Search

Found 69,854 results in 2974ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6401 medium 4.3 4.3 18d ago The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update fo…
CVE-2026-6400 medium 4.3 4.3 18d ago The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the opti…
CVE-2026-6399 medium 4.4 4.4 18d ago The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use of sanitize_text_field() for output escaping in the…
CVE-2026-6397 medium 6.4 6.4 18d ago The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This is due to insufficien…
CVE-2026-6395 medium 6.1 6.1 18d ago The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of n…
CVE-2026-6394 medium 5.4 5.4 18d ago The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due…
CVE-2026-6391 medium 6.1 6.1 18d ago The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect no…
CVE-2026-6072 medium 6.5 6.5 18d ago The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin prote…
CVE-2026-5293 medium 6.4 6.4 18d ago The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing autho…
CVE-2026-43620 medium 5.5 5.5 FIX slesdebian debianwindows windows samba 18d ago Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver.c that allows a malicious rsync server to crash the rsync client process. Atta…
CVE-2026-43619 medium 6.3 6.3 FIX slesdebian debianwindows windows samba 18d ago Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unlink, mkdir, symlink, mknod, link, rmdir, and lstat …
CVE-2026-43618 high 8.1 8.1 FIX slesdebian debianwindows windows samba 18d ago Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigg…
CVE-2026-43617 medium 4.8 4.8 FIX slesdebian debianwindows windows samba 18d ago Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass host…
CVE-2026-3985 high 7.5 7.5 18d ago The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. T…
CVE-2026-45585 medium 6.8 6.8 windows windows 18d ago Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coor…
CVE-2026-39309 medium 5.5 5.5 18d ago Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to …
CVE-2026-35593 medium 6.8 6.8 18d ago Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, al…
CVE-2026-46333 high 7.1 7.1 FIX rhel slesdebian debian google 18d ago RHSA-2026:23470: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_40_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update (Important)
CVE-2026-46300 high 7.8 8.8 EXPFIX rhel slesdebian debian awsgoogle 18d ago RHSA-2026:23470: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_40_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update (Important)
CVE-2026-43163 medium 4.7 4.7 FIX rhel slesdebian debian 18d ago In the Linux kernel, the following vulnerability has been resolved: md/bitmap: fix GPF in write_page caused by resize race A General Protection Fault occurs in write_page() during array resize: RIP…
CVE-2026-43128 high 7.8 7.8 FIX rhel slesdebian debian 18d ago In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix double dma_buf_unpin in failure path In ib_umem_dmabuf_get_pinned_with_dma_device(), the call to ib_umem_dmabuf_ma…
CVE-2026-37555 high 7.5 7.5 FIX rheldebian debian sles libsndfile_project 18d ago RHSA-2026:19559: libsndfile security update (Important)
CVE-2026-31532 high 7.8 7.8 FIX rhel slesdebian debian google 18d ago In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive filters via can_rx_unregister(), but…
CVE-2026-23401 high 8.0 FIX rhel slesdebian debian google 18d ago In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE When installing an emulated MMIO SPTE, do so *after*…
CVE-2026-23204 high 7.1 7.1 FIX rocky rhel sles 18d ago Moderate: kernel security update
CVE-2026-22990 high 8.0 FIX rhel slesdebian debian 18d ago In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciously) corrupted such that the incremen…
CVE-2026-22984 high 8.0 FIX rhel slesdebian debian 18d ago In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an explicit bounds check on payload_len to avoid a p…
CVE-2025-71116 high 8.0 FIX rhel slesdebian debian 18d ago In the Linux kernel, the following vulnerability has been resolved: libceph: make decode_pool() more resilient against corrupted osdmaps If the osdmap is (maliciously) corrupted such that the encod…
CVE-2025-68741 high 8.0 FIX rhel slesdebian debian 18d ago Important: kernel security update
CVE-2025-39766 high 7.8 7.8 FIX rhel slesdebian debian 18d ago Important: kernel security update
CVE-2026-8493 medium 5.4 5.4 colorbox_inline_project 18d ago This module enables you to open content already on the page within a colorbox. The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading …
CVE-2026-6871 medium 6.1 6.1 obfuscate_project 18d ago This module enables you to obfuscate email addresses in content. The module doesn't sufficiently sanitize user input via the Twig filter. This vulnerability is mitigated by the fact that it only af…
CVE-2026-6367 medium 6.1 6.1 drupal 18d ago Drupal core allows Cross-Site Scripting (XSS)
CVE-2026-6366 medium 6.6 6.6 drupal 18d ago Drupal core allows Object Injection
CVE-2026-6365 medium 6.1 6.1 drupal 18d ago Drupal core is Vulnerable to Cross-Site Scripting
CVE-2026-6095 medium 6.1 6.1 gaya 18d ago The IframeConsent element writes HTML attributes without escaping their value. This module has a XSS vulnerability. If an attacker is able to write an `<iframe-consent>` tag, they may be able to ins…
CVE-2026-34600 medium 5.7 5.7 18d ago Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients …
CVE-2026-5090 medium 6.1 6.1 FIX debian debian 18d ago Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could…
CVE-2026-34358 high 8.1 8.1 18d ago CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on …
CVE-2026-34246 medium 4.8 4.8 18d ago CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In a…
CVE-2026-34241 high 8.7 8.7 18d ago CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitize…
CVE-2025-15645 medium 4.6 4.6 18d ago Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. A…
CVE-2023-7345 medium 6.5 6.5 18d ago Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting inc…
CVE-2026-39250 high 7.3 7.3 18d ago An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations.
CVE-2026-34233 medium 6.5 6.5 18d ago CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers expose DataTable endpoints without authorization checks, allowing any authenti…
CVE-2026-34216 medium 6.6 6.6 18d ago CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied requ…
CVE-2026-32882 high 7.1 7.1 debian debian sles 18d ago libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overla…
CVE-2026-32814 medium 6.5 6.5 debian debian sles 18d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to …
CVE-2026-32741 high 7.1 7.1 debian debian sles 18d ago libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mas…
CVE-2025-57798 medium 5.5 5.5 18d ago Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial of Service (DoS) vulnerability in the title input …
CVE-2026-46417 high 8.0 18d ago @angular/platform-server: SSRF via Hostname Hijacking
CVE-2026-46415 high 8.0 18d ago Caddy Defender trusted proxy client IP bypass
CVE-2026-42526 medium 5.3 5.3 18d ago Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
CVE-2026-32740 high 8.8 8.8 debian debian sles struktur 18d ago libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write …
CVE-2026-32739 medium 6.5 6.5 debian debian sles struktur 18d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 1…
CVE-2026-27173 high 8.7 8.7 18d ago Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
CVE-2026-46410 high 8.0 18d ago FileBrowser Quantum: unauthenticated user share share info
CVE-2026-46374 high 8.0 18d ago SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
CVE-2026-46373 high 8.0 18d ago SQLFluff: Recursive Stack Overflow in Parser
CVE-2026-46372 high 8.5 8.5 18d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-46378 high 8.0 18d ago Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
CVE-2026-46377 high 8.0 18d ago Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
CVE-2026-45783 high 8.0 18d ago @libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
CVE-2026-46338 medium 5.5 18d ago Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
CVE-2026-45805 high 8.0 18d ago PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
CVE-2026-45802 medium 5.5 18d ago FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-45799 high 8.0 18d ago Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
CVE-2026-45796 medium 5.5 18d ago Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
CVE-2026-46357 medium 6.5 6.5 18d ago HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site crea…
CVE-2026-45785 medium 5.5 18d ago OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
CVE-2026-45784 medium 5.5 18d ago rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVE-2026-8096 medium 6.5 6.5 18d ago The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not p…
CVE-2026-8073 high 7.5 7.5 18d ago The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in …
CVE-2026-41470 medium 5.9 5.9 sles 18d ago LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attack…
CVE-2026-34154 medium 5.3 5.3 discourse 18d ago Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain a…
CVE-2026-33741 medium 6.8 6.8 18d ago EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later…
CVE-2026-32738 medium 6.5 6.5 debian debian sles struktur 18d ago libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer und…
CVE-2026-8604 high 8.8 8.8 scadabr 18d ago In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
CVE-2026-47107 high 8.1 8.1 18d ago Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authentica…
CVE-2026-33633 high 8.8 8.8 FIX debian debian kovidgoyal 18d ago Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash ki…
CVE-2026-32134 medium 5.9 5.9 18d ago NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the br…
CVE-2025-61081 high 7.5 7.5 18d ago Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2026-47358 high 8.6 8.6 tenable 18d ago Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …
CVE-2026-47357 high 8.6 8.6 tenable 18d ago Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/sca…
CVE-2026-47356 high 8.6 8.6 tenable 18d ago Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when run…
CVE-2026-36828 high 8.8 8.8 18d ago A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell…
CVE-2026-36827 medium 5.4 5.4 18d ago A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters …
CVE-2026-46341 medium 5.5 18d ago Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
CVE-2026-46337 medium 5.3 5.3 wwbn 18d ago AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
CVE-2026-8706 medium 6.5 6.5 sles mozilla 18d ago Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…
CVE-2026-5804 high 8.4 8.4 18d ago An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external …
CVE-2026-31069 high 8.8 8.8 18d ago BillaBear is Vulnerable to SQL Injection in the EventRepository
CVE-2026-45739 medium 4.3 4.3 strawberry 18d ago Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser U…
CVE-2026-45738 high 8.0 18d ago Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
CVE-2026-45737 medium 5.5 18d ago Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
CVE-2026-45713 high 8.0 18d ago Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
CVE-2026-45712 medium 5.5 18d ago Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVE-2026-45711 medium 5.5 18d ago Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
CVE-2026-45709 medium 5.5 18d ago Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
CVE-2026-45692 medium 5.5 18d ago Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization