Search

Found 49,728 results in 2014ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-33893 high 7.5 7.5 siemens 26d ago A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All …
CVE-2026-27662 high 7.7 7.7 26d ago Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security mechanisms are in place. This could allow an unauthenticated attacker to gain…
CVE-2026-25789 high 7.1 7.1 26d ago Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user into selecting the modified firmware file…
CVE-2026-22925 high 7.5 7.5 26d ago A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when subjected to high volume of TCP SYN packets This cou…
CVE-2025-40947 high 7.5 7.5 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2025-40946 high 8.3 8.3 26d ago A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All version…
CVE-2025-40833 high 7.5 7.5 26d ago The affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an attacker to cause denial of service condition. A manual res…
CVE-2026-6690 high 7.2 7.2 26d ago The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the …
CVE-2026-39432 high 8.2 8.2 26d ago Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.
CVE-2026-2993 high 7.5 7.5 26d ago The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and …
CVE-2026-1185 high 8.8 8.8 26d ago A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if …
CVE-2026-0804 high 7.3 7.3 26d ago An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axi…
CVE-2026-0802 high 7.3 7.3 26d ago An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis d…
CVE-2026-0541 high 7.3 7.3 26d ago ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited …
CVE-2026-41872 high 7.4 7.4 26d ago "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notific…
CVE-2026-7287 high 7.5 7.5 27d ago ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100…
CVE-2026-7256 high 8.8 8.8 27d ago ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operat…
CVE-2026-45430 high 7.1 7.1 27d ago The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
CVE-2026-34259 high 8.2 8.2 27d ago Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administrative authorizations could abuse a non-remote-enabled function to execute arbi…
CVE-2026-45393 high 7.8 7.8 27d ago A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorrect default permissions on the Windows installer's…
CVE-2026-45392 high 8.7 8.7 27d ago DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a craf…
CVE-2026-45391 high 7.8 7.8 27d ago A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary commands in the context of the Cribl Edge service account.
CVE-2026-8346 high 8.8 8.8 27d ago A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The at…
CVE-2026-4887 high 7.1 7.1 FIX rheldebian debian sles gimp 27d ago Important: gimp security update
CVE-2026-43284 high 8.8 9.8 EXPFIX rhel slesdebian debian awsgoogle 27d ago Linux kernel vulnerabilities
CVE-2026-42559 high 8.8 8.8 27d ago rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
CVE-2026-4154 high 8.0 FIX rheldebian debian sles 27d ago Important: gimp security update
CVE-2026-4153 high 8.0 FIX rheldebian debian sles 27d ago Important: gimp security update
CVE-2026-4152 high 8.0 FIX rheldebian debian sles 27d ago Important: gimp security update
CVE-2026-4151 high 8.0 FIX rheldebian debian sles 27d ago Important: gimp security update
CVE-2026-4150 high 8.0 FIX rheldebian debian sles 27d ago Important: gimp security update
CVE-2026-8345 high 8.8 8.8 27d ago A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the …
CVE-2026-43913 high 8.1 8.1 dani-garcia 27d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flo…
CVE-2026-43912 high 8.7 8.7 dani-garcia 27d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as grou…
CVE-2026-43911 high 8.1 8.1 dani-garcia 27d ago Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (pass…
CVE-2026-34963 high 7.8 7.8 pengutronix 27d ago barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithm…
CVE-2026-8344 high 8.8 8.8 27d ago A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command in…
CVE-2026-43897 high 8.0 27d ago link-preview-js vulnerable to IPv6 and internal loopback attacks
CVE-2026-43893 high 8.2 8.2 27d ago exiftool-vendored vulnerable to argument injection via newline characters in tag names
CVE-2026-43890 high 7.7 7.7 27d ago Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API endpoint in server/routes/api/subscriptions/subscriptions.ts exhibits a broken aut…
CVE-2026-43888 high 8.7 8.7 27d ago Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extraction path for each entry by passing a full filesystem path through trimFileAndEx…
CVE-2026-43887 high 7.3 7.3 27d ago Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section permits users to mention other users; however, the backend does not validate or san…
CVE-2026-43886 high 8.2 8.2 27d ago Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing t…
CVE-2026-42564 high 8.2 8.2 27d ago jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is jo…
CVE-2026-42046 high 7.8 7.8 FIX debian debian slesubuntu ubuntu 27d ago libcaca vulnerability
CVE-2026-34961 high 7.7 7.7 pengutronix 27d ago barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.…
CVE-2026-2614 high 7.5 7.5 lfprojects 27d ago MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2026-41489 high 8.8 8.8 27d ago Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by s…
CVE-2026-37630 high 7.3 7.3 FIX debian debian 27d ago An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
CVE-2026-28860 high 7.5 7.5 FIX macos macos ios tvos 27d ago visionOS 26.4
CVE-2026-8321 high 7.3 7.3 27d ago A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. P…
CVE-2026-36734 high 8.8 8.8 27d ago EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient…
CVE-2022-4988 high 7.3 7.3 27d ago Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…
CVE-2026-44657 high 8.0 27d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execu…
CVE-2026-44655 high 8.0 27d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an attacker that can set it (which typically requires manager or administrator acces…
CVE-2026-42071 high 8.0 27d ago Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to…
CVE-2026-40607 high 8.0 27d ago MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
CVE-2026-40597 high 8.0 27d ago MantisBT has a Content Security Policy bypass via attachments
CVE-2026-40596 high 8.0 27d ago MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
CVE-2026-39850 high 7.4 7.4 27d ago Yii 2: Local file inclusion via view parameter name collision
CVE-2026-34463 high 8.0 27d ago MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
CVE-2026-7790 high 7.5 7.5 debian debianwindows windows ninenines 27d ago Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number …
CVE-2026-45224 high 7.1 7.1 27d ago Crabbox contains a path traversal vulnerability in the Islo provider's workspace path resolution
CVE-2026-45223 high 8.8 8.8 27d ago Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin …
CVE-2026-2393 high 7.1 7.1 lfprojects 27d ago MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-7818 high 7.8 7.8 sles pgadmin 27d ago pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
CVE-2026-31253 high 7.3 7.3 27d ago flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism
CVE-2026-5172 high 7.3 7.3 FIX debian debian sleswindows windows 27d ago Dnsmasq vulnerabilities
CVE-2026-45006 high 8.8 8.8 openclaw 27d ago OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration…
CVE-2026-45004 high 7.8 7.8 openclaw 27d ago OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
CVE-2026-45001 high 7.1 7.1 openclaw 27d ago OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox p…
CVE-2026-44995 high 7.3 7.3 openclaw 27d ago OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
CVE-2026-44413 high 7.5 7.5 jetbrains 27d ago In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-43640 high 8.1 8.1 bitwarden 27d ago Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management …
CVE-2026-42856 high 8.0 27d ago Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
CVE-2026-42313 high 8.3 8.3 pyload-ng_project 27d ago pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …
CVE-2026-41431 high 8.0 8.0 27d ago Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Fi…
CVE-2026-3609 high 7.8 7.8 wellbia 27d ago Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cr…
CVE-2026-38568 high 8.1 8.1 27d ago HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve …
CVE-2026-38566 high 8.1 8.1 27d ago HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission …
CVE-2026-36983 high 7.3 7.3 27d ago D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.
CVE-2026-36962 high 7.3 7.3 27d ago SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution…
CVE-2026-30635 high 8.1 8.1 27d ago automagik-genie has a command injection vulnerability
CVE-2026-42603 high 8.8 8.8 27d ago OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_ta…
CVE-2026-42349 high 8.1 8.1 clerk 27d ago Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other…
CVE-2026-33362 high 8.6 8.6 27d ago In Meari IoT SDK builds embedded in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and white-label Android apps <= 1.8.x (latest observed), multiple security-critical secrets are hardcoded an…
CVE-2026-33361 high 7.5 7.5 27d ago In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx3" files use reversi…
CVE-2026-33359 high 7.5 7.5 27d ago In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforce…
CVE-2026-33357 high 7.5 7.5 27d ago In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearic…
CVE-2026-33356 high 7.7 7.7 27d ago In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to global wildcard topics and receive telemetry from devices the user does not own. …
CVE-2026-31254 high 7.3 7.3 27d ago The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python …
CVE-2026-31251 high 7.3 7.3 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads…
CVE-2026-31250 high 7.3 7.3 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads…
CVE-2026-31249 high 7.3 7.3 27d ago CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script l…
CVE-2026-31248 high 7.5 7.5 27d ago Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-23411 unknown FIX slesdebian debianubuntu ubuntu google 27d ago Linux kernel (BlueField) vulnerabilities
CVE-2026-23410 unknown FIX slesdebian debianubuntu ubuntu google 27d ago Linux kernel (BlueField) vulnerabilities
CVE-2026-23405 unknown FIX slesdebian debianubuntu ubuntu google 27d ago Linux kernel (BlueField) vulnerabilities
CVE-2026-23404 unknown FIX slesdebian debianubuntu ubuntu google 27d ago Linux kernel (BlueField) vulnerabilities
CVE-2026-23403 unknown FIX slesdebian debianubuntu ubuntu google 27d ago Linux kernel (BlueField) vulnerabilities