Search

Found 62,236 results in 5296ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-41097 medium 6.7 6.7 FIX windows windows 26d ago Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-40421 medium 4.3 4.3 windows windows microsoft 26d ago Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40416 medium 4.3 4.3 windows windows microsoft 26d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-40380 medium 6.2 6.2 FIX windows windows 26d ago Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
CVE-2026-40374 medium 6.5 6.5 windows windows microsoft 26d ago Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2026-35440 medium 5.5 5.5 windows windows microsoft 26d ago Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-35429 medium 4.3 4.3 windows windows microsoft 26d ago User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35423 medium 5.4 5.4 FIX windows windows 26d ago Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-35422 medium 6.5 6.5 FIX windows windows 26d ago Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
CVE-2026-35419 medium 5.5 5.5 FIX windows windows 26d ago Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-34663 medium 5.5 5.5 macos macos adobe 26d ago Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to d…
CVE-2026-34662 medium 5.5 5.5 macos macos adobe 26d ago Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerabil…
CVE-2026-34350 medium 6.5 6.5 FIX windows windows 26d ago Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-34339 medium 5.5 5.5 FIX windows windows 26d ago Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
CVE-2026-32209 medium 4.4 4.4 FIX windows windows 26d ago Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
CVE-2026-32185 medium 5.5 5.5 windows windows microsoft 26d ago Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-32175 medium 4.3 4.3 windows windows 26d ago A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to ce…
CVE-2026-32170 medium 6.7 6.7 FIX windows windows 26d ago Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-31245 medium 5.3 5.3 mem0 26d ago mem0 server lacks authentication and authorization controls for its memory creation API endpoint
CVE-2026-31244 medium 6.5 6.5 mem0 26d ago The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memories/{memory_id}). The endpoint allows unauthenticated users to delete arbitrar…
CVE-2026-31243 medium 6.5 6.5 mem0 26d ago The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functionality accessible via the DELETE /memories endpoint. An unauthenticated attacke…
CVE-2026-31241 medium 6.5 6.5 mem0 26d ago mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
CVE-2026-25690 medium 6.5 6.5 fortinet 26d ago An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2…
CVE-2026-21530 medium 6.7 6.7 FIX windows windows 26d ago Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2025-67604 medium 5.3 5.3 fortinet 26d ago A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions,…
CVE-2025-53870 medium 6.7 6.7 fortinet 26d ago An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versi…
CVE-2025-53680 medium 6.7 6.7 fortinet 26d ago An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5…
CVE-2026-8407 medium 4.3 4.3 devolutions 26d ago Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted re…
CVE-2026-40300 medium 6.5 6.5 zulip 26d ago Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "moves", /api/v1/messages/{id}/history still returns historical content values, allo…
CVE-2026-25431 medium 5.3 5.3 26d ago Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hustle: through 7.8.10.1.
CVE-2026-20914 medium 5.5 5.5 intel 26d ago Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…
CVE-2026-20905 medium 6.6 6.6 intel 26d ago Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…
CVE-2026-20881 medium 5.5 5.5 intel 26d ago Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authentic…
CVE-2026-20782 medium 6.6 6.6 intel 26d ago Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenti…
CVE-2026-20771 medium 6.1 6.1 intel 26d ago Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…
CVE-2026-20717 medium 6.6 6.6 intel 26d ago Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with a…
CVE-2023-30059 medium 5.4 5.4 26d ago An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.
CVE-2026-42073 medium 6.5 6.5 gitlawb 26d ago OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP serv…
CVE-2026-34933 unknown debian debian slesubuntu ubuntu 26d ago Avahi vulnerabilities
CVE-2026-24401 unknown FIX debian debian slesubuntu ubuntu 26d ago Avahi vulnerabilities
CVE-2026-8368 medium 6.5 6.5 FIX debian debian sleswindows windows 26d ago libwww-perl vulnerability
CVE-2026-8109 medium 6.5 6.5 ivanti 26d ago An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
CVE-2026-7431 medium 4.4 4.4 ivanti 26d ago An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…
CVE-2026-5061 medium 4.7 4.7 26d ago The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) …
CVE-2025-70842 medium 5.4 5.4 26d ago A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containin…
CVE-2026-43930 medium 5.9 5.9 parseplatform 26d ago parse-server: MFA SMS one-time password accepted twice under concurrent login
CVE-2026-42006 medium 4.3 4.3 FIX debian debian slesubuntu ubuntu dovecotopen-xchange 26d ago Dovecot vulnerabilities
CVE-2026-40638 medium 6.7 6.7 dell 26d ago Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this v…
CVE-2026-40020 medium 4.3 4.3 FIX debian debian slesubuntu ubuntu dovecotopen-xchange 26d ago Dovecot vulnerabilities
CVE-2026-40016 medium 6.5 6.5 FIX debian debian slesubuntu ubuntu dovecotopen-xchange 26d ago Dovecot vulnerabilities
CVE-2026-33603 medium 5.3 5.3 FIX debian debian slesubuntu ubuntu dovecotopen-xchange 26d ago Dovecot vulnerabilities
CVE-2026-45215 medium 5.3 5.3 26d ago Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Embedded Sensitive Data.This issue affects WP EasyPay: from n/a through <= 4.3.0.
CVE-2026-45212 medium 5.3 5.3 26d ago Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asset …
CVE-2026-45210 medium 5.4 5.4 26d ago Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broadstreet Ads: from n/a thr…
CVE-2026-6813 medium 4.4 4.4 26d ago The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output esca…
CVE-2026-6800 medium 4.4 4.4 26d ago The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escapi…
CVE-2026-41125 medium 6.0 6.0 26d ago A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions), bluepla…
CVE-2026-33862 medium 6.1 6.1 siemens 26d ago A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All …
CVE-2026-1934 medium 4.3 4.3 26d ago The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the s…
CVE-2025-40948 medium 6.8 6.8 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2024-54017 medium 5.3 5.3 26d ago A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V11.0), SIPROTEC 5 6…
CVE-2026-7661 medium 6.4 6.4 27d ago The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitiza…
CVE-2026-7659 medium 6.4 6.4 27d ago The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, and including, 1.2. This is due to insufficient inp…
CVE-2026-7626 medium 5.3 5.3 27d ago The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due to the wsb_handle_slek_payment_redirect() function placing the merchant's slek_…
CVE-2026-7616 medium 4.3 4.3 27d ago The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the zawgyi_admin…
CVE-2026-7562 medium 4.3 4.3 27d ago The WP-Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.3. This is due to the absence of a nonce field in the admin settings form a…
CVE-2026-7561 medium 6.1 6.1 27d ago The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on a fu…
CVE-2026-7464 medium 6.1 6.1 27d ago The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.2. This is due to insufficient inp…
CVE-2026-7437 medium 6.1 6.1 27d ago The AzonPost plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `editpos_hidden` parameter in all versions up to, and including, 1.3. This is due to insufficient input sanit…
CVE-2026-7050 medium 4.3 4.3 27d ago The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. This is due to the plugin not properly verifying that a user is authorized to perf…
CVE-2026-6932 medium 4.3 4.3 27d ago The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.0.1. This is due to missing nonce verification on the settings u…
CVE-2026-6913 medium 6.4 6.4 27d ago The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…
CVE-2026-6808 medium 6.1 6.1 27d ago The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input …
CVE-2026-6710 medium 4.3 4.3 27d ago The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the Skysa…
CVE-2026-6709 medium 4.3 4.3 27d ago The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce…
CVE-2026-6708 medium 5.3 5.3 27d ago The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability che…
CVE-2026-6663 medium 4.8 4.8 27d ago The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints…
CVE-2026-6402 medium 6.5 6.5 sleswindows windows webpack.js 27d ago webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVE-2026-6256 medium 6.4 6.4 27d ago The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficie…
CVE-2026-6247 medium 6.4 6.4 27d ago The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due…
CVE-2026-6237 medium 6.4 6.4 27d ago The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient inp…
CVE-2026-5715 medium 6.4 6.4 27d ago The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, and including, 1.0.6 due to insuffic…
CVE-2026-5693 medium 5.3 5.3 27d ago The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking(…
CVE-2026-5340 medium 6.4 6.4 27d ago The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up to, and including, 9.1 due to insufficient input …
CVE-2026-5028 medium 6.5 6.5 27d ago The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and includ…
CVE-2026-4920 medium 6.4 6.4 27d ago The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization …
CVE-2026-4859 medium 6.4 6.4 27d ago The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up to, and including, 1.0.0 du…
CVE-2026-4301 medium 4.3 4.3 27d ago The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler la…
CVE-2026-3604 medium 4.9 4.9 27d ago The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficien…
CVE-2026-2300 medium 6.4 6.4 27d ago The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. This is due to the use of regex-base…
CVE-2026-1681 medium 6.1 6.1 27d ago Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the d…
CVE-2026-7257 medium 4.4 4.4 27d ago ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker …
CVE-2026-7255 medium 6.5 6.5 27d ago ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could a…
CVE-2026-40137 medium 6.1 6.1 27d ago SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially e…
CVE-2026-40136 medium 4.3 4.3 27d ago SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromis…
CVE-2026-40135 medium 6.5 6.5 sap 27d ago An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially c…
CVE-2026-40134 medium 4.3 4.3 27d ago Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operatio…
CVE-2026-40133 medium 6.3 6.3 27d ago Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting in low impact o…
CVE-2026-40132 medium 5.4 5.4 27d ago Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are otherwise unaut…
CVE-2026-40129 medium 4.3 4.3 27d ago Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processe…