Search

Found 69,865 results in 2756ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-6340 medium 6.5 6.5 mattermost 20d ago Mattermost doesn't validate 7zip archive structure before processing
CVE-2026-4273 medium 4.3 4.3 mattermost 20d ago Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
CVE-2026-3637 medium 4.3 4.3 mattermost 20d ago Mattermost doesn't check the create_post channel permission during post edit operations
CVE-2026-3495 medium 4.8 4.8 mattermost 20d ago Mattermost doesn't escape some variables that could contain malicious content during error page composition
CVE-2026-2325 medium 6.5 6.5 mattermost 20d ago Mattermost doesn't limit the size of the request body on the start meeting API endpoint
CVE-2026-28759 medium 4.3 4.3 mattermost 20d ago Mattermost does not verify remote cluster channel access when processing shared channel membership removals
CVE-2026-6495 high 7.1 7.1 20d ago The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again…
CVE-2026-6381 high 7.5 7.5 20d ago The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
CVE-2026-6379 high 8.6 8.6 20d ago The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection at…
CVE-2026-3220 high 8.8 8.8 20d ago The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress plugin before 7.7.9 are vulnerable to unauthenticated Stored Cross-Site Script…
CVE-2026-1631 medium 5.4 5.4 20d ago The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and galle…
CVE-2026-8786 medium 6.3 6.3 tencent 20d ago A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component…
CVE-2026-8785 high 7.3 7.3 20d ago A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Param…
CVE-2026-8784 medium 4.2 4.2 20d ago A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink following. The attack r…
CVE-2026-8783 medium 4.3 4.3 20d ago AMF Vulnerable to Improper Resource Shutdown or Release
CVE-2026-8782 medium 4.3 4.3 20d ago AMF Vulnerable to Improper Resource Shutdown or Release
CVE-2026-8781 medium 4.3 4.3 20d ago AMF Vulnerable to Improper Resource Shutdown or Release
CVE-2026-8780 medium 4.3 4.3 20d ago AMF Improperly Restricts Operations within the Bounds of a Memory Buffer
CVE-2026-8779 medium 4.3 4.3 20d ago AMF Improperly Restricts Operations within the Bounds of a Memory Buffer
CVE-2026-8777 medium 6.3 6.3 20d ago A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Performing a manipulatio…
CVE-2026-8776 high 8.8 8.8 20d ago A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Such manipulati…
CVE-2026-8775 high 8.8 8.8 20d ago A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. This manipulation of the argument L2TP…
CVE-2026-8774 medium 6.3 6.3 20d ago A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of the argument command…
CVE-2026-8773 medium 4.7 4.7 20d ago A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall…
CVE-2026-8772 medium 4.7 4.7 20d ago A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can …
CVE-2026-8771 high 7.3 7.3 20d ago org.linlinjava:litemall-wx-api has an Injection issue
CVE-2026-45363 high 8.0 20d ago ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
CVE-2026-42945 high 8.1 8.1 FIX rhel slesdebian debian 20d ago RHSA-2026:18041: nginx:1.24 security update (Critical)
CVE-2026-41316 high 8.1 8.1 FIX rhel slesdebian debian google 20d ago Important: ruby:4.0 security update
CVE-2026-33637 medium 6.5 6.5 FIX debian debian faraday_project 20d ago Faraday has a possible incomplete fix for GHSA-33mh-2634-fwr2: protocol-relative URI objects still bypass host scoping
CVE-2026-33416 high 8.0 FIX rheldebian debian sles 20d ago Important: thunderbird security update
CVE-2026-8769 medium 6.5 6.5 vercel 21d ago @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
CVE-2026-8768 high 7.3 7.3 vercel 21d ago A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils.…
CVE-2026-8767 high 7.5 7.5 vercel 21d ago A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manip…
CVE-2026-8766 medium 6.5 6.5 kilo 21d ago @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-8765 medium 6.5 6.5 kilo 21d ago A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component Fi…
CVE-2026-8764 high 7.2 7.2 21d ago A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffe…
CVE-2026-46720 high 8.2 8.2 21d ago Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources c…
CVE-2026-8759 high 7.3 7.3 21d ago Beetl's SpELFunction extension function has an expression injection risk
CVE-2026-8758 high 7.3 7.3 21d ago A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lea…
CVE-2026-8756 high 7.3 7.3 21d ago A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_config of the file webui_preprocess.py of the comp…
CVE-2026-8755 high 7.3 7.3 21d ago A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of the file hiyoriUI.py of the component Model Handl…
CVE-2026-8754 medium 6.3 6.3 21d ago AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
CVE-2026-8753 medium 6.3 6.3 21d ago A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.ph…
CVE-2018-25339 high 8.2 8.2 21d ago Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the…
CVE-2018-25338 high 8.2 8.2 21d ago Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit th…
CVE-2018-25337 medium 4.3 4.3 21d ago Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML fo…
CVE-2018-25336 medium 5.3 5.3 21d ago jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML form…
CVE-2018-25334 medium 5.4 5.4 21d ago Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but…
CVE-2018-25333 high 8.2 8.2 21d ago Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the …
CVE-2018-25331 medium 6.1 6.1 21d ago Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attac…
CVE-2018-25330 high 8.2 8.2 21d ago Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. At…
CVE-2018-25329 high 7.5 7.5 21d ago WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the url parameter. Attack…
CVE-2018-25328 high 8.4 8.4 21d ago VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craf…
CVE-2018-25327 medium 5.3 5.3 21d ago Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTM…
CVE-2018-25326 high 7.5 7.5 21d ago Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parame…
CVE-2018-25325 high 7.5 7.5 21d ago Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX …
CVE-2018-25324 medium 6.2 6.2 21d ago Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null bytes into the wp_abspat…
CVE-2018-25323 high 8.4 8.4 21d ago Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payl…
CVE-2018-25322 high 8.4 8.4 21d ago Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can…
CVE-2018-25321 medium 4.3 4.3 21d ago TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker…
CVE-2018-25319 high 7.1 7.1 21d ago Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Att…
CVE-2026-8752 medium 5.3 5.3 h2o 21d ago A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the compon…
CVE-2026-8750 high 7.5 7.5 h2o 21d ago A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFi…
CVE-2026-8747 medium 6.3 6.3 21d ago A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval Handler. This manipu…
CVE-2026-8746 medium 6.5 6.5 open5gs 21d ago A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF. The manipulation res…
CVE-2026-8745 medium 6.5 6.5 open5gs 21d ago A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation le…
CVE-2026-8744 medium 6.5 6.5 open5gs 21d ago A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing …
CVE-2026-8743 medium 6.3 6.3 open5gs 21d ago A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a manipulation results in …
CVE-2026-8740 medium 6.3 6.3 21d ago A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirectiv…
CVE-2026-8739 medium 5.3 5.3 21d ago A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigC…
CVE-2026-8738 medium 6.5 6.5 21d ago A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file public…
CVE-2026-8737 medium 5.3 5.3 21d ago A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListD…
CVE-2026-8736 medium 4.1 4.1 21d ago A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the component RestController. Perfor…
CVE-2026-8735 medium 6.3 6.3 21d ago A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulat…
CVE-2026-8734 high 7.3 7.3 21d ago A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interface. This manipulatio…
CVE-2026-8733 medium 6.3 6.3 21d ago A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based …
CVE-2026-8731 medium 6.5 6.5 open5gs 21d ago A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation of the argument client_pool …
CVE-2026-8730 medium 6.5 6.5 open5gs 21d ago A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manipulation of the argument nfI…
CVE-2026-8729 medium 6.5 6.5 open5gs 21d ago A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/s…
CVE-2026-8728 medium 6.5 6.5 open5gs 21d ago A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. S…
CVE-2026-8719 high 8.8 8.8 21d ago The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in t…
CVE-2026-8725 high 7.3 7.3 21d ago A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file src/caal/webhooks.py of the component test-hass Endpoint. This manipulation cau…
CVE-2026-8724 high 7.2 7.2 dataease 21d ago A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results …
CVE-2026-8723 medium 5.3 5.3 debian debianwindows windows 21d ago ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not ha…
CVE-2026-46728 high 8.2 8.2 slesdebian debian 22d ago Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
CVE-2021-47981 medium 5.4 5.4 22d ago Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription par…
CVE-2021-47980 high 7.1 7.1 22d ago Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log i…
CVE-2021-47979 high 8.8 8.8 22d ago WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers …
CVE-2021-47978 medium 6.2 6.2 22d ago ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send req…
CVE-2021-47977 high 7.5 7.5 22d ago WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the f…
CVE-2021-47976 high 8.8 8.8 22d ago TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can…
CVE-2021-47975 high 7.2 7.2 22d ago WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the `fieldtitle` parameter. Attackers can submit …
CVE-2021-47974 high 7.8 7.8 22d ago VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place ma…
CVE-2021-47973 high 7.5 7.5 22d ago Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can gener…
CVE-2021-47972 high 7.5 7.5 22d ago Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can p…
CVE-2021-47971 high 7.5 7.5 22d ago My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a pa…
CVE-2021-47970 high 7.5 7.5 22d ago Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload…
CVE-2021-47969 high 7.5 7.5 22d ago Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payl…
CVE-2021-47957 medium 6.4 6.4 22d ago Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Att…