Search

Found 12,855 results in 581ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-46453 critical 9.8 9.8 27d ago Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular express…
CVE-2024-51092 critical 9.1 10.0 EXP librenms 27d ago LibreNMS has an Authenticated OS Command Injection
CVE-2026-43944 critical 9.6 9.6 electerm_project 27d ago Electerm users can run dangrous code through link or command line
CVE-2026-43941 critical 9.6 9.6 electerm_project 27d ago Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
CVE-2026-42264 critical 9.1 9.1 FIX slesdebian debian axios 27d ago Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
CVE-2026-42208 critical 9.8 10.0 KEV litellm 27d ago BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the cr…
CVE-2026-41900 critical 10.0 10.0 th30d4y 27d ago OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX code execution envir…
CVE-2026-41501 critical 9.8 9.8 electerm_project 27d ago electerm has Command Injection via runLinux funtion
CVE-2026-41500 critical 9.8 9.8 electerm_project 27d ago electerm: electerm_install_script_CommandInjection Vulnerability Report
CVE-2026-42880 critical 9.6 9.6 argoproj 27d ago ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-8034 critical 9.8 9.8 github 28d ago A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusi…
CVE-2026-42826 critical 10.0 10.0 windows windows microsoft 28d ago Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
CVE-2026-35428 critical 9.6 9.6 windows windows microsoft 28d ago Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33844 critical 9.0 9.0 windows windows microsoft 28d ago Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
CVE-2026-33823 critical 9.6 9.6 windows windows microsoft 28d ago Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-33109 critical 9.9 9.9 windows windows microsoft 28d ago Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
CVE-2026-41691 critical 9.1 9.1 i18next 28d ago Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3…
CVE-2026-42284 critical 9.8 9.8 FIX slesdebian debian gitpython_project 28d ago GitPython: Unsafe option check validates multi_options before shlex.split transformation
CVE-2026-41902 critical 9.1 9.1 28d ago FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new use…
CVE-2026-7415 critical 9.8 9.8 28d ago The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetr…
CVE-2026-7414 critical 9.8 9.8 28d ago Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or r…
CVE-2026-7413 critical 9.8 9.8 28d ago A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cann…
CVE-2026-7821 critical 9.1 9.1 ivanti 28d ago Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled…
CVE-2026-5788 critical 9.8 9.8 ivanti 28d ago An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
CVE-2026-5787 critical 9.1 9.1 ivanti 28d ago An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-…
CVE-2025-63704 critical 9.8 9.8 28d ago query-parser-string is vulnerable to Prototype Pollution
CVE-2025-63703 critical 9.8 9.8 28d ago parse-ini is vulnerable to Prototype Pollution in index.js()
CVE-2026-36458 critical 9.8 9.8 28d ago ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered.
CVE-2025-63706 critical 9.8 9.8 28d ago next-npm-version is vulnerable to Command injection
CVE-2026-6795 critical 9.6 9.6 28d ago URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 befor…
CVE-2026-41589 critical 9.6 9.6 charm 28d ago Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A ma…
CVE-2026-30496 critical 9.8 9.8 28d ago The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated remote control of the device. The API supports bot…
CVE-2026-8091 critical 9.8 9.8 FIX debian debian sles mozilla 28d ago Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.…
CVE-2026-6508 critical 9.8 9.8 28d ago Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Lidera…
CVE-2026-33587 critical 10.0 10.0 lfnovo 28d ago Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (S…
CVE-2025-1978 critical 9.8 9.8 hitachi 28d ago Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Vi…
CVE-2025-9661 critical 9.8 9.8 hitachi 28d ago OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform On…
CVE-2026-41586 critical 9.5 28d ago fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE
CVE-2026-44603 critical 9.1 9.1 FIX debian debian torproject 28d ago Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
CVE-2026-42217 critical 9.8 9.8 slesdebian debian openexr 28d ago OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…
CVE-2026-42216 critical 9.1 9.1 slesdebian debian openexr 28d ago OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…
CVE-2026-41203 critical 9.5 28d ago CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
CVE-2026-41202 critical 9.5 28d ago CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
CVE-2026-41201 critical 9.1 9.1 28d ago CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
CVE-2026-40982 critical 9.1 9.1 vmware 28d ago Spring Cloud Config vulnerable to Path Traversal
CVE-2026-44597 critical 9.1 9.1 FIX debian debian torproject 28d ago Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
CVE-2026-40281 critical 9.1 9.1 thecodingmachine 29d ago Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
CVE-2026-44112 critical 9.6 9.6 openclaw 29d ago OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root
CVE-2026-44109 critical 9.8 9.8 openclaw 29d ago OpenClaw: Feishu webhook and card-action validation now fail closed
CVE-2026-43585 critical 9.8 9.8 openclaw 29d ago OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
CVE-2026-43581 critical 9.6 9.6 openclaw 29d ago OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools proto…
CVE-2026-43578 critical 9.1 9.1 openclaw 29d ago OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can…
CVE-2026-43575 critical 9.8 9.8 openclaw 29d ago OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can acces…
CVE-2026-44262 critical 9.4 10.0 EXP 29d ago Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules
CVE-2026-7910 critical 9.6 9.6 FIX debian debian linux-kernelmacos macos google 29d ago Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security…
CVE-2026-7908 critical 9.6 9.6 FIX debian debian linux-kernelmacos macos google 29d ago Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-41930 critical 9.8 9.8 29d ago Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin con…
CVE-2026-0300 critical 9.8 10.0 KEV 29d ago Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitra…
CVE-2026-5081 critical 9.1 9.1 debian debian 29d ago Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_…
CVE-2026-43208 critical 9.8 9.8 FIX slesdebian debian linux-kernel 29d ago In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption that the RPS table for each receive queue would have …
CVE-2026-43198 critical 9.8 9.8 FIX slesdebian debian linux-kernel 29d ago In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done…
CVE-2026-43197 critical 9.1 9.1 FIX slesdebian debian linux-kernel 29d ago In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to b…
CVE-2026-43186 critical 9.8 9.8 FIX slesdebian debian linux-kernel 29d ago In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->node…
CVE-2026-43185 critical 9.8 9.8 FIX slesdebian debian linux-kernel 29d ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value fr…
CVE-2026-43125 critical 9.8 9.8 FIX slesdebian debian linux-kernel 29d ago In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network mess…
CVE-2025-59852 critical 9.1 9.1 hcltech 29d ago HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise t…
CVE-2025-59851 critical 9.8 9.8 hcltech 29d ago HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker to identify and …
CVE-2026-43117 critical 9.1 9.1 FIX slesdebian debian linux-kernel google 29d ago In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_s…
CVE-2026-43114 critical 9.4 9.4 FIX slesdebian debian linux-kernel google 29d ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching fun…
CVE-2026-43083 critical 9.1 9.1 FIX slesdebian debianwindows windows 29d ago In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_g…
CVE-2026-40010 critical 9.1 9.1 apache 29d ago Apache Wicket has a Session Fixation issue
CVE-2026-28780 critical 9.8 9.8 FIX debian debian rhel sles apache 1mo ago Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy…
CVE-2026-42608 critical 9.1 9.1 getgrav 1mo ago Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component
CVE-2026-42613 critical 9.4 9.4 1mo ago Grav Vulnerable to Privilege Escalation via Missing Server-Side Validation of groups/access
CVE-2026-42607 critical 9.1 10.0 EXP 1mo ago Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
CVE-2026-35579 critical 9.8 9.8 windows windows coredns.io 1mo ago CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
CVE-2026-42196 critical 9.5 1mo ago django-s3file is vulnerable to relative path traversal
CVE-2026-42155 critical 9.5 1mo ago Magento LTS has Weak API Session ID — Predictable MD5 of Time-Derived Inputs
CVE-2026-7854 critical 9.8 9.8 1mo ago A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler.…
CVE-2026-38428 critical 9.8 9.8 kestra 1mo ago Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitiza…
CVE-2026-27960 critical 9.8 9.8 citeum 1mo ago OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploi…
CVE-2026-7853 critical 9.8 9.8 1mo ago A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time…
CVE-2026-25660 critical 9.5 1mo ago Codechecker has an authentication bypass for certain API calls
CVE-2026-38431 critical 9.8 9.8 frappe 1mo ago ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on…
CVE-2026-38429 critical 9.8 9.8 1mo ago OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.
CVE-2026-7411 critical 10.0 10.0 1mo ago Eclipse BaSyx Java Server SDK vulnerable to Path Traversal
CVE-2026-43071 critical 9.1 9.1 FIX slesdebian debian linux-kernel google 1mo ago In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=…
CVE-2026-43067 critical 9.8 9.8 FIX slesdebian debian linux-kernel google 1mo ago In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Commit 4865c768b563 ("ext4: always allocate blocks o…
CVE-2026-7834 critical 9.8 9.8 1mo ago A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-bas…
CVE-2026-36356 critical 9.1 10.0 EXP 1mo ago The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
CVE-2026-34408 critical 9.1 9.1 1mo ago An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if th…
CVE-2026-43566 critical 9.8 9.8 openclaw 1mo ago OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
CVE-2026-43534 critical 9.8 9.8 openclaw 1mo ago OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
CVE-2026-43526 critical 9.3 9.3 openclaw 1mo ago OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes
CVE-2023-54344 critical 9.8 9.8 1mo ago Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface.…
CVE-2023-54342 critical 9.8 9.8 1mo ago Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the…
CVE-2026-40797 critical 9.3 9.3 1mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: …
CVE-2026-7823 critical 9.8 9.8 1mo ago A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results…
CVE-2026-5294 critical 9.8 9.8 1mo ago The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispa…
CVE-2025-13618 critical 9.8 9.8 1mo ago The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can regis…