Search

Found 49,728 results in 2129ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-25077 high 8.8 8.8 apache 1mo ago Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an…
CVE-2025-66467 high 8.1 8.1 apache 1mo ago Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, th…
CVE-2025-66172 high 8.1 8.1 apache 1mo ago The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is e…
CVE-2022-50994 high 8.1 8.1 1mo ago DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands…
CVE-2026-7330 high 7.2 7.2 1mo ago The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST par…
CVE-2026-5127 high 8.8 8.8 1mo ago The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and …
CVE-2026-4935 high 8.6 8.6 1mo ago The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to per…
CVE-2025-67888 high 7.3 8.3 EXP 1mo ago An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized bef…
CVE-2024-53326 high 7.3 8.3 EXP 1mo ago LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.
CVE-2024-46508 high 7.5 7.5 yeti-platform 1mo ago yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
CVE-2024-46507 high 7.3 7.3 yeti-platform 1mo ago A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
CVE-2024-45257 high 7.3 8.3 EXP 1mo ago A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in free…
CVE-2024-33288 high 7.3 7.3 1mo ago Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.
CVE-2024-27686 high 7.5 7.5 1mo ago Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.
CVE-2026-8148 high 7.8 7.8 navercorp 1mo ago NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.
CVE-2026-8138 high 8.8 8.8 1mo ago A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow.…
CVE-2026-8137 high 8.8 8.8 1mo ago A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url l…
CVE-2023-42346 high 7.5 7.5 1mo ago Alkacon OpenCms is vulnerable to XXE when the <!DOCTYPE> refers to an external host
CVE-2023-42344 high 7.3 7.3 1mo ago Alkacon OpenCms allows remote unauthenticated attackers to obtain sensitive information
CVE-2022-26522 high 7.8 7.8 1mo ago The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service…
CVE-2026-8133 high 7.3 7.3 1mo ago A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Fileli…
CVE-2026-8132 high 7.3 7.3 1mo ago A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. T…
CVE-2026-8131 high 7.3 7.3 1mo ago A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql …
CVE-2026-8130 high 7.3 7.3 1mo ago A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injecti…
CVE-2026-8129 high 7.3 7.3 1mo ago A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can…
CVE-2026-43943 high 7.8 7.8 electerm_project 1mo ago Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor
CVE-2026-43940 high 8.4 8.4 electerm_project 1mo ago Electerm runWidget has a path traversal that leads to arbitrary code execution
CVE-2026-42275 high 8.7 8.7 netfoundry 1mo ago zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
CVE-2026-42274 high 8.0 1mo ago Heimdall has an authorization bypass via path normalization mismatch
CVE-2026-42273 high 8.0 1mo ago Heimdall: Case-sensitive host matching may lead to policy bypass
CVE-2026-42272 high 8.0 1mo ago Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
CVE-2026-42271 high 8.8 8.8 litellm 1mo ago LiteLLM: Authenticated command execution via MCP stdio test endpoints
CVE-2026-42261 high 7.1 7.1 legeling 1mo ago PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/sk…
CVE-2026-42203 high 8.8 8.8 litellm 1mo ago LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-8128 high 7.3 7.3 1mo ago A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of the argument msgid result…
CVE-2026-8126 high 7.3 7.3 1mo ago A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_comment.php. This manipulation of the argument Name causes sql injection. Remot…
CVE-2026-44837 high 7.5 7.5 debian debian viewcomponent 1mo ago view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file …
CVE-2026-6411 high 7.3 7.3 1mo ago This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain encrypted tenant email addresses and related metadata from any tenant. Due to t…
CVE-2026-8112 high 8.8 8.8 8421bit 1mo ago A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation resul…
CVE-2026-7541 high 7.5 7.5 github 1mo ago A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON p…
CVE-2026-41105 high 8.1 8.1 windows windows microsoft 1mo ago Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-40213 high 7.4 7.4 FIX debian debian 1mo ago OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless…
CVE-2026-35435 high 8.6 8.6 windows windows microsoft 1mo ago Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-34327 high 8.2 8.2 windows windows microsoft 1mo ago Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33111 high 7.5 7.5 windows windows microsoft 1mo ago Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
CVE-2026-32207 high 8.8 8.8 windows windows microsoft 1mo ago Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26164 high 7.5 7.5 windows windows microsoft 1mo ago Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-26129 high 7.5 7.5 windows windows microsoft 1mo ago Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-8098 high 7.3 7.3 1mo ago A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument email leads to sq…
CVE-2026-42449 high 8.5 8.5 n8n-mcp 1mo ago n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
CVE-2026-42047 high 8.6 8.6 inngest 1mo ago Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods
CVE-2026-8087 high 7.8 7.8 FIX debian debian osgeo 1mo ago A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the argument DataFieldNam…
CVE-2026-43510 high 7.6 7.6 1mo ago manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. F…
CVE-2026-42501 high 7.5 7.5 FIX debian debian sleswindows windows golanggoogle 1mo ago A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module pr…
CVE-2026-42499 high 7.5 7.5 FIX debian debian sleswindows windows golanggoogle 1mo ago Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-42239 high 8.1 8.1 budibase 1mo ago Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.…
CVE-2026-39836 high 7.5 7.5 FIX debian debian sleswindows windows golanggoogle 1mo ago The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
CVE-2026-39820 high 7.5 7.5 FIX debian debian sleswindows windows golanggoogle 1mo ago Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVE-2026-33814 high 7.5 7.5 debian debian sleswindows windows golanggoogle 1mo ago When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.
CVE-2026-33811 high 7.5 7.5 FIX debian debian sleswindows windows golanggoogle 1mo ago When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
CVE-2026-27891 high 7.2 7.2 1mo ago FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
CVE-2026-8086 high 7.8 7.8 FIX debian debian osgeo 1mo ago A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName lead…
CVE-2026-8083 high 7.3 7.3 1mo ago A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation of the argument ID results i…
CVE-2026-44244 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gitpython_project 1mo ago GitPython vulnerabilities
CVE-2026-42215 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu gitpython_project 1mo ago GitPython vulnerabilities
CVE-2026-42214 high 7.8 7.8 dail8859 1mo ago Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script…
CVE-2026-41906 high 7.1 7.1 1mo ago FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filte…
CVE-2026-41905 high 7.7 7.7 1mo ago FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastR…
CVE-2026-41904 high 7.6 7.6 1mo ago FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply …
CVE-2026-6973 high 7.2 8.7 KEV ivanti 1mo ago Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
CVE-2026-5786 high 8.8 8.8 ivanti 1mo ago An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
CVE-2025-65122 high 7.5 7.5 1mo ago youtube-regex vulnerable to Regex Denial of Service
CVE-2026-23409 unknown FIX slesdebian debianubuntu ubuntu google 1mo ago Linux kernel (BlueField) vulnerabilities
CVE-2026-23408 unknown FIX slesdebian debianubuntu ubuntu google 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2026-23407 unknown FIX slesdebian debianubuntu ubuntu google 1mo ago Linux kernel (BlueField) vulnerabilities
CVE-2026-23406 unknown FIX slesdebian debianubuntu ubuntu google 1mo ago Linux kernel (BlueField) vulnerabilities
CVE-2025-68746 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (GCP) vulnerabilities
CVE-2025-68734 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68343 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68342 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68339 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68331 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68330 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68328 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68327 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68322 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68321 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68320 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68313 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68312 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68311 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68310 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68308 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68303 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68302 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68297 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-68295 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68290 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68289 unknown FIX slesdebian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2025-68288 unknown FIX debian debianubuntu ubuntu 1mo ago Linux kernel (Azure) vulnerabilities