Search

Found 90,912 results in 4462ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-42013 high 8.2 8.2 FIX debian debian sles rhel 12d ago GnuTLS vulnerabilities
CVE-2026-42012 high 7.1 7.1 FIX debian debian rhelwindows windows 12d ago GnuTLS vulnerabilities
CVE-2026-5260 high 8.2 8.2 FIX debian debian sles rhel 12d ago GnuTLS vulnerabilities
CVE-2026-44903 medium 6.1 6.1 FIX slesdebian debian prometheus 12d ago Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-f…
CVE-2026-44905 high 7.5 7.5 12d ago Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza…
CVE-2026-43988 high 7.5 7.5 12d ago Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When pr…
CVE-2026-9583 medium 4.3 4.3 12d ago A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. E…
CVE-2026-9581 medium 6.3 6.3 12d ago A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can …
CVE-2026-8676 high 8.8 8.8 12d ago An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
CVE-2026-45575 high 7.4 7.4 12d ago epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI netwo…
CVE-2026-44897 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 12d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTM…
CVE-2026-44847 high 7.5 7.5 12d ago MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth clas…
CVE-2026-44443 medium 4.8 4.8 12d ago Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP…
CVE-2026-44209 high 7.5 7.5 12d ago Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass use…
CVE-2026-9584 high 7.3 7.3 12d ago A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql in…
CVE-2026-44895 high 8.0 12d ago GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin…
CVE-2026-45574 high 8.1 8.1 12d ago epa4all-client: TLS Certificate Validation Disabled in Production
CVE-2026-47672 medium 6.5 6.5 12d ago epa4all-client: Unauthenticated REST API for Patient Record Writes
CVE-2025-14361 high 7.1 7.1 12d ago Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n…
CVE-2026-9582 medium 4.3 4.3 12d ago A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site …
CVE-2026-44708 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 12d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied con…
CVE-2026-44899 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 12d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^…
CVE-2026-44896 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 12d ago Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options direc…
CVE-2026-48048 high 8.0 12d ago XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
CVE-2026-9580 high 7.3 7.3 12d ago A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access cont…
CVE-2026-44844 medium 5.5 windows windows 12d ago eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurse…
CVE-2026-44843 high 8.2 8.2 langchain 12d ago LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-9579 medium 6.3 6.3 12d ago A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument u…
CVE-2026-44836 medium 6.5 6.5 debian debian 12d ago view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls…
CVE-2026-44214 medium 5.3 5.3 rexxars 12d ago eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage b…
CVE-2026-48047 medium 5.5 12d ago XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
CVE-2026-25426 medium 5.3 5.3 12d ago Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking M…
CVE-2026-24520 medium 4.3 4.3 12d ago Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24.
CVE-2026-25444 medium 4.3 4.3 12d ago Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
CVE-2026-9575 high 7.3 7.3 12d ago A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulat…
CVE-2026-27331 medium 6.3 6.3 12d ago Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.
CVE-2026-8890 high 8.2 8.2 12d ago code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea…
CVE-2026-9574 high 7.3 7.3 12d ago A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the a…
CVE-2020-37127 unknown FIX debian debian slesubuntu ubuntu 12d ago Dnsmasq vulnerability
CVE-2026-9573 high 7.3 7.3 12d ago A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation o…
CVE-2026-34080 unknown FIX slesdebian debianubuntu ubuntu 12d ago xdg-dbus-proxy vulnerability
CVE-2026-6507 unknown FIX debian debian slesubuntu ubuntu 12d ago Dnsmasq vulnerability
CVE-2026-3603 high 7.1 7.1 ibm 12d ago IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML exter…
CVE-2026-8854 high 7.5 7.5 linux-kernel ibm 12d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
CVE-2026-8835 high 7.3 7.3 linux-kernel ibm 12d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive informat…
CVE-2026-8834 high 8.0 8.0 linux-kernel ibm 12d ago IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause …
CVE-2026-7453 medium 5.5 5.5 autodesk 12d ago A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.
CVE-2026-7450 medium 5.5 5.5 autodesk 12d ago A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a deni…
CVE-2026-48695 high 8.1 8.1 FIX debian debian pavel-odintsov 12d ago FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php…
CVE-2026-48694 high 8.1 8.1 FIX debian debian pavel-odintsov 12d ago FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK vari…
CVE-2026-44749 medium 4.3 4.3 12d ago The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leadi…
CVE-2026-44730 high 7.2 7.2 citeum 12d ago OpenCTI: Privilege escalation via graphQL API is abusable by organization admins, due to incorrect ACL on userEdit relationAdd
CVE-2026-44706 high 8.5 8.5 12d ago Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type da…
CVE-2026-44669 high 8.7 8.7 12d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview f…
CVE-2026-24195 high 7.1 7.1 12d ago NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-4051 high 7.2 7.2 ibm 12d ago IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.
CVE-2026-9568 medium 5.0 5.0 12d ago A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. Th…
CVE-2026-44728 high 8.2 8.2 slesdebian debian babel 12d ago Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…
CVE-2026-44667 high 8.7 8.7 12d ago FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification …
CVE-2026-9560 high 7.8 7.8 openvpn 12d ago Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
CVE-2026-41164 medium 4.4 4.4 12d ago nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token
CVE-2025-33221 medium 4.4 4.4 12d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of…
CVE-2026-24201 medium 5.8 5.8 12d ago NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering…
CVE-2026-24200 high 7.0 7.0 12d ago NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to den…
CVE-2026-24194 high 7.8 7.8 12d ago NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead t…
CVE-2026-24191 high 7.8 7.8 12d ago NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service,…
CVE-2026-24190 high 7.8 7.8 12d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability mi…
CVE-2026-24193 high 7.8 7.8 12d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, …
CVE-2026-24196 high 7.1 7.1 12d ago NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information dis…
CVE-2026-24197 medium 6.5 6.5 12d ago NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lea…
CVE-2026-24199 medium 4.7 4.7 nvidia 12d ago NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of…
CVE-2026-24198 medium 5.6 5.6 12d ago NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive informati…
CVE-2026-9565 medium 6.3 6.3 12d ago A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handle…
CVE-2026-9562 high 7.3 7.3 12d ago A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such mani…
CVE-2026-8852 high 7.5 7.5 linux-kernel ibm 12d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
CVE-2026-8850 high 7.5 7.5 linux-kernel ibm 12d ago IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
CVE-2026-48901 high 7.5 7.5 joomla 12d ago The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48864 high 7.8 7.8 debian debian sles rhel opensuseredhat 12d ago A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker ca…
CVE-2026-48697 high 7.4 7.4 debian debian pavel-odintsov 12d ago FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl…
CVE-2026-48693 medium 5.5 5.5 debian debian pavel-odintsov 12d ago FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp l…
CVE-2026-48690 high 7.1 7.1 FIX debian debian pavel-odintsov 12d ago FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memor…
CVE-2026-48126 high 8.2 8.2 12d ago Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request…
CVE-2026-47728 medium 4.3 4.3 12d ago Bugsink: Project scoping missing in sourcemap and debug-file lookup
CVE-2026-46431 medium 4.3 4.3 12d ago Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVE-2026-46430 medium 4.3 4.3 12d ago Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVE-2026-45836 unknown FIX slesdebian debianwindows windows 12d ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb() Add the same NULL guard already present in l2cap_sock_resume…
CVE-2026-45835 unknown FIX slesdebian debianwindows windows 12d ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() Add the same NULL guard already present in l2cap_sock_resu…
CVE-2026-45834 unknown FIX slesdebian debianwindows windows 12d ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() Add the same NULL guard already present in l2cap_sock_resume…
CVE-2026-45728 high 7.5 7.5 12d ago Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-44680 high 7.6 8.6 EXP 12d ago MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys
CVE-2026-44314 medium 4.3 4.3 traccar 12d ago Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and th…
CVE-2026-24182 medium 6.5 6.5 12d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-30894 medium 6.1 6.1 joomla 12d ago Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-24162 high 7.8 7.8 linux-kernel nvidia 12d ago NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code exec…
CVE-2025-36221 high 7.5 7.5 ibm 12d ago IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the inst…
CVE-2025-36145 medium 5.3 5.3 ibm 12d ago IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
CVE-2025-14290 medium 5.4 5.4 ibm 12d ago IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). Th…
CVE-2025-13755 medium 5.5 5.5 ibm 12d ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local …
CVE-2026-8620 high 7.5 7.5 ibm 12d ago IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggl…
CVE-2026-24192 high 7.8 7.8 12d ago NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this v…