Search

Found 49,667 results in 2158ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-34088 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-34087 high 7.5 7.5 FIX debian debian mediawiki 27d ago Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
CVE-2026-31247 high 7.5 7.5 27d ago Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2025-65418 high 7.5 7.5 27d ago docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
CVE-2025-61314 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in…
CVE-2025-61313 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascrip…
CVE-2025-61312 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in …
CVE-2025-61311 high 7.3 7.3 27d ago A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in t…
CVE-2026-44543 high 8.7 8.7 27d ago Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in …
CVE-2026-44521 high 8.8 8.8 27d ago elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…
CVE-2026-45017 high 7.5 7.5 jg-rp 27d ago Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search pa…
CVE-2026-44345 high 8.8 8.8 bentoml 27d ago BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
CVE-2026-44338 high 7.3 7.3 praison 27d ago PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-4802 high 8.0 8.0 FIX debian debian rhel sles 27d ago A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links i…
CVE-2025-9973 high 7.2 7.2 wso2 27d ago Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations.…
CVE-2025-10470 high 8.6 8.6 wso2 27d ago The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerabilit…
CVE-2026-41951 high 7.2 7.2 27d ago Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
CVE-2026-40636 high 7.8 7.8 dell 27d ago Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could p…
CVE-2026-32658 high 8.8 8.8 dell 27d ago Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …
CVE-2025-8325 high 8.8 8.8 wso2 27d ago The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This…
CVE-2025-8154 high 7.5 7.5 wso2 27d ago In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses…
CVE-2025-10908 high 7.3 7.3 wso2 27d ago Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses the intended security …
CVE-2026-43500 high 7.8 8.8 EXPFIX slesdebian debian linux-kernel 27d ago In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and th…
CVE-2026-6433 high 7.3 7.3 27d ago The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execut…
CVE-2026-8273 high 7.2 7.2 27d ago A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation caus…
CVE-2026-8272 high 7.2 7.2 27d ago A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os comma…
CVE-2026-8271 high 7.2 7.2 27d ago A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the f…
CVE-2026-8265 high 7.2 7.2 27d ago A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the…
CVE-2026-8264 high 8.8 8.8 27d ago A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation …
CVE-2026-8260 high 8.8 8.8 28d ago A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipu…
CVE-2026-8259 high 7.2 7.2 28d ago A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip lea…
CVE-2026-43668 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-43661 high 7.5 7.5 FIX iosmacos macos tvos 28d ago watchOS 26.5
CVE-2026-43656 high 7.3 7.3 FIX iosmacos macos 28d ago An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, ma…
CVE-2026-43655 high 7.3 7.3 FIX iosmacos macos tvos 28d ago watchOS 26.5
CVE-2026-43654 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-43652 high 7.5 7.5 FIX macos macos 28d ago A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.
CVE-2026-39871 high 7.5 7.5 FIX macos macos 28d ago A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.
CVE-2026-39870 high 7.5 7.5 FIX macos macos 28d ago The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Processing a maliciously crafted image may corrupt process m…
CVE-2026-28995 high 8.8 8.8 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28991 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28990 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28987 high 7.5 7.5 FIX iosmacos macos tvos 28d ago watchOS 26.5
CVE-2026-28986 high 7.5 7.5 FIX iosmacos macos tvos 28d ago watchOS 26.5
CVE-2026-28983 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28978 high 8.8 8.8 FIX macos macos 28d ago A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its san…
CVE-2026-28976 high 7.5 7.5 FIX macos macos 28d ago An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.
CVE-2026-28974 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28969 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28965 high 7.5 7.5 FIX iosmacos macos 28d ago A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.5 and iPadOS 26.5. A user may be able to view restricted content from the lock screen.
CVE-2026-28964 high 7.5 7.5 FIX iosmacos macos apple 28d ago visionOS 26.5
CVE-2026-28959 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28954 high 7.5 7.5 FIX iosmacos macos 28d ago A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted …
CVE-2026-28952 high 7.5 7.5 FIX iosmacos macos 28d ago An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able …
CVE-2026-28951 high 7.8 7.8 FIX iosmacos macos 28d ago An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Ta…
CVE-2026-28943 high 7.5 7.5 FIX iosmacos macos tvos 28d ago watchOS 26.5
CVE-2026-28941 high 7.1 7.1 FIX iosmacos macos 28d ago The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-o…
CVE-2026-28940 high 8.8 8.8 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28936 high 7.5 7.5 FIX iosmacos macos apple 28d ago visionOS 26.5
CVE-2026-28930 high 7.5 7.5 FIX macos macos 28d ago A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.5. An app may be able to access protected user data.
CVE-2026-28929 high 7.5 7.5 FIX iosmacos macos 28d ago A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Replying to an email could display …
CVE-2026-28925 high 7.5 7.5 FIX macos macos 28d ago A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to cause unexpected system termin…
CVE-2026-28924 high 7.5 7.5 FIX macos macos 28d ago A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access Contacts with…
CVE-2026-28923 high 8.8 8.8 FIX macos macos 28d ago A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its sandbox.
CVE-2026-28919 high 7.8 7.8 FIX macos macos 28d ago A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to gain root privileges.
CVE-2026-28915 high 7.8 7.8 FIX macos macos 28d ago A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able …
CVE-2026-28908 high 7.5 7.5 FIX macos macos 28d ago A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to modify protected par…
CVE-2026-28906 high 7.5 7.5 FIX iosmacos macos apple 28d ago visionOS 26.5
CVE-2026-28894 unknown iosmacos macos 28d ago macOS Sonoma 14.8.5
CVE-2026-28873 high 7.5 7.5 FIX iosmacos macos 28d ago iOS 26.4 and iPadOS 26.4
CVE-2026-28872 high 7.5 7.5 FIX iosmacos macos 28d ago iOS 26.4 and iPadOS 26.4
CVE-2026-28848 high 7.5 7.5 FIX macos macos 28d ago A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination.
CVE-2026-28846 high 7.5 7.5 FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2026-28840 high 7.8 7.8 FIX macos macos 28d ago macOS Tahoe 26.4
CVE-2026-1837 unknown FIX iosmacos macos tvos 28d ago visionOS 26.5
CVE-2025-43524 high 8.8 8.8 FIX macos macos 28d ago An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox.
CVE-2026-8177 high 7.5 7.5 FIX debian debian sleswindows windows 28d ago XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UT…
CVE-2026-45180 high 7.5 7.5 28d ago Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on ano…
CVE-2022-50944 high 8.8 8.8 28d ago Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can up…
CVE-2021-47949 high 8.8 8.8 28d ago CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager con…
CVE-2021-47945 high 7.8 7.8 28d ago Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attacke…
CVE-2021-47944 high 7.5 7.5 28d ago memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a p…
CVE-2021-47943 high 8.8 8.8 28d ago TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functio…
CVE-2021-47941 high 8.2 8.2 28d ago WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap co…
CVE-2021-47939 high 8.8 8.8 28d ago Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into mod…
CVE-2021-47938 high 8.8 8.8 28d ago ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code…
CVE-2021-47937 high 8.8 8.8 28d ago e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Att…
CVE-2021-47935 high 8.8 8.8 sentry 28d ago Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log e…
CVE-2021-47930 high 8.2 8.2 28d ago Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can …
CVE-2021-47928 high 8.2 8.2 28d ago Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id paramete…
CVE-2026-8234 high 8.8 8.8 28d ago A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument se…
CVE-2026-45186 high 7.5 7.5 FIX debian debian sleswindows windows libexpat_project 28d ago RHSA-2026:23230: expat security update (Important)
CVE-2026-7263 high 7.5 7.5 FIX slesdebian debian php 28d ago In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML docu…
CVE-2026-8230 high 8.8 8.8 28d ago A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command…
CVE-2026-8229 high 8.8 8.8 28d ago A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypTy…
CVE-2026-8228 high 8.8 8.8 28d ago A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/…
CVE-2026-8227 high 8.8 8.8 28d ago A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be init…
CVE-2026-8226 high 7.5 7.5 open5gs 28d ago A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in…
CVE-2026-8225 high 7.5 7.5 open5gs 28d ago A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation …
CVE-2026-7568 high 7.5 7.5 FIX slesdebian debianwindows windows php 28d ago In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the cur…