Search

Found 12,874 results in 566ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-26210 critical 9.8 9.8 kvcache-ai 1mo ago KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authe…
CVE-2026-24303 critical 9.6 9.6 microsoft 1mo ago Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-25874 critical 9.8 9.8 huggingface 1mo ago LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels wit…
CVE-2026-41247 critical 9.8 9.8 std42 1mo ago elFinder: Command injection in resize background color parameter when using ImageMagick CLI
CVE-2026-6920 critical 9.6 9.6 FIX debian debian linux-kernel google 1mo ago Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
CVE-2026-6919 critical 9.6 9.6 FIX debian debian linux-kernel google 1mo ago Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
CVE-2026-31533 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUSY handling in tls_do_encryption(), introduced by c…
CVE-2026-39087 critical 9.8 9.8 1mo ago ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
CVE-2025-62373 critical 9.8 9.8 pipecat 1mo ago Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
CVE-2026-41460 critical 9.8 9.8 socialengine 1mo ago SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized befo…
CVE-2026-6887 critical 9.8 9.8 1mo ago Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, mod…
CVE-2026-6886 critical 9.8 9.8 1mo ago Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.
CVE-2026-6885 critical 9.8 9.8 1mo ago Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell back…
CVE-2026-3960 critical 9.8 9.8 h2o 1mo ago H2O-3 is Vulnerable to Code Injection
CVE-2026-41211 critical 10.0 10.0 voidzero 1mo ago Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME
CVE-2026-41196 critical 10.0 10.0 FIX debian debian minetest 1mo ago Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to…
CVE-2026-5935 critical 9.8 9.8 ibm 1mo ago IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due …
CVE-2026-41179 critical 9.8 9.8 debian debian rclone 1mo ago RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CVE-2026-29198 critical 9.8 9.8 rocket.chat 1mo ago In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OA…
CVE-2026-42087 critical 9.6 9.6 openc3 1mo ago OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
CVE-2026-41167 critical 9.1 9.1 1mo ago Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields direct…
CVE-2026-32885 critical 9.1 9.1 ddev 1mo ago DDEV has ZipSlip path traversal in tar and zip archive extraction
CVE-2018-25272 critical 9.8 9.8 1mo ago ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to …
CVE-2026-41176 critical 9.5 debian debian 1mo ago Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
CVE-2026-6356 critical 9.6 9.6 augmentt 1mo ago A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitiv…
CVE-2026-31501 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_hdesc_get_psdata() returns a pointer into the CPPI …
CVE-2026-31478 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add supp…
CVE-2026-31463 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Commit aa35dd5cbc06 ("iomap: fix invalid folio access…
CVE-2026-31448 critical 9.4 9.4 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if in…
CVE-2026-31444 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock() has two issues in the oplock publication sequen…
CVE-2026-31436 critical 9.8 9.8 FIX slesdebian debian linux-kernel 1mo ago In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal c…
CVE-2026-6023 critical 9.8 9.8 progress 1mo ago In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the c…
CVE-2026-41144 critical 9.8 9.8 nasa 1mo ago F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize …
CVE-2026-40575 critical 9.1 9.1 oauth2_proxy_project 1mo ago OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
CVE-2026-5845 critical 9.6 9.6 github 1mo ago An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the int…
CVE-2026-40910 critical 9.1 9.1 fatedier 1mo ago frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access control
CVE-2026-33519 critical 9.8 9.8 linux-kernel esrikubernetes 1mo ago An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentia…
CVE-2026-40903 critical 9.1 9.1 goshs 1mo ago goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the…
CVE-2026-40372 critical 9.1 9.1 microsoft 1mo ago Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-5652 critical 9.0 9.0 craftycontrol 1mo ago An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permiss…
CVE-2026-5965 critical 9.8 9.8 2mo ago NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-6257 critical 9.1 9.1 2mo ago Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to r…
CVE-2026-32311 critical 9.8 9.8 flowsint 2mo ago Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to ma…
CVE-2026-5760 critical 9.8 9.8 lmsys 2mo ago SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered usin…
CVE-2026-5964 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-5963 critical 9.8 9.8 digiwin 2mo ago EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2026-6644 critical 9.1 9.1 2mo ago A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary co…
CVE-2026-40324 critical 9.1 9.1 2mo ago ChilliCream GraphQL Platform: Utf8GraphQLParser Stack Overflow via Deeply Nested GraphQL Documents
CVE-2026-5720 critical 9.1 9.1 FIX debian debian miniupnp_project 2mo ago miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPActio…
CVE-2026-40351 critical 9.8 9.8 fastgpt 2mo ago FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attac…
CVE-2026-40258 critical 9.1 9.1 2mo ago gramps-webapi: Zip Slip Path Traversal in Media Archive Import
CVE-2026-29013 critical 9.8 9.8 FIX debian debian libcoap 2mo ago libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which i…
CVE-2026-23500 critical 9.1 9.1 dolibarr 2mo ago Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
CVE-2026-35546 critical 9.8 9.8 2mo ago Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
CVE-2026-40525 critical 9.1 9.1 volcengine 2mo ago OpenViking: Unauthenticated remote bot control via OpenAPI HTTP routes
CVE-2025-15625 critical 9.8 9.8 sparxsystems 2mo ago Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
CVE-2026-41242 critical 9.5 2mo ago Arbitrary code execution in protobufjs
CVE-2026-5426 critical 9.1 9.1 2mo ago Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot…
CVE-2026-33804 critical 9.1 9.1 fastify 2mo ago @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
CVE-2026-6270 critical 9.1 9.1 fastify 2mo ago @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CVE-2026-31843 critical 9.8 9.8 2mo ago goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
CVE-2026-6350 critical 9.8 9.8 2mo ago MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
CVE-2026-6349 critical 9.8 9.8 2mo ago The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVE-2026-40504 critical 9.8 9.8 2mo ago Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string li…
CVE-2026-40959 critical 9.3 9.3 FIX slesdebian debian 2mo ago Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
CVE-2026-32179 critical 9.5 2mo ago MsQuic has a Remote Elevation of Privilege Vulnerability
CVE-2026-33808 critical 9.1 9.1 fastify 2mo ago Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-…
CVE-2026-33807 critical 9.1 9.1 fastify 2mo ago @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is register…
CVE-2026-6296 critical 9.6 9.6 FIX debian debian linux-kernelmacos macos google 2mo ago Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-39907 critical 10.0 10.0 unisys 2mo ago Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's L…
CVE-2026-39906 critical 10.0 10.0 unisys 2mo ago Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hash…
CVE-2026-34615 critical 9.3 9.3 macos macos adobe 2mo ago Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An…
CVE-2026-27303 critical 9.6 9.6 macos macos adobe 2mo ago Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Ex…
CVE-2026-27246 critical 9.3 9.3 macos macos adobe 2mo ago Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a …
CVE-2026-27245 critical 9.3 9.3 macos macos adobe 2mo ago Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a …
CVE-2026-27243 critical 9.3 9.3 macos macos adobe 2mo ago Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a …
CVE-2026-26149 critical 9.0 9.0 microsoft 2mo ago Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
CVE-2026-33824 critical 9.8 9.8 2mo ago Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-22564 critical 9.8 9.8 2mo ago An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized changes to the system.
 Affected Products: UniFi Play…
CVE-2026-22563 critical 9.8 9.8 2mo ago A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. Affected Products: UniFi Play PowerAmp (Version 1.0…
CVE-2026-22562 critical 9.8 9.8 2mo ago A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code exe…
CVE-2026-31282 critical 9.8 9.8 2mo ago Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker can chain that with missing rate-limit on the log…
CVE-2026-31414 critical 9.8 9.8 FIX slesdebian debian linux-kernel 2mo ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetlink and /proc to dump the helper name. Using nfct_…
CVE-2026-40446 critical 9.8 9.8 samsung 2mo ago Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a715…
CVE-2026-25209 critical 9.1 9.1 samsung 2mo ago Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.
CVE-2026-25208 critical 9.8 9.8 samsung 2mo ago Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.
CVE-2026-25207 critical 9.8 9.8 samsung 2mo ago Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.
CVE-2026-25206 critical 9.1 9.1 samsung 2mo ago Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.
CVE-2026-25205 critical 9.8 9.8 samsung 2mo ago Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash  97e8115ab1110bc502b4b5e4a0c689a71520d335 .
CVE-2026-23891 critical 9.5 2mo ago Decidim has a cross-site scripting (XSS) in user name
CVE-2026-6110 critical 9.8 9.8 deepwisdom 2mo ago MetaGPT has an eval injection in metagpt/strategy/tot.py
CVE-2026-31845 critical 9.3 9.3 2mo ago A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflect…
CVE-2026-6068 critical 9.6 9.6 slesdebian debian nasm 2mo ago NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response…
CVE-2026-6057 critical 9.8 9.8 2mo ago FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
CVE-2026-6024 critical 9.8 9.8 2mo ago A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. …
CVE-2026-5393 critical 9.1 9.1 FIX debian debian wolfssl 2mo ago Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-of-bounds read can occur on crafted input. This can only occur when --enable-ex…
CVE-2026-4631 critical 10.0 EXPFIX rheldebian debian sles 2mo ago Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit…
CVE-2026-5264 critical 9.8 9.8 FIX debian debian wolfssl 2mo ago Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that triggers a heap buffer overflow.
CVE-2026-29145 critical 9.5 FIX slesdebian debian 2mo ago CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0…
CVE-2026-5974 critical 9.8 9.8 deepwisdom 2mo ago FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py