Search

Found 45,582 results in 2422ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-7536 medium 5.3 5.3 1mo ago A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsf_sess_add_by_ip_address of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a…
CVE-2026-7535 medium 4.3 4.3 1mo ago A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c of the file /namf-comm/v1/ue-con…
CVE-2026-7518 medium 4.3 4.3 1mo ago A flaw has been found in Open5GS up to 2.7.7. This issue affects the function amf_namf_callback_handle_sdm_data_change_notify of the file /namf-callback/v1/{id}/sdmsubscription-notify of the componen…
CVE-2026-5404 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-22726 medium 5.0 5.0 cloudfoundry 1mo ago Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure…
CVE-2026-7510 medium 6.3 6.3 1mo ago A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulati…
CVE-2026-7508 medium 6.3 6.3 1mo ago A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulat…
CVE-2026-28909 medium 6.5 6.5 apple 1mo ago Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
CVE-2026-7502 medium 5.4 5.4 1mo ago A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Ma…
CVE-2026-40686 medium 5.3 5.3 FIX debian debianubuntu ubuntu exim 1mo ago Exim vulnerabilities
CVE-2026-1577 medium 6.5 6.5 ibm 1mo ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
CVE-2025-36335 medium 5.5 5.5 ibm 1mo ago IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a local user.
CVE-2025-36122 medium 6.5 6.5 ibm 1mo ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially cra…
CVE-2025-14688 medium 5.3 5.3 ibm 1mo ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
CVE-2026-7501 low 3.5 3.5 1mo ago A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument p…
CVE-2026-6539 medium 4.4 4.4 notepad-plus-plus 1mo ago Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious …
CVE-2026-4502 medium 6.5 6.5 langflow 1mo ago IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot d…
CVE-2026-41263 low 3.7 3.7 traefik 1mo ago Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware
CVE-2026-41174 medium 6.4 6.4 traefik 1mo ago Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
CVE-2026-40951 medium 5.5 5.5 absolute 1mo ago CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and trigger…
CVE-2026-40950 medium 6.5 6.5 absolute 1mo ago CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and caus…
CVE-2026-40949 medium 4.4 4.4 absolute 1mo ago CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.
CVE-2026-3346 medium 6.4 6.4 langflow 1mo ago IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus al…
CVE-2026-3340 medium 6.5 6.5 langflow 1mo ago IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pote…
CVE-2026-33452 medium 5.5 5.5 absolute 1mo ago CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to ‘blue screen’ the system.
CVE-2026-33450 medium 5.5 5.5 macos macos absolute 1mo ago CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing…
CVE-2026-28532 medium 6.5 6.5 FIX debian debian slesubuntu ubuntu frrouting 1mo ago FRR vulnerabilities
CVE-2026-3345 medium 6.5 6.5 langflow 1mo ago IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../)…
CVE-2026-42137 medium 6.5 6.5 getkirby 1mo ago Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
CVE-2026-7429 medium 4.6 4.6 1mo ago SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads t…
CVE-2026-33448 low 3.3 3.3 macos macos absolute 1mo ago CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump t…
CVE-2026-40603 medium 6.5 6.5 1mo ago Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that return…
CVE-2026-35514 medium 6.5 6.5 1mo ago Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any …
CVE-2026-32148 medium 5.9 5.9 hex 1mo ago Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for …
CVE-2026-3832 low 3.7 3.7 FIX debian debian rhelubuntu ubuntu gnuredhat 1mo ago GnuTLS vulnerabilities
CVE-2026-36766 medium 5.4 5.4 1mo ago Shopizer is vulnerable to Cross-site Scripting
CVE-2026-36763 medium 6.1 6.1 1mo ago A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted…
CVE-2026-36761 medium 6.1 6.1 1mo ago A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into th…
CVE-2026-3833 medium 6.5 6.5 FIX debian debian sles rhel gnuredhat 1mo ago GnuTLS vulnerabilities
CVE-2026-41519 medium 5.4 5.4 weblate 1mo ago Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-36764 medium 5.0 5.0 1mo ago A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.
CVE-2026-36757 medium 4.3 4.3 1mo ago A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
CVE-2026-38940 medium 6.1 6.1 1mo ago Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component
CVE-2026-38939 medium 6.1 6.1 1mo ago Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component
CVE-2026-36759 medium 6.5 6.5 1mo ago A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
CVE-2026-36758 medium 4.3 4.3 1mo ago A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
CVE-2026-36756 medium 5.4 5.4 1mo ago A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
CVE-2026-7500 medium 5.4 5.4 redhat 1mo ago Keycloak has a Forced Browsing issue
CVE-2026-7163 medium 5.5 5.5 redhat 1mo ago A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-sco…
CVE-2026-7382 medium 6.5 6.5 1mo ago Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.…
CVE-2026-5080 medium 5.9 5.9 FIX debian debian perldancer 1mo ago Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the proce…
CVE-2026-1493 medium 5.4 5.4 wolterskluwer 1mo ago LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker to execute arbitrary JavaScript …
CVE-2026-31692 medium 5.5 5.5 FIX debian debian linux-kernel sles 1mo ago In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the pee…
CVE-2026-6498 medium 5.3 5.3 1mo ago The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function…
CVE-2026-42800 medium 5.3 5.3 1mo ago NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/s…
CVE-2026-41016 medium 5.9 5.9 apache 1mo ago apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider
CVE-2026-6870 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6869 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6867 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6538 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6537 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6536 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
CVE-2026-6535 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6534 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6533 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6532 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6531 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6530 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6529 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6528 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service
CVE-2026-6527 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6526 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
CVE-2026-6524 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6523 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6522 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6521 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5409 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5408 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5407 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5406 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5401 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5299 medium 5.5 5.5 FIX slesdebian debian wireshark 1mo ago ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-42798 medium 4.0 4.0 FIX debian debian slesubuntu ubuntu 1mo ago Little CMS vulnerability
CVE-2026-41226 medium 4.7 4.7 1mo ago Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary webs…
CVE-2026-7469 medium 6.3 6.3 1mo ago A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. This impacts the function sub_425A28 of the file /goform/DelFil. The manipulation of the argument delflag results in comm…
CVE-2026-7447 medium 6.3 6.3 1mo ago A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/update_customer.php. This manipulation of the argument type/le…
CVE-2026-7445 medium 6.3 6.3 1mo ago A security vulnerability has been detected in ZachHandley ZMCPTools up to 0.2.2. Affected by this issue is some unknown functionality of the file src/managers/ResourceManager.ts of the component MCP …
CVE-2026-7410 medium 6.3 6.3 1mo ago A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument…
CVE-2026-7409 medium 4.7 4.7 1mo ago A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql inject…
CVE-2026-41671 medium 6.8 6.8 1mo ago Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation
CVE-2026-41663 low 3.5 3.5 1mo ago Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send
CVE-2026-41662 medium 5.2 5.2 1mo ago Admidio Missing Minimum Administrator Check in Role Membership Removal
CVE-2026-41661 medium 6.1 6.1 1mo ago Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion
CVE-2026-41659 low 2.7 2.7 1mo ago Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment
CVE-2026-41658 medium 6.5 6.5 1mo ago Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items
CVE-2026-41657 medium 4.9 4.9 1mo ago Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php
CVE-2026-41656 medium 4.5 4.5 1mo ago Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read
CVE-2026-41655 medium 6.5 6.5 1mo ago Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials
CVE-2026-7408 medium 4.7 4.7 1mo ago A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation r…
CVE-2026-7407 medium 4.7 4.7 1mo ago A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save…