-2026-43500 high 7.8 8.8 EXPFIX slesdebian debian linux-kernel 27d ago In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and th…
CVE-2026-6433 high 7.3 7.3 27d ago The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execut…
CVE-2026-8273 high 7.2 7.2 27d ago A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation caus…
CVE-2026-8272 high 7.2 7.2 27d ago A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os comma…
CVE-2026-8271 high 7.2 7.2 27d ago A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the f…
CVE-2026-8265 high 7.2 7.2 27d ago A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the…
CVE-2026-8264 high 8.8 8.8 27d ago A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation …
CVE-2026-8263 critical 9.8 9.8 27d ago A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipula…
CVE-2026-8260 high 8.8 8.8 27d ago A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipu…
CVE-2026-8259 high 7.2 7.2 27d ago A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip lea…
CVE-2026-43668 high 7.5 7.5 FIX iosmacos macos tvos 27d ago visionOS 26.5
CVE-2026-43661 high 7.5 7.5 FIX iosmacos macos tvos 27d ago watchOS 26.5
CVE-2026-43656 high 7.3 7.3 FIX iosmacos macos 27d ago An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, ma…
CVE-2026-43655 high 7.3 7.3 FIX iosmacos macos tvos 27d ago watchOS 26.5
CVE-2026-43654 high 7.5 7.5 FIX iosmacos macos tvos 27d ago visionOS 26.5
CVE-2026-43652 high 7.5 7.5 FIX macos macos 27d ago A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.