Search

Found 38,471 results in 2147ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-5368 critical 9.8 9.8 projectworlds 2mo ago A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the…
CVE-2026-5360 low 3.7 3.7 free5gc 2mo ago A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. Thi…
CVE-2026-34877 critical 9.8 9.8 FIX debian debian armtrustedfirmware 2mo ago An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the ser…
CVE-2026-4636 unknown 2mo ago Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants
CVE-2026-4634 unknown 2mo ago Keycloak: Application-Level DoS via Scope Processing
CVE-2026-4325 unknown 2mo ago Keycloak: Replay of action tokens via improper handling of single-use entries
CVE-2026-4282 unknown 2mo ago Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
CVE-2026-3872 unknown 2mo ago Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint
CVE-2026-5334 critical 9.8 9.8 itsourcecode 2mo ago A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This …
CVE-2026-5333 critical 9.8 9.8 defaultfuction 2mo ago A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host res…
CVE-2026-5244 critical 9.8 9.8 FIX debian debian cesanta 2mo ago A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pu…
CVE-2026-5325 low 3.5 3.5 2mo ago A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create …
CVE-2026-3502 unknown 1.5 KEV 2mo ago TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the paylo…
CVE-2026-34525 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
CVE-2026-34520 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in res…
CVE-2026-34519 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject e…
CVE-2026-34518 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but re…
CVE-2026-34517 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking clie…
CVE-2026-34516 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory tha…
CVE-2026-34515 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This…
CVE-2026-34514 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra …
CVE-2026-34513 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situ…
CVE-2026-34873 critical 9.1 9.1 FIX slesdebian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.
CVE-2026-22815 unknown FIX slesdebian debian 2mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This i…
CVE-2026-34875 critical 9.8 9.8 FIX slesdebian debian trustedfirmware 2mo ago An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.
CVE-2026-34159 critical 9.8 9.8 FIX debian debian ggml 2mo ago llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthentica…
CVE-2026-34072 critical 9.8 9.8 fccview 2mo ago Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthe…
CVE-2026-5310 low 2.5 2.5 2mo ago A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph…
CVE-2026-34430 critical 9.6 9.6 deerflow 2mo ago ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing re…
CVE-2026-5257 critical 9.8 9.8 code-projects 2mo ago A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php of the component Parameter Handler. Such manipulati…
CVE-2026-5256 critical 9.8 9.8 code-projects 2mo ago A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Parameter Handler. This manipulation of the argument…
CVE-2026-5254 low 3.5 3.5 2mo ago A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component…
CVE-2026-5253 low 3.5 3.5 2mo ago A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component edi…
CVE-2026-5252 low 3.5 3.5 2mo ago A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation …
CVE-2026-5249 low 3.5 3.5 2mo ago A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulatio…
CVE-2026-5281 unknown 1.5 KEVFIX debian debian 2mo ago Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium securit…
CVE-2026-28886 unknown watchos iosmacos macos 2mo ago visionOS 26.4
CVE-2026-28880 unknown macos macos ios apple 2mo ago visionOS 26.4
CVE-2026-28879 unknown macos macos tvos ios 2mo ago visionOS 26.4
CVE-2026-28876 unknown iosmacos macos apple 2mo ago visionOS 26.4
CVE-2026-28868 unknown watchos iosmacos macos 2mo ago visionOS 26.4
CVE-2026-28867 unknown macos macos ios watchos 2mo ago visionOS 26.4
CVE-2026-28866 unknown macos macos ios 2mo ago macOS Sonoma 14.8.5
CVE-2026-28865 unknown tvosmacos macos ios 2mo ago visionOS 26.4
CVE-2026-28864 unknown macos macos watchos apple 2mo ago visionOS 26.4
CVE-2026-28852 unknown watchos iosmacos macos 2mo ago visionOS 26.4
CVE-2026-20690 unknown iosmacos macos tvos 2mo ago visionOS 26.4
CVE-2026-20687 unknown watchos iosmacos macos 2mo ago watchOS 26.4
CVE-2026-20668 unknown macos macos ios 2mo ago macOS Sonoma 14.8.5
CVE-2026-20637 unknown macos macos ios 2mo ago macOS Sonoma 14.8.5
CVE-2025-64505 unknown FIX debian debian sles apple 2mo ago visionOS 26.4
CVE-2025-43534 unknown ios 2mo ago iOS 18.7.7 and iPadOS 18.7.7
CVE-2025-43376 unknown ios 2mo ago iOS 18.7.7 and iPadOS 18.7.7
CVE-2025-14524 unknown FIX debian debian sles tvos 2mo ago When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass…
CVE-2026-5209 low 2.4 2.4 2mo ago A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipula…
CVE-2026-0596 critical 9.5 2mo ago Mlflow: Command Injection when serving models with enable_mlserver=True
CVE-2026-5183 critical 9.8 9.8 2mo ago A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Executing a manipulation of the argument dest can lead…
CVE-2026-5176 critical 9.8 9.8 2mo ago A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provid…
CVE-2026-34237 unknown 2mo ago MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
CVE-2026-34361 unknown 2mo ago FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
CVE-2026-34360 unknown 2mo ago FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
CVE-2026-34359 unknown 2mo ago HAPI FHIR Core has Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect
CVE-2026-34165 unknown FIX debian debian 2mo ago go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can ca…
CVE-2026-33762 unknown FIX debian debian 2mo ago go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applyi…
CVE-2025-15379 critical 9.8 9.8 lfprojects 2mo ago MLflow Command Injection vulnerability
CVE-2025-15036 critical 10.0 10.0 lfprojects 2mo ago MLFlow path traversal vulnerability
CVE-2026-3055 unknown 2.5 KEVEXP 2mo ago Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP lea…
CVE-2026-0562 unknown 2mo ago A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function …
CVE-2026-34214 unknown 2mo ago Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
CVE-2026-5037 low 3.3 3.3 FIX slesdebian debian 2mo ago A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr c…
CVE-2026-5035 critical 9.8 9.8 sherlock 2mo ago A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation of the argument en…
CVE-2026-5034 critical 9.8 9.8 sherlock 2mo ago A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation…
CVE-2026-5033 critical 9.8 9.8 sherlock 2mo ago A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The …
CVE-2026-5030 critical 9.8 9.8 2mo ago A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipul…
CVE-2026-5020 critical 9.8 9.8 2mo ago A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The ma…
CVE-2026-5019 critical 9.8 9.8 carmelo 2mo ago A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parame…
CVE-2026-5018 critical 9.8 9.8 carmelo 2mo ago A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulat…
CVE-2026-5017 critical 9.8 9.8 carmelo 2mo ago A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manip…
CVE-2026-4995 low 3.5 3.5 2mo ago A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message E…
CVE-2026-4994 low 3.5 3.5 2mo ago A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The mani…
CVE-2026-4973 low 3.5 3.5 2mo ago A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulatio…
CVE-2026-4972 low 2.4 2.4 2mo ago A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.ph…
CVE-2026-34073 unknown FIX slesdebian debian 2mo ago cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-4969 low 3.5 3.5 2mo ago A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the a…
CVE-2026-4963 critical 10.0 10.0 huggingface 2mo ago Hugging Face Smolagents has an Injection issue
CVE-2026-28369 unknown debian debian 2mo ago Undertow is Vulnerable to HTTP Request/Response Smuggling
CVE-2026-28368 unknown debian debian 2mo ago Undertow is Vulnerable to HTTP Request/Response Smuggling
CVE-2026-28367 unknown debian debian 2mo ago Undertow is Vulnerable to HTTP Request/Response Smuggling
CVE-2026-4965 critical 9.8 9.8 letta 2mo ago A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performin…
CVE-2026-33997 unknown FIX debian debian sles google 2mo ago Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. D…
CVE-2026-33945 unknown FIX debian debian sles 2mo ago Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Pri…
CVE-2026-33898 unknown FIX debian debian 2mo ago Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value wil…
CVE-2026-33897 unknown FIX debian debian sles 2mo ago Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for po…
CVE-2026-33743 unknown FIX debian debian 2mo ago Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to cras…
CVE-2026-33711 unknown FIX debian debian 2mo ago Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is …
CVE-2026-33542 unknown FIX debian debian sles 2mo ago Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to ima…
CVE-2026-32984 low 3.5 3.5 wazuh 2mo ago Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulne…
CVE-2026-4957 low 2.7 2.7 openbmb 2mo ago A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the component API Key Handler. This mani…
CVE-2026-22743 unknown 2mo ago Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
CVE-2026-22738 critical 9.8 9.8 vmware 2mo ago Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key