Search

Found 45,176 results in 3381ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-68708 low 2.4 2.4 9d ago SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's …
CVE-2026-47672 medium 6.5 6.5 9d ago epa4all-client: Unauthenticated REST API for Patient Record Writes
CVE-2026-9582 medium 4.3 4.3 9d ago A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site …
CVE-2026-44708 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 9d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied con…
CVE-2026-44899 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 9d ago Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^…
CVE-2026-44896 medium 6.1 6.1 slesdebian debianwindows windows mistune_project 9d ago Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options direc…
CVE-2025-68710 low 2.4 2.4 9d ago Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay …
CVE-2026-44844 medium 5.5 windows windows 9d ago eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurse…
CVE-2026-9579 medium 6.3 6.3 9d ago A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument u…
CVE-2026-44836 medium 6.5 6.5 debian debian 9d ago view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls…
CVE-2026-44214 medium 5.3 5.3 rexxars 9d ago eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage b…
CVE-2026-48047 medium 5.5 9d ago XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
CVE-2026-25426 medium 5.3 5.3 9d ago Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking M…
CVE-2026-24520 medium 4.3 4.3 9d ago Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24.
CVE-2026-25444 medium 4.3 4.3 9d ago Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.
CVE-2026-35202 low 2.5 9d ago Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass their assigned limits for database allocat…
CVE-2026-27331 medium 6.3 6.3 9d ago Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5.
CVE-2026-9572 low 3.3 3.3 debian debian gpac 9d ago A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of t…
CVE-2026-9567 low 3.3 3.3 debian debian 9d ago A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointe…
CVE-2026-7453 medium 5.5 5.5 autodesk 9d ago A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.
CVE-2026-7450 medium 5.5 5.5 autodesk 9d ago A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a deni…
CVE-2026-44749 medium 4.3 4.3 9d ago The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leadi…
CVE-2026-9568 medium 5.0 5.0 9d ago A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. Th…
CVE-2026-42448 low 3.5 3.5 9d ago Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
CVE-2026-41164 medium 4.4 4.4 9d ago nuts-node has JWT type confusion in v1 access token introspection that allows VP replay as access token
CVE-2025-33221 medium 4.4 4.4 9d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of…
CVE-2026-24201 medium 5.8 5.8 9d ago NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering…
CVE-2026-24197 medium 6.5 6.5 9d ago NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lea…
CVE-2026-24199 medium 4.7 4.7 nvidia 9d ago NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of…
CVE-2026-24198 medium 5.6 5.6 9d ago NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive informati…
CVE-2026-9565 medium 6.3 6.3 9d ago A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handle…
CVE-2026-9564 low 2.4 2.4 9d ago A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Perf…
CVE-2026-48693 medium 5.5 5.5 debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defaults to '/tmp/fastnetmon.dat' (src/fastnetmon.cpp l…
CVE-2026-47728 medium 4.3 4.3 9d ago Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An a…
CVE-2026-47715 low 3.1 3.1 9d ago Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requir…
CVE-2026-46431 medium 4.3 4.3 9d ago Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVE-2026-46430 medium 4.3 4.3 9d ago Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
CVE-2026-44314 medium 4.3 4.3 traccar 9d ago Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and th…
CVE-2026-24182 medium 6.5 6.5 9d ago NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.
CVE-2026-30894 medium 6.1 6.1 joomla 9d ago Lack of output escaping leads to a XSS vector in the content history component.
CVE-2025-36145 medium 5.3 5.3 ibm 9d ago IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
CVE-2025-14290 medium 5.4 5.4 ibm 9d ago IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). Th…
CVE-2025-13755 medium 5.5 5.5 ibm 9d ago IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local …
CVE-2026-44707 medium 6.8 6.8 9d ago Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enf…
CVE-2026-9566 medium 4.3 4.3 9d ago A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipul…
CVE-2026-48903 medium 6.1 6.1 joomla 9d ago Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-35220 medium 4.3 4.3 joomla 9d ago Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-48905 medium 6.1 6.1 joomla 9d ago Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-25901 medium 6.1 6.1 joomla 9d ago Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-48900 medium 4.3 4.3 joomla 9d ago An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-25900 medium 6.1 6.1 joomla 9d ago Lack of output escaping leads to a XSS vector in the feed modules.
CVE-2026-30895 medium 6.1 6.1 joomla 9d ago Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVE-2025-66407 medium 5.5 9d ago Weblate has a Server-Side Request Forgery issue
CVE-2026-47716 low 3.1 3.1 9d ago Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the requested bulk action to the …
CVE-2026-48685 medium 6.5 6.5 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_…
CVE-2026-48684 medium 6.5 6.5 FIX debian debian pavel-odintsov 9d ago FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.…
CVE-2026-48683 medium 6.5 6.5 FIX debian debian 9d ago FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template bra…
CVE-2026-43936 medium 4.3 4.3 9d ago e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "M…
CVE-2026-43934 medium 6.5 6.5 9d ago e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by othe…
CVE-2026-40564 medium 6.5 6.5 apache 9d ago Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so th…
CVE-2026-38587 medium 4.3 4.3 9d ago An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-l…
CVE-2026-44502 medium 4.3 4.3 9d ago Bunsink has an SSRF bypass in `validate_webhook_url`
CVE-2025-36148 medium 6.1 6.1 ibm 9d ago IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allo…
CVE-2026-41401 medium 6.5 6.5 sleswindows windowsdebian debian 9d ago libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. At…
CVE-2026-46620 medium 6.5 6.5 9d ago e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check…
CVE-2026-9542 medium 6.3 6.3 9d ago A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_i…
CVE-2026-9541 medium 5.3 5.3 debian debian squirrel-lang 9d ago A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results …
CVE-2026-9540 medium 5.3 5.3 9d ago A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial of service. I…
CVE-2026-8174 medium 5.7 5.7 9d ago Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2.
CVE-2026-48136 medium 4.1 4.1 9d ago When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Comp…
CVE-2026-48134 medium 5.6 5.6 9d ago When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to…
CVE-2026-41917 medium 4.9 4.9 9d ago OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying…
CVE-2026-48135 medium 5.3 5.3 9d ago A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.
CVE-2026-44410 low 3.8 3.8 10d ago This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out ma…
CVE-2026-39642 medium 5.3 5.3 10d ago Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a through 1.7.
CVE-2026-27427 medium 6.5 6.5 10d ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.
CVE-2026-24638 medium 4.3 4.3 10d ago Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.
CVE-2026-24590 medium 5.3 5.3 10d ago Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey…
CVE-2026-39655 medium 5.3 5.3 10d ago Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.
CVE-2026-9534 medium 6.3 6.3 10d ago A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the arg…
CVE-2026-9533 medium 6.3 6.3 10d ago A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a mani…
CVE-2026-9532 medium 6.3 6.3 10d ago A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Su…
CVE-2026-3314 medium 4.6 4.6 10d ago Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint…
CVE-2026-9531 medium 6.3 6.3 10d ago A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the arg…
CVE-2026-9530 low 3.3 3.3 10d ago A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgbmp Utility. Executing a mani…
CVE-2026-9529 low 3.3 3.3 10d ago A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulati…
CVE-2026-9527 medium 4.3 4.3 10d ago A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes …
CVE-2026-9524 medium 6.3 6.3 10d ago A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulation of the argument reportPa…
CVE-2026-9520 medium 4.3 4.3 10d ago A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the comp…
CVE-2026-9519 medium 4.3 4.3 10d ago A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto…
CVE-2026-9518 medium 4.3 4.3 10d ago A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. T…
CVE-2026-4795 medium 6.5 6.5 10d ago A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0,  GS1200-5HPv3 firmware versions through 1.00(A…
CVE-2026-9515 medium 6.3 6.3 10d ago A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation…
CVE-2026-48696 medium 6.2 6.2 FIX debian debian pavel-odintsov 10d ago FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.
CVE-2026-4438 medium 5.5 FIX rheldebian debian sles google 10d ago Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS host…
CVE-2026-4437 medium 5.5 FIX rheldebian debian sles google 10d ago Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from…
CVE-2026-4046 medium 5.5 FIX rheldebian debian sles google 10d ago RHSA-2026:20587: glibc security update (Moderate)
CVE-2026-40386 medium 5.5 FIX debian debian sles rhel 10d ago Moderate: libexif security update
CVE-2026-40385 medium 5.5 FIX debian debian sles rhel 10d ago Moderate: libexif security update
CVE-2026-36239 medium 4.3 4.3 10d ago PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality