Search

Found 17,252 results in 898ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44523 critical 10.0 10.0 21d ago Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
CVE-2026-41315 critical 9.8 9.8 midoks 21d ago mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond a…
CVE-2026-44990 critical 9.5 21d ago Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CVE-2026-44970 low 2.5 21d ago dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
CVE-2026-44969 low 2.5 21d ago dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
CVE-2026-46470 critical 9.1 9.1 FIX debian debian sles freedesktop 21d ago An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…
CVE-2026-44542 critical 9.1 9.1 gtsteffaniak 21d ago FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
CVE-2026-41615 critical 9.6 9.6 windows windows microsoft 21d ago Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
CVE-2026-6923 low 3.8 3.8 21d ago A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
CVE-2026-44348 low 2.5 2.5 FIX debian debian sles 21d ago PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFin…
CVE-2026-42555 critical 9.1 9.1 21d ago Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
CVE-2026-20182 critical 10.0 10.0 KEVEXP cisco 21d ago Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges…
CVE-2025-62317 low 2.6 2.6 21d ago HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary syst…
CVE-2025-62316 low 2.3 2.3 21d ago HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based securi…
CVE-2025-62312 low 3.0 3.0 21d ago HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse,…
CVE-2025-62309 low 2.6 2.6 21d ago HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to…
CVE-2026-44881 critical 9.9 9.9 portainer 21d ago Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
CVE-2026-44791 critical 9.5 21d ago n8n Has an XML Node Prototype Pollution Patch Bypass
CVE-2026-44790 critical 9.5 21d ago n8n Has an Arbitrary File Read via Git Node
CVE-2026-44789 critical 9.5 21d ago n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-42596 critical 9.4 9.4 thecodingmachine 21d ago Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
CVE-2026-42589 critical 9.8 9.8 thecodingmachine 21d ago Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
CVE-2026-44484 critical 9.8 9.8 lightningai 21d ago Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-44482 critical 9.6 9.6 21d ago soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app…
CVE-2026-42457 critical 9.0 9.0 21d ago vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulner…
CVE-2026-46442 critical 9.5 21d ago FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVE-2026-2347 critical 9.8 9.8 21d ago Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: b…
CVE-2025-11024 critical 9.8 9.8 21d ago Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL Injection. Th…
CVE-2026-6512 critical 9.1 9.1 21d ago The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized t…
CVE-2026-6510 critical 9.8 9.8 21d ago The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capa…
CVE-2026-6271 critical 9.8 9.8 21d ago The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This m…
CVE-2026-8181 critical 9.8 9.8 21d ago The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to inc…
CVE-2026-7471 low 3.5 3.5 gitlab 21d ago GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control o…
CVE-2026-2900 low 2.7 2.7 gitlab 21d ago GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention w…
CVE-2026-8500 critical 9.8 9.8 22d ago Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated o…
CVE-2026-45158 critical 9.1 9.1 opnsense 22d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell scrip…
CVE-2026-44442 critical 9.9 9.9 frappe 22d ago ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permi…
CVE-2026-44194 critical 9.1 9.1 opnsense 22d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileg…
CVE-2026-44193 critical 9.1 9.1 opnsense 22d ago OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. T…
CVE-2026-45714 critical 9.1 9.1 22d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Inv…
CVE-2026-45053 critical 9.1 9.1 22d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The end…
CVE-2026-44377 critical 9.1 9.1 22d ago CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and …
CVE-2025-27851 critical 9.3 9.3 garmin 22d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including…
CVE-2026-44364 critical 9.5 22d ago misp-modules website - Missing CSRF protection in the website home blueprint
CVE-2026-44351 critical 9.1 9.1 22d ago fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
CVE-2026-42584 critical 9.1 9.1 slesdebian debian netty 22d ago Netty has HttpClientCodec response desynchronization
CVE-2026-42581 critical 9.8 9.8 slesdebian debian netty 22d ago Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVE-2026-42579 critical 9.1 9.1 slesdebian debian netty 22d ago Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
CVE-2026-42032 critical 9.1 9.1 okfn 22d ago CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2026-42031 critical 9.8 9.8 okfn 22d ago CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-33585 low 3.8 3.8 22d ago Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session.…
CVE-2026-0257 critical 9.1 10.0 KEV paloaltonetworks 22d ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2026-45411 critical 9.8 9.8 vm2_project 22d ago vm2 Has a Sandbox Breakout Using Async Generator
CVE-2026-44582 low 3.7 3.7 vercel 22d ago Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44009 critical 9.8 9.8 vm2_project 22d ago vm2 has Sandbox Breakout Through Null Proto Exception
CVE-2026-44008 critical 9.8 9.8 vm2_project 22d ago vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
CVE-2026-44007 critical 9.1 9.1 vm2_project 22d ago vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
CVE-2026-44006 critical 10.0 10.0 vm2_project 22d ago vm2 has a Sandbox Escape Vulnerability
CVE-2026-44005 critical 10.0 10.0 vm2_project 22d ago vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
CVE-2026-43999 critical 9.9 9.9 vm2_project 22d ago vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
CVE-2026-43997 critical 10.0 10.0 vm2_project 22d ago vm2 Access to Host Object Enables Sandbox Escape
CVE-2026-44459 low 3.8 3.8 hono 22d ago Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-42557 critical 9.6 9.6 debian debian jupyter 22d ago jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlink…
CVE-2026-41225 critical 9.1 9.1 22d ago A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note…
CVE-2020-37168 critical 9.8 9.8 22d ago Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. A…
CVE-2026-45083 critical 9.8 9.8 22d ago The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted …
CVE-2026-42062 critical 9.8 9.8 22d ago ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authenticati…
CVE-2026-40621 critical 9.8 9.8 22d ago ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
CVE-2026-41050 critical 9.9 9.9 22d ago Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVE-2026-32661 critical 9.8 9.8 22d ago Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's…
CVE-2026-44672 critical 9.5 23d ago mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dyna…
CVE-2026-44547 critical 9.6 9.6 23d ago ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/publ…
CVE-2026-42288 critical 10.0 10.0 23d ago ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard …
CVE-2026-41901 critical 9.0 9.0 23d ago Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
CVE-2026-44650 critical 9.1 9.1 23d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44649 critical 9.8 9.8 23d ago SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
CVE-2026-44593 critical 9.5 23d ago esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ulti…
CVE-2026-44242 low 3.7 3.7 23d ago Micronaut has Unbounded `bundleCache` in `ResourceBundleMessageSource` that Allows Memory Exhaustion via `Accept-Language` Header
CVE-2026-44015 critical 9.9 9.9 nginxui 23d ago Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
CVE-2026-43948 critical 9.9 9.9 23d ago wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
CVE-2026-42854 critical 9.8 9.8 espressif 23d ago arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a …
CVE-2026-45185 critical 9.8 9.8 FIX debian debian sles exim 23d ago Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a C…
CVE-2026-44225 critical 9.3 9.3 23d ago Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the …
CVE-2026-44221 critical 9.0 9.0 23d ago ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
CVE-2026-44220 low 3.2 3.2 23d ago ciguard: discover_pipeline_files follows symlinks out of scan root
CVE-2026-44219 low 3.7 3.7 23d ago ciguard: SCA HTTP client reads response body without size cap
CVE-2026-44218 low 3.0 3.0 23d ago ciguard: Container image runs as root (no USER directive)
CVE-2026-42889 critical 9.1 9.1 23d ago Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured…
CVE-2026-34685 low 3.4 3.4 adobe 23d ago Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier [NEEDS REVIEW: impact mismatch — ticket says 'Arbitrary file system write', CIA triad derives 'Sec…
CVE-2026-34660 critical 9.3 9.3 adobe 23d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An …
CVE-2026-34659 critical 9.6 9.6 adobe 23d ago Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current …
CVE-2026-44343 critical 9.8 9.8 wgdashboard 23d ago WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file sys…
CVE-2026-44277 critical 9.1 9.1 fortinet 23d ago A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attack…
CVE-2026-44196 critical 9.1 9.1 23d ago Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and …
CVE-2026-44183 critical 9.8 9.8 23d ago Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.…
CVE-2026-42898 critical 9.9 9.9 windows windows microsoft 23d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42833 critical 9.1 9.1 windows windows microsoft 23d ago Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42823 critical 9.9 9.9 windows windows microsoft 23d ago Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-42300 critical 9.5 23d ago DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
CVE-2026-42048 critical 9.6 9.6 langflow 23d ago Langflow Knowledge Bases API is Vulnerable to Path Traversal