Search

Found 1,247 results in 106ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-10812 low 3.6 3.6 12h ago A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. …
CVE-2026-10811 medium 6.3 6.3 12h ago A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the ar…
CVE-2026-45730 unknown 12h ago Nuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project
CVE-2026-45337 unknown 12h ago Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
CVE-2026-45056 unknown 12h ago Sender-binding gaps in to-device messages
CVE-2026-44476 unknown 12h ago Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret
CVE-2026-44889 unknown 12h ago WebOb: Location header normalization during redirect leads to open redirect - again
CVE-2026-44496 unknown 13h ago Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVE-2026-44488 unknown 13h ago Allocation of Resources Without Limits or Throttling in Axios
CVE-2026-44487 unknown 13h ago Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
CVE-2026-8762 unknown 13h ago Rejected reason: After analysis, the originally reported behaviour was determined not to constitute a security vulnerability. The findings were parser-strictness defects without an exploitable framin…
CVE-2026-8037 critical 9.6 9.6 13h ago OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting un…
CVE-2026-45433 unknown 13h ago This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the…
CVE-2026-43926 unknown 13h ago FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-AP…
CVE-2026-40605 unknown 13h ago Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access t…
CVE-2026-10861 unknown 13h ago An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination w…
CVE-2026-10856 unknown 13h ago A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation …
CVE-2026-10855 unknown 13h ago An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already e…
CVE-2026-10854 unknown 13h ago A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enab…
CVE-2026-10810 medium 4.3 4.3 13h ago A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scri…
CVE-2026-10809 medium 6.3 6.3 13h ago A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injec…
CVE-2026-10808 medium 6.3 6.3 13h ago A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection…
CVE-2026-10807 medium 6.3 6.3 13h ago A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of t…
CVE-2026-10806 medium 6.3 6.3 13h ago A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_fi…
CVE-2025-62338 low 3.3 3.3 13h ago The HCL BigFix Cloud Lifecycle Management is affected by Lack Of Input Validation. It may leads to an information exposure vulnerability. This low-level flaw allows unauthorized access.
CVE-2019-25744 medium 6.4 6.4 13h ago WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title …
CVE-2019-25743 medium 6.4 6.4 13h ago WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title fiel…
CVE-2019-25742 medium 6.4 6.4 13h ago WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when crea…
CVE-2019-25741 critical 9.8 9.8 13h ago Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code…
CVE-2019-25740 medium 6.5 6.5 13h ago Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requ…
CVE-2019-25739 medium 6.4 6.4 13h ago GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers…
CVE-2019-25738 critical 9.8 9.8 13h ago WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option actio…
CVE-2019-25734 medium 4.0 4.0 13h ago Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanit…
CVE-2019-25729 critical 9.8 9.8 13h ago PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie paramete…
CVE-2019-25727 critical 9.8 9.8 13h ago WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers…
CVE-2026-44486 unknown 13h ago Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
CVE-2026-4104 critical 9.8 9.8 15h ago Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: f…
CVE-2026-45432 unknown 15h ago This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability…
CVE-2026-45431 unknown 15h ago This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker cou…
CVE-2026-10840 critical 9.6 9.6 15h ago A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources…
CVE-2026-10804 low 3.6 3.6 15h ago A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation l…
CVE-2026-10803 low 3.6 3.6 lfprojects 15h ago A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipu…
CVE-2026-10802 medium 4.3 4.3 15h ago A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL …
CVE-2025-52611 medium 4.3 4.3 hcltech 15h ago HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Spec…
CVE-2025-52609 medium 5.3 5.3 hcltech 15h ago HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
CVE-2025-52608 medium 4.3 4.3 hcltech 15h ago HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path…
CVE-2025-52606 medium 4.3 4.3 hcltech 15h ago HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain…
CVE-2025-12694 unknown 15h ago A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: ver…
CVE-2026-49077 medium 5.3 5.3 16h ago Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from…
CVE-2026-10801 low 3.6 3.6 16h ago A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache K…
CVE-2026-8916 medium 6.1 6.1 debian debian 17h ago Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.
CVE-2026-50226 unknown 17h ago Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extra…
CVE-2026-50225 unknown 17h ago The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
CVE-2026-50224 unknown 17h ago The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.
CVE-2026-50214 unknown 17h ago The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
CVE-2026-4881 unknown 17h ago In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receivi…
CVE-2026-49510 medium 6.1 6.1 debian debian 17h ago Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.
CVE-2026-47320 medium 6.1 6.1 debian debian 17h ago Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: befo…
CVE-2026-47319 medium 6.1 6.1 debian debian 17h ago Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.
CVE-2026-47318 medium 6.1 6.1 debian debian 17h ago Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.
CVE-2026-47306 medium 6.1 6.1 debian debian 17h ago Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.
CVE-2026-10800 low 3.6 3.6 17h ago A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHash…
CVE-2026-10305 medium 6.1 6.1 17h ago Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.
CVE-2026-50212 medium 6.5 6.5 acer 18h ago Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
CVE-2026-50211 critical 9.8 9.8 acer 18h ago Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
CVE-2026-50208 critical 9.4 9.4 acer 18h ago High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
CVE-2026-50206 medium 6.8 6.8 acer 20h ago Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
CVE-2026-49204 medium 6.5 6.5 acer 20h ago Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
CVE-2026-49192 medium 5.4 5.4 acer 20h ago The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
CVE-2026-49191 critical 9.8 9.8 acer 20h ago The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
CVE-2026-10805 medium 6.7 6.7 sles 22h ago A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A lo…
CVE-2026-50219 medium 5.9 5.9 debian debian sles libexpat_project 23h ago libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation.…
CVE-2026-49186 critical 9.8 9.8 acer 23h ago The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish r…
CVE-2026-49185 critical 9.8 9.8 acer 23h ago The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
CVE-2026-44917 medium 4.9 4.9 debian debian openstack 23h ago OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
CVE-2026-41283 critical 9.9 9.9 debian debian 23h ago OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
CVE-2026-49188 critical 9.8 9.8 acer 23h ago The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
CVE-2026-41858 medium 6.5 6.5 1d ago Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a s…
CVE-2026-10597 medium 5.3 5.3 1d ago OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.
CVE-2026-8653 medium 6.5 6.5 1d ago The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the u…
CVE-2026-7764 medium 6.8 6.8 1d ago An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to di…
CVE-2026-8722 medium 6.5 6.5 1d ago Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inj…
CVE-2026-10783 low 2.5 2.5 1d ago A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of we…
CVE-2026-35240 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35239 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35238 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35237 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-35236 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34308 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34304 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34303 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34293 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34278 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34276 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34271 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34270 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-34267 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22017 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22015 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)
CVE-2026-22009 medium 5.5 FIX debian debian rhel 1d ago RHSA-2026:23332: mysql security update (Moderate)