Search

Found 33,081 results in 3336ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-5653 high 7.5 7.5 FIX slesdebian debian wireshark 1mo ago DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5402 high 8.8 8.8 FIX slesdebian debian wireshark 1mo ago TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
CVE-2026-42511 high 8.1 8.1 freebsd freebsd 1mo ago The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by …
CVE-2024-39847 high 7.5 7.5 4d 1mo ago Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adja…
CVE-2026-7379 high 7.5 7.5 FIX slesdebian debian wireshark 1mo ago Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7378 high 7.5 7.5 FIX slesdebian debian wireshark 1mo ago Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7376 high 7.5 7.5 FIX slesdebian debian wireshark 1mo ago Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7375 high 7.5 7.5 FIX slesdebian debian wireshark 1mo ago UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6868 high 7.5 7.5 FIX slesdebian debian wireshark 1mo ago HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7470 high 8.8 8.8 1mo ago A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based…
CVE-2026-7468 high 7.3 7.3 1mo ago A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipul…
CVE-2026-7446 high 7.3 7.3 1mo ago mcp-server-semgrep has a Command Injection issue
CVE-2026-4775 high 7.8 7.8 FIX rhel sles rocky libtiffredhat 1mo ago RHSA-2026:20585: compat-libtiff3 security update (Important)
CVE-2026-44216 high 7.5 7.5 FIX slesdebian debian bytecodealliance 1mo ago wasmtime has a panic when allocating a table exceeding the size of the host's address space
CVE-2026-35535 high 7.4 7.4 FIX rhel sles rocky sudo_projectsiemens 1mo ago In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.
CVE-2026-7443 high 7.3 7.3 1mo ago A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function fuzz_domain of the file src/index.ts of the component MCP Interface. Executing …
CVE-2026-7420 high 8.8 8.8 1mo ago A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile res…
CVE-2026-7419 high 8.8 8.8 1mo ago A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile…
CVE-2026-7418 high 8.8 8.8 1mo ago A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function strcpy of the file route/goform/NTP. Executing a manipulation of the argument Pro…
CVE-2026-7417 high 7.3 7.3 1mo ago A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of t…
CVE-2026-7416 high 7.3 7.3 1mo ago A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of th…
CVE-2026-41670 high 8.2 8.2 1mo ago Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest
CVE-2026-41669 high 8.2 8.2 1mo ago Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests
CVE-2026-41663 low 3.5 3.5 1mo ago Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send
CVE-2026-41660 high 7.1 7.1 1mo ago Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP
CVE-2026-41659 low 2.7 2.7 1mo ago Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment
CVE-2026-7404 high 7.3 7.3 1mo ago mcpo-simple-server has a Path Traversal issue
CVE-2025-50328 high 7.3 7.3 1mo ago A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and e…
CVE-2026-42224 high 7.6 7.6 1mo ago ipl/web is vulnerable to reflected XSS by malformed search requests
CVE-2026-41587 high 8.0 1mo ago CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
CVE-2026-40902 high 7.5 7.5 phpoffice 1mo ago PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
CVE-2026-40863 high 7.5 7.5 phpoffice 1mo ago PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
CVE-2026-7426 high 8.1 8.1 amazonaws 1mo ago Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by…
CVE-2026-7400 high 7.3 7.3 1mo ago A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_…
CVE-2026-34965 high 8.8 8.8 1mo ago Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privilege…
CVE-2018-25315 high 8.4 8.4 1mo ago Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can…
CVE-2018-25314 high 8.4 8.4 1mo ago Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Na…
CVE-2018-25308 high 8.8 8.8 1mo ago BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attack…
CVE-2018-25307 high 8.4 8.4 1mo ago SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key…
CVE-2018-25304 high 8.4 8.4 1mo ago Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploita…
CVE-2018-25303 high 8.4 8.4 1mo ago Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exce…
CVE-2018-25302 high 7.8 7.8 1mo ago Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a ma…
CVE-2018-25301 high 8.4 8.4 1mo ago Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious userna…
CVE-2018-25300 high 8.2 8.2 1mo ago XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers c…
CVE-2018-25299 high 8.4 8.4 1mo ago Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malici…
CVE-2026-7466 high 8.8 8.8 1mo ago AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs …
CVE-2026-7424 high 8.1 8.1 amazonaws 1mo ago Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, an…
CVE-2026-7398 high 7.3 7.3 1mo ago A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of…
CVE-2026-28221 high 8.2 8.2 wazuh 1mo ago Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() i…
CVE-2026-27105 high 7.1 7.1 dell 1mo ago Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could p…
CVE-2026-38991 high 8.8 8.8 1mo ago Cockpit Vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2026-5712 high 8.8 8.8 sailpoint 1mo ago This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned…
CVE-2026-6914 high 7.5 7.5 mongodb 1mo ago Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB Server v8.2 versions, all MongoDB Serv…
CVE-2026-0204 high 8.0 8.0 1mo ago A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
CVE-2026-7390 low 3.5 3.5 1mo ago A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function Customer of the file /index.php?page=customer. The manipulation of the arg…
CVE-2026-7389 high 7.3 7.3 1mo ago A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads…
CVE-2026-7386 high 7.3 7.3 1mo ago A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manipulation of the argument message_ids can lead to pa…
CVE-2026-6849 high 8.8 8.8 1mo ago Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Com…
CVE-2026-42198 high 7.5 7.5 FIX debian debian sles rhel postgresql 1mo ago RHSA-2026:22304: postgresql-jdbc security update (Important)
CVE-2026-30769 high 7.8 7.8 entechtaiwan 1mo ago An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending crafted IOCTL 0x80002008 requests.
CVE-2026-7384 high 7.3 7.3 1mo ago A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c. This impacts the function search_papers of the file research_se…
CVE-2026-7111 high 8.4 8.4 FIX debian debian sles hmbrand 1mo ago Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, get…
CVE-2026-5161 high 8.8 8.8 1mo ago Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus …
CVE-2026-5141 high 8.8 8.8 1mo ago Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking…
CVE-2026-41952 high 7.8 7.8 1mo ago Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) …
CVE-2026-41220 high 7.8 7.8 1mo ago Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) …
CVE-2026-36837 high 7.5 7.5 1mo ago TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname parameter in the formMapDelDevice function.
CVE-2026-5140 high 8.8 8.8 1mo ago Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects P…
CVE-2026-42524 high 8.0 8.0 jenkins 1mo ago Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file
CVE-2026-42520 high 7.5 7.5 jenkins 1mo ago Jenkins Credentials Binding Plugin has a path traversal vulnerability
CVE-2026-42652 high 7.1 7.1 1mo ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Regist…
CVE-2026-42646 high 7.6 7.6 1mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n…
CVE-2026-22741 low 3.1 3.1 debian debian vmware 1mo ago Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVE-2026-42377 high 7.3 7.3 1mo ago Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.…
CVE-2026-35155 high 7.1 7.1 1mo ago Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privilege…
CVE-2026-42615 high 7.2 7.2 1mo ago CyberChef has a Cross-site Scripting issue
CVE-2026-40560 high 7.5 7.5 FIX debian debian miyagawa 1mo ago Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both hea…
CVE-2026-41651 high 8.8 8.8 FIX rhel sles rocky packagekit_project 1mo ago PackageKit vulnerability
CVE-2026-34982 high 8.0 FIX rhel sles rocky 1mo ago RHSA-2026:11509: vim security update (Important)
CVE-2026-7363 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security s…
CVE-2026-7361 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-7360 low 3.1 3.1 FIX debian debian linux-kernelmacos macos google 1mo ago Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a c…
CVE-2026-7359 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…
CVE-2026-7358 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7357 high 7.5 7.5 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chro…
CVE-2026-7356 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7355 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7354 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: …
CVE-2026-7353 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 1mo ago Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2026-7352 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT…
CVE-2026-7351 low 3.1 3.1 FIX debian debian linux-kernelmacos macos google 1mo ago Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium se…
CVE-2026-7350 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
CVE-2026-7349 high 7.5 7.5 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium se…
CVE-2026-7348 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7347 high 8.1 8.1 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
CVE-2026-7346 high 8.1 8.1 FIX debian debian linux-kernelmacos macos google 1mo ago Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Hi…
CVE-2026-7345 high 8.3 8.3 FIX debian debian linux-kernelmacos macos google 1mo ago Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esc…
CVE-2026-7344 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr…
CVE-2026-7343 high 7.5 7.5 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT…
CVE-2026-7342 high 8.8 8.8 FIX debian debian linux-kernelmacos macos google 1mo ago Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity…