Unknown Vendor
212 tracked CVEs · 0 in CISA KEV · 49 confirmed exploited in the wild.
CVE-2026-54159 · CVSS 10CVE-2026-54159: PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear
CVE-2026-54052: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m
CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API
CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul
CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations
CVE-2023-49899: An unauthenticated remote attacker canexecute any command on the affected device due to not correctly verifying the ori
CVE-2023-49900: An unauthenticated remote attacker is able to perform remote code executiondue to incorrectly sanitized user input in t
CVE-2025-65720: An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user
CVE-2026-12393 - WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR
CVE-2026-12492: The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu
CVE-2026-12585: The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover
CVE-2026-12684: The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non
CVE-2026-12692: Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This
CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 containshard-coded credentials, such as a password or cryptographic key, which it
CVE-2026-15013: The SAML Single Sign On SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algor
CVE-2026-15982: The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable
Gitea has insufficient permission checks for Composer package source links
CVE-2026-3031: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg
CVE-2026-30618: xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution
EXPLOITED
View CVE report →
CVE-2026-30623 · CVSS 9.8
CVE-2026-30623: LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application
EXPLOITED
View CVE report →
CVE-2026-3891 · CVSS 9.8
Exploit for CVE-2026-3891 exploit
EXPLOITED
View CVE report →
CVE-2026-39808 · CVSS 9.8
CISA Warns of Fortinet FortiSandbox OS Injection Vulnerabilities Exploited in Attacks
EXPLOITED
View CVE report →
CVE-2026-44227 · CVSS 9.8
CVE-2026-44227 - RT: Reflected Cross-Site Scripting via URL parameters
CVE-2026-44228 - RT: Stored Cross-Site Scripting via insufficient template escaping
CVE-2026-44359 - Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
CVE-2026-44739: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi
CVE-2026-44986: Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation
CVE-2026-45260: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass
CVE-2026-45313: Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist
CVE-2026-45695: Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en
CVE-2026-45704: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i
CVE-2026-45795: The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac
CVE-2026-45806: Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa
CVE-2026-46562: Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip
Medium: Sipeed PicoClaw web.go web_fetch server-side request forgery (CVE-2026-47865)
CVE-2026-48062: CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St
CVE-2026-48373: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i
EXPLOITED
View CVE report →
CVE-2026-48504 · CVSS 9.8
CVE-2026-48504: OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont
CVE-2026-50147: Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2
CVE-2026-52890: Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm
CVE-2026-52891: Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil
CVE-2026-52892: Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r
CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted Connector
CVE-2026-53447: Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
CVE-2026-55234: Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j
CVE-2026-55242: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use
CVE-2026-55440: Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
CVE-2026-55652: Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest
CVE-2026-56453: HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter
CVE-2026-56454: HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy
CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application
EXPLOITED
View CVE report →
CVE-2026-57860 · CVSS 9.8
CVE-2026-57860 - ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
EXPLOITED
View CVE report →
CVE-2026-60137 · CVSS 9.8
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
EXPLOITED
View CVE report →
CVE-2026-61498 · CVSS 9.8
Exploit for CVE-2026-61498
EXPLOITED
View CVE report →
CVE-2026-62312 · CVSS 9.8
CVE-2026-62312: 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra
CVE-2026-62314: Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap
CVE-2026-63307 - Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource
CVE-2026-63770 - Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
CVE-2026-64619 - FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
CVE-2026-64625 - AVideo before 29.0 OS Command Injection via execAsync
CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution
CVE-2026-9586 - Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
CVE-2026-9810: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val
CVE-2026-22752: Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe
CVE-2026-53513: Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin'
CVE-2026-54458: WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi
CVE-2026-55518 - Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
CVE-2026-54466: websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions
Critical ServiceNow code execution flaw now exploited in attacks
EXPLOITED
View CVE report →
CVE-2026-12693 · CVSS 9.4
CVE-2026-12693: Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi
CVE-2026-54496 - Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2024-23564 - HCL Aftermarket EPC Business Logic Vulnerability
CVE-2026-10525 - NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
CVE-2026-11575 - PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
CVE-2026-11961 - User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
CVE-2026-11966 - User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
CVE-2026-12694: Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper
CVE-2026-12978: The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the
CVE-2026-13402 - Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
CVE-2026-14890: SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d
CVE-2026-26718: A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att
CVE-2026-44632: Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a
CVE-2026-45295 - FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVE-2026-46555 - WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVE-2026-46621: Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica
CVE-2026-47158: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did
CVE-2026-48812 - FreeScout Allows Unauthenticated Access to Legacy Attachment Files
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
CVE-2026-53512: Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and
CVE-2026-54538 - xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER
CVE-2026-56740 - JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
CVE-2026-56741 - JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
CVE-2026-57206: SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
CVE-2026-58482 - Network-AI: ApprovalInbox HTTP server has no authentication anyone can approve pending agent actions
CVE-2026-61424 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
CVE-2026-61900 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CVE-2026-62241: clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')
CVE-2026-63096 - Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVE-2026-63098 - TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVE-2026-63101 - Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint
CVE-2026-63306: stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e
CVE-2026-9103 - Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
CVE-2026-9585 - Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution Across Cloud Workloads
CVE-2026-58195 - Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
CVE-2026-63108 - Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
CVE-2026-63304: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list
CVE-2026-63305: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and
CVE-2026-45805: Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve
Pheditor has an authenticated terminal command whitelist bypass
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
CVE-2026-63093 - Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
CVE-2026-12228: A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (l
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
CVE-2026-54498 - view_component: around_render HTML-Safety Bypass
Exploit for CVE-2026-15583 exploit
EXPLOITED
View CVE report →
CVE-2026-61836 · CVSS 8.6
Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-64623 - Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
CVE-2026-53516: Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
CVE-2026-35149: HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us
EXPLOITED
View CVE report →
CVE-2026-58658 · CVSS 8.2
CVE-2026-58658: GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that a
EXPLOITED
View CVE report →
CVE-2026-60005 · CVSS 8.2
CVE-2026-60005: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slicedirective and
Exploit for CVE-2017-0144 exploit
EXPLOITED
View CVE report →
CVE-2026-1609 · CVSS 8.1
CVE-2026-1609: A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac
EXPLOITED
View CVE report →
CVE-2026-42533 · CVSS 8.1
Critical Heap Buffer Overflow in NGINX Allows Unauthenticated Remote Code Execution
CVE-2026-63094 - SigNoz 0.133.0 SSO OAuth State Manipulation Session Token Theft
Exploit for CVE-2022-35499 exploit
EXPLOITED
View CVE report →
CVE-2023-4346 · CVSS 7.8
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
EXPLOITED
View CVE report →
CVE-2025-9951 · CVSS 7.8
Exploit for CVE-2025-9951 exploit
EXPLOITED
View CVE report →
CVE-2026-11374 · CVSS 7.8
Exploit for CVE-2026-11374 exploit
EXPLOITED
View CVE report →
CVE-2026-12191 · CVSS 7.8
Exploit for CVE-2026-12191 exploit
EXPLOITED
View CVE report →
CVE-2026-13445 · CVSS 7.8
CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an
EXPLOITED
View CVE report →
CVE-2026-13473 · CVSS 7.8
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner
CVE-2026-15895: OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent
CVE-2026-16014: A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo
CVE-2026-16016: A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex
Exploit for CVE-2026-16219 exploit
EXPLOITED
View CVE report →
CVE-2026-23550 · CVSS 7.8
Exploit for CVE-2026-23550 exploit
EXPLOITED
View CVE report →
CVE-2026-34150 · CVSS 7.8
CVE-2026-34150: Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov
CVE-2026-3842: A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond
EXPLOITED
View CVE report →
CVE-2026-39359 · CVSS 7.8
CVE-2026-39359: Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through
CVE-2026-43977: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth
CVE-2026-43978: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess
Exploit for CVE-2026-44680 exploit
EXPLOITED
View CVE report →
CVE-2026-45162 · CVSS 7.8
CVE-2026-45162: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc
CVE-2026-45793: Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf
Exploit for CVE-2026-46420 exploit
EXPLOITED
View CVE report →
CVE-2026-50454 · CVSS 7.8
Exploit for CVE-2026-50454 exploit
EXPLOITED
View CVE report →
CVE-2026-52869 · CVSS 7.8
CVE-2026-52869: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2,
CVE-2026-52870: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti
CVE-2026-56687: Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attack
EXPLOITED
View CVE report →
CVE-2026-62349 · CVSS 7.8
CVE-2026-62349: TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc
CVE-2026-62350: TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit
CVE-2026-8297: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En
CVE-2026-9762 - IBM Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control
CVE-2026-15783 - Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
CVE-2026-49485 - HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2026-50273 - Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-52746 - JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary file read via file reference expansion
CVE-2026-53712 - SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` bomb protection bypass via PCF font loading
vLLM has Remote DoS via Invalid Recovered Token Reinjection
vLLM denial of service via prompt embeds on M-RoPE models
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
CVE-2026-59252 - Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
CVE-2026-59694 - Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
CVE-2026-59695 - Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-59950: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,
CVE-2026-15907: A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=
EXPLOITED
View CVE report →
CVE-2026-16152 · CVSS 7.3
CVE-2026-16152: A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of th
EXPLOITED
View CVE report →
CVE-2026-16200 · CVSS 7.3
CVE-2026-16200: A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file cla
EXPLOITED
View CVE report →
CVE-2026-16209 · CVSS 7.3
CVE-2026-16209: A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/se
EXPLOITED
View CVE report →
CVE-2026-16210 · CVSS 7.3
CVE-2026-16210: A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpl
EXPLOITED
View CVE report →
CVE-2026-14266 · CVSS 7.2
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
PocketSphinx: Buffer overflows in language and acoustic model loading code
CVE-2026-56171 - Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
EXPLOITED
View CVE report →
CVE-2026-54497 · CVSS 6.8
CVE-2026-54497 - view_component: Reused Component Instances Retain Stale Render Context
CVE-2026-11763: Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D
EXPLOITED
View CVE report →
CVE-2026-15343 · CVSS 6.5
CVE-2026-15343 - Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot depende
CVE-2026-16215: A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone
EXPLOITED
View CVE report →
CVE-2026-48022 · CVSS 6.5
CVE-2026-48022 - @hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVE-2026-63099: TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t
EXPLOITED
View CVE report →
CVE-2026-63100 · CVSS 6.5
CVE-2026-63100: Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u
EXPLOITED
View CVE report →
CVE-2026-8075 · CVSS 6.5
CVE-2026-8075 - Posting a malicious markdown image crashes the Mattermost Desktop App
CVE-2026-9602 - Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
CVE-2026-16015 - poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
EXPLOITED
View CVE report →
CVE-2026-16131 · CVSS 6.3
CVE-2026-16131: A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f
EXPLOITED
View CVE report →
CVE-2026-16199 · CVSS 6.3
CVE-2026-16199: A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the
EXPLOITED
View CVE report →
CVE-2026-16214 · CVSS 6.3
CVE-2026-16214: A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/das
EXPLOITED
View CVE report →
CVE-2026-56087 · CVSS 6.1
CVE-2026-56087: Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with ph
EXPLOITED
View CVE report →
CVE-2026-34760 · CVSS 5.9
vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
EXPLOITED
View CVE report →
CVE-2026-9271 · CVSS 5.9
Exploit for CVE-2026-9271 exploit
EXPLOITED
View CVE report →
CVE-2026-57852 · CVSS 5.6
CVE-2026-57852 - Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
EXPLOITED
View CVE report →
CVE-2026-16013 · CVSS 5.3
CVE-2026-16013 - liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
EXPLOITED
View CVE report →
CVE-2026-54541 · CVSS 3.7
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
EXPLOITED
View CVE report →
CVE-2026-50416 · CVSS 3.3
Exploit for CVE-2026-50416 exploit
EXPLOITED
View CVE report →