Unknown Vendor
471 tracked CVEs · 0 in CISA KEV · 136 confirmed exploited in the wild.
CVE-2026-42933 · CVSS 10CVE-2026-42933: Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow
CVE-2026-47668 - DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVE-2026-54159: PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear
CVE-2026-56191 - Microsoft Exchange Online Tampering Vulnerability
CVE-2026-58275: Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 - Azure Key Vault Elevation of Privilege Vulnerability
CVE-2026-6516 - Remote Code Execution
CVE-2024-58354: cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
CVE-2026-47724: nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/
CVE-2026-50517 - Microsoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-54052: n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior
CVE-2026-54120: Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Exploit for CVE-2026-60206 exploit
EXPLOITED
View CVE report →
CVE-2026-60369 · CVSS 9.9
CVE-2026-60369: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
EXPLOITED
View CVE report →
CVE-2026-63732 · CVSS 9.9
CVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authent
CVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m
CVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API
CVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul
CVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations
Re: 432 Linux kernel CVEs
CVE-2023-49899: An unauthenticated remote attacker canexecute any command on the affected device due to not correctly verifying the ori
CVE-2023-49900: An unauthenticated remote attacker is able to perform remote code executiondue to incorrectly sanitized user input in t
CVE-2025-65720: An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user
CVE-2026-12393 - WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR
CVE-2026-12492: The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu
CVE-2026-12585: The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover
CVE-2026-12684: The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non
CVE-2026-12692: Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This
Exploit for CVE-2026-13001 exploit
EXPLOITED
View CVE report →
CVE-2026-13067 · CVSS 9.8
CVE-2026-13067 - tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket
CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 containshard-coded credentials, such as a password or cryptographic key, which it
Exploit for CVE-2026-15013 exploit
EXPLOITED
View CVE report →
CVE-2026-15158 · CVSS 9.8
Medium Remote Code Execution [High EPSS] (CVE-2026-15158)
EXPLOITED
View CVE report →
CVE-2026-15704 · CVSS 9.8
Low Security Vulnerability (CVE-2026-15704)
CVE-2026-15981: The SAML Single Sign On SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a
CVE-2026-15982: The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable
CVE-2026-1617 - SQLi in Turkmesh's Turkhotspot 5651 Loglama
CVE-2026-16244: A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit
CVE-2026-16395: Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16396: Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,
CVE-2026-16401: Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird
CVE-2026-16402: Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153
CVE-2026-16408: Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153
CVE-2026-16421 - Google Chrome WebAudio Remote Code Execution Vulnerability
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Low: ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp tra (CVE-2026-17501)
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
CVE-2026-2395: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Trkiye Info
CVE-2026-25039: Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit
Gitea has insufficient permission checks for Composer package source links
CVE-2026-28304 - SolarWinds Serv-U Remote Code Execution Vulnerability
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
EXPLOITED
View CVE report →
CVE-2026-3031 · CVSS 9.8
CVE-2026-3031: Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg
CVE-2026-30618: xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution
EXPLOITED
View CVE report →
CVE-2026-30623 · CVSS 9.8
CVE-2026-30623: LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application
EXPLOITED
View CVE report →
CVE-2026-30631 · CVSS 9.8
CVE-2026-30631: An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Exploit for CVE-2026-3891 exploit
EXPLOITED
View CVE report →
CVE-2026-39808 · CVSS 9.8
CISA Warns of Fortinet FortiSandbox OS Injection Vulnerabilities Exploited in Attacks
EXPLOITED
View CVE report →
CVE-2026-44227 · CVSS 9.8
CVE-2026-44227 - RT: Reflected Cross-Site Scripting via URL parameters
CVE-2026-44228 - RT: Stored Cross-Site Scripting via insufficient template escaping
CVE-2026-44739: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi
CVE-2026-44986: Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation
CVE-2026-45139: CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo
CVE-2026-45260: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass
CVE-2026-45313: Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist
CVE-2026-45382: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_sl
CVE-2026-45383: libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVE-2026-45695: Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en
CVE-2026-45704: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i
CVE-2026-45795: The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac
CVE-2026-45806: Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa
CVE-2026-45813: Apache NimBLE: Incorrect data validation in BASS add/modify source operation
CVE-2026-46562: Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip
CVE-2026-47393 - PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-47396 - PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
CVE-2026-47410 praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
CVE-2026-47657 - HumHub Missing Authorization on Remove All Space Members Action
CVE-2026-47685: FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
CVE-2026-47687: FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
CVE-2026-47688: FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
CVE-2026-47690: MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to
Medium: Sipeed PicoClaw web.go web_fetch server-side request forgery (CVE-2026-47865)
CVE-2026-48062: CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St
CVE-2026-48373: Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i
EXPLOITED
View CVE report →
CVE-2026-48504 · CVSS 9.8
CVE-2026-48504: OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont
CVE-2026-50147: Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2
CVE-2026-52439: An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the p
CVE-2026-52469: SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.
CVE-2026-52890: Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm
CVE-2026-52891: Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil
CVE-2026-52892: Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r
CVE-2026-53421: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen
CVE-2026-53447: Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
CVE-2026-55234: Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j
CVE-2026-55242: ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use
CVE-2026-55440: Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND
CVE-2026-55579 - Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
CVE-2026-55652: Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest
CVE-2026-55968: Apache Thrift: Node.js quadratic-time DoS in server receive transports
Exploit for CVE-2026-56121 exploit
EXPLOITED
View CVE report →
CVE-2026-56165 · CVSS 9.8
CVE-2026-56165 - Microsoft Account Remote Code Execution Vulnerability
CVE-2026-56453: HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter
CVE-2026-56454: HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy
CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application
EXPLOITED
View CVE report →
CVE-2026-56748 · CVSS 9.8
CVE-2026-56748 - Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
CVE-2026-57860 - ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository
Exploit for CVE-2026-58138 exploit
EXPLOITED
View CVE report →
CVE-2026-58389 · CVSS 9.8
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
EXPLOITED
View CVE report →
CVE-2026-59940 · CVSS 9.8
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
EXPLOITED
View CVE report →
CVE-2026-60367 · CVSS 9.8
CVE-2026-60367: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
EXPLOITED
View CVE report →
CVE-2026-61498 · CVSS 9.8
Exploit for CVE-2026-61498
EXPLOITED
View CVE report →
CVE-2026-62183 · CVSS 9.8
CVE-2026-62183: Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure
CVE-2026-62312: 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra
CVE-2026-62314: Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
CVE-2026-63071: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements
CVE-2026-63280: Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manage
CVE-2026-63307 - Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource
CVE-2026-63359: The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att
CVE-2026-63759: SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot
CVE-2026-63760: SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin
CVE-2026-63770 - Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
CVE-2026-64241 - gpio: rockchip: teardown bugs and resource leaks
CVE-2026-64273: In the Linux kernel, the following vulnerability has been resolved: Input: iforce - bound the device-reported force-fee
CVE-2026-64278: In the Linux kernel, the following vulnerability has been resolved: i2c: imx-lpi2c: mark I2C adapter when hardware is p
CVE-2026-64285: In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Pin source page for write when adding CPU
CVE-2026-64303: In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prep
CVE-2026-64330: In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: Validate SVID index in svdm_consu
CVE-2026-64513 - KVM: x86: Unconditionally recompute CR8 intercept on PPR update
CVE-2026-64532: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco
CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
CVE-2026-64619 - FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
CVE-2026-64623: Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the
CVE-2026-64625: AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-q
CVE-2026-64791: Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager
CVE-2026-64796: Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both t
CVE-2026-64824 - Home Assistant Core < 2026.6.0 Symlink Path Traversal RCE via backup-restore
CVE-2026-65617 - Potential remote code execution on an Artifactory package service container.
CVE-2026-65907 - JetBrains TeamCity Remote Code Execution Vulnerability
CVE-2026-65908 - JetBrains PyCharm Arbitrary Code Execution
CVE-2026-66037 - FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()
CVE-2026-66395 - SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol
CVE-2026-66396 - SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL
CVE-2026-66398 - phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API
CVE-2026-8082 - Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection
CVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica
Exploit for CVE-2026-9198 exploit
EXPLOITED
View CVE report →
CVE-2026-9202 · CVSS 9.8
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution
CVE-2026-9586 - Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
CVE-2026-9810: The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val
CVE-2026-15899: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially
CVE-2026-15900: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perfo
CVE-2026-15901: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap
EXPLOITED
View CVE report →
CVE-2026-15902 · CVSS 9.6
CVE-2026-15902: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code insi
Low: Chromium: CVE-2026-16424 Use after free in GPU (CVE-2026-16424)
CVE-2026-22752: Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
CVE-2026-53513: Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin'
CVE-2026-54458: WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi
CVE-2026-55518 - Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Gitea: Public-only repository tokens can update private PR head branches
CVE-2026-65605 - SiYuan before v3.7.2 Stored XSS to RCE via Attribute View
CVE-2026-65606 - SiYuan before v3.7.2 Cross-Site Scripting to RCE
Critical: Thailands Ministry of Finance Targeted With Hermes AI Agent Running Unattended (CVE-2017-7269)
Exploit for CVE-2022-30190 exploit
EXPLOITED
View CVE report →
CVE-2024-24919 · CVSS 9.5
Critical: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (CVE-2024-24919)
EXPLOITED
View CVE report →
CVE-2025-2783 · CVSS 9.5
Exploit for CVE-2025-2783 exploit
EXPLOITED
View CVE report →
CVE-2025-55182 · CVSS 9.5
Critical: Cal.com before 5.9.9 Remote Code Execution via RSC (CVE-2025-55182)
Critical: UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainia (CVE-2025-66376)
CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Critical: Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to J (CVE-2026-11324)
CVE-2026-12495: Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys M
EXPLOITED
View CVE report →
CVE-2026-13385 · CVSS 9.5
ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
Critical: July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploit (CVE-2026-15409)
EXPLOITED
View CVE report →
CVE-2026-47669 · CVSS 9.5
CVE-2026-47669 - DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE
CVE-2026-47670 - DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
CVE-2026-48144: Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affect
Critical: WhatsApp Web chats exposed by Adobes Acrobat extension flaw (CVE-2026-48294)
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
EXPLOITED
View CVE report →
CVE-2026-52824 · CVSS 9.5
Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
CVE-2026-54466: websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
Exploit for CVE-2026-65761 exploit
EXPLOITED
View CVE report →
CVE-2026-65876 · CVSS 9.5
CVE-2026-65876: Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of c
Low: OpenRemote before 1.26.2 Authentication Bypass via Console Registration (CVE-2026-66013)
Critical ServiceNow code execution flaw now exploited in attacks
EXPLOITED
View CVE report →
CVE-2026-12693 · CVSS 9.4
CVE-2026-12693: Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi
CVE-2026-54496 - Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2024-23564 - HCL Aftermarket EPC Business Logic Vulnerability
Hackers Exploiting Palo Altos PAN-OS Vulnerability to Deploy Qilin Ransomware
EXPLOITED
View CVE report →
CVE-2026-10033 · CVSS 9.1
CVE-2026-10033 EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action
CVE-2026-10525 - NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
CVE-2026-11354 - Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter
CVE-2026-11575 - PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
CVE-2026-11961 - User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
CVE-2026-11966 - User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
CVE-2026-12694: Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper
CVE-2026-12978: The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the
Exploit for CVE-2026-13233 exploit
EXPLOITED
View CVE report →
CVE-2026-13402 · CVSS 9.1
CVE-2026-13402 - Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
CVE-2026-13464 - Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
CVE-2026-13693 - Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal
CVE-2026-14890: SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d
CVE-2026-15401 VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
EXPLOITED
View CVE report →
CVE-2026-16394 · CVSS 9.1
CVE-2026-16394: Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16406: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-26718: A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att
CVE-2026-44632: Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a
CVE-2026-45295 - FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint
CVE-2026-46555 - WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVE-2026-46621: Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica
CVE-2026-47158: Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did
CVE-2026-47769 - APIFold Vulnerable to Unauthenticated Webhook Event Injection
CVE-2026-48812 - FreeScout Allows Unauthenticated Access to Legacy Attachment Files
Exploit for CVE-2026-49952 exploit
EXPLOITED
View CVE report →
CVE-2026-53412 · CVSS 9.1
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug
CVE-2026-53512: Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and
CVE-2026-54538 - xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER
CVE-2026-56160 - Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVE-2026-56740 - JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
CVE-2026-56741 - JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
CVE-2026-57206: SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
CVE-2026-58482 - Network-AI: ApprovalInbox HTTP server has no authentication anyone can approve pending agent actions
CVE-2026-60366: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
EXPLOITED
View CVE report →
CVE-2026-61424 · CVSS 9.1
CVE-2026-61424 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
CVE-2026-61900 - Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CVE-2026-62144: An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an
EXPLOITED
View CVE report →
CVE-2026-62241 · CVSS 9.1
CVE-2026-62241: clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')
CVE-2026-63096 - Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
CVE-2026-63098 - TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
CVE-2026-63101 - Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint
CVE-2026-63306: stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e
CVE-2026-63756: SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows
CVE-2026-63757: SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at
CVE-2026-63762: SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript
CVE-2026-63765 - Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
CVE-2026-64319: In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds a
CVE-2026-64320: In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Disc
CVE-2026-64609: Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
CVE-2026-64620: FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt
CVE-2026-64622: Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/
CVE-2026-65455: Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-65879: Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder <
CVE-2026-9103 - Unauthenticated Superuser Token Issuance via Auto-Login Endpoint
CVE-2026-9585 - Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution Across Cloud Workloads
CVE-2026-16630: A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct
EXPLOITED
View CVE report →
CVE-2026-24252 · CVSS 9
CVE-2026-24252 - NVIDIA NeMo OS Command Injection Vulnerability
CVE-2026-58195 - Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
CVE-2026-63108 - Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
CVE-2026-63304: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list
CVE-2026-63305: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and
CVE-2026-66138 - OpenStack Ironic Python Agent Command Injection Vulnerability
CVE-2024-58353: Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac
CVE-2024-58355: Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-15663 Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key
CVE-2026-15904: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user
EXPLOITED
View CVE report →
CVE-2026-15962 · CVSS 8.8
CVE-2026-15962 - Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field
CVE-2026-17191 - VeloCloud Orchestrator Flow Metrics API SQL Injection
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
CVE-2026-3821: Supermicro (SMC) SMASH services contain an Arbitrary code execution issue inX14DBG-DAP and X14DBI. An authorized attack
EXPLOITED
View CVE report →
CVE-2026-42215 · CVSS 8.8
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
CVE-2026-44880 - Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
EXPLOITED
View CVE report →
CVE-2026-45805 · CVSS 8.8
CVE-2026-45805: Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve
Microsoft Security Advisory CVE-2026-47300 .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-47303 .NET Elevation of Privilege Vulnerability
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
EXPLOITED
View CVE report →
CVE-2026-54540 · CVSS 8.8
Pheditor has an authenticated terminal command whitelist bypass
CVE-2026-55578 - Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit Events search
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
CVE-2026-60368: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
EXPLOITED
View CVE report →
CVE-2026-63093 · CVSS 8.8
CVE-2026-63093 - Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
CVE-2026-64835 - FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder
Low: WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Fo (CVE-2026-65608)
CVE-2026-65897 - Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups
CVE-2026-12228: A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (l
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
CVE-2026-54498 - view_component: around_render HTML-Safety Bypass
Exploit for CVE-2026-15583 exploit
EXPLOITED
View CVE report →
CVE-2026-61836 · CVSS 8.6
Directus: Authorization-dependent response served from unsegmented cache key
Budibase: SSRF via DNS rebinding in the REST datasource integration
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-53516: Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
CVE-2026-35149: HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us
EXPLOITED
View CVE report →
CVE-2026-58658 · CVSS 8.2
CVE-2026-58658: GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that a
EXPLOITED
View CVE report →
CVE-2026-60005 · CVSS 8.2
CVE-2026-60005: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slicedirective and
Exploit for CVE-2017-0144 exploit
EXPLOITED
View CVE report →
CVE-2026-13186 · CVSS 8.1
CVE-2026-13186: In Progress Telerik UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence sto
EXPLOITED
View CVE report →
CVE-2026-13187 · CVSS 8.1
CVE-2026-13187: In Progress Telerik UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentia
EXPLOITED
View CVE report →
CVE-2026-1609 · CVSS 8.1
CVE-2026-1609: A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac
EXPLOITED
View CVE report →
CVE-2026-63094 · CVSS 8.1
CVE-2026-63094 - SigNoz 0.133.0 SSO OAuth State Manipulation Session Token Theft
Exploit for CVE-2015-1328 exploit
EXPLOITED
View CVE report →
CVE-2018-3214 · CVSS 7.8
Exploit for CVE-2018-3214 exploit
EXPLOITED
View CVE report →
CVE-2022-35499 · CVSS 7.8
Exploit for CVE-2022-35499 exploit
EXPLOITED
View CVE report →
CVE-2023-4346 · CVSS 7.8
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
EXPLOITED
View CVE report →
CVE-2025-9951 · CVSS 7.8
Exploit for CVE-2025-9951 exploit
EXPLOITED
View CVE report →
CVE-2026-10818 · CVSS 7.8
Exploit for CVE-2026-10818 exploit
EXPLOITED
View CVE report →
CVE-2026-11374 · CVSS 7.8
Exploit for CVE-2026-11374 exploit
EXPLOITED
View CVE report →
CVE-2026-12080 · CVSS 7.8
CVE-2026-12080: A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a
EXPLOITED
View CVE report →
CVE-2026-12191 · CVSS 7.8
Exploit for CVE-2026-12191 exploit
EXPLOITED
View CVE report →
CVE-2026-12592 · CVSS 7.8
CVE-2026-12592: The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu
CVE-2026-12688 - ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery
CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an
EXPLOITED
View CVE report →
CVE-2026-13473 · CVSS 7.8
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner
Exploit for CVE-2026-14266 exploit
EXPLOITED
View CVE report →
CVE-2026-14448 · CVSS 7.8
CVE-2026-14448: An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi
EXPLOITED
View CVE report →
CVE-2026-15895 · CVSS 7.8
CVE-2026-15895: OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent
CVE-2026-15905: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap cor
EXPLOITED
View CVE report →
CVE-2026-16014 · CVSS 7.8
CVE-2026-16014: A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo
CVE-2026-16016: A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex
Exploit for CVE-2026-16219 exploit
EXPLOITED
View CVE report →
CVE-2026-16324 · CVSS 7.8
CVE-2026-16324: A vulnerability was identified in Metasoft MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function
EXPLOITED
View CVE report →
CVE-2026-16354 · CVSS 7.8
CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115
CVE-2026-16357: Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38
CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.
CVE-2026-16360: Memory safety bugs present in Thunderbird ESR 140.12 and Thunderbird 152. Some of these bugs showed evidence of memory c
EXPLOITED
View CVE report →
CVE-2026-16361 · CVSS 7.8
CVE-2026-16361: Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we pre
EXPLOITED
View CVE report →
CVE-2026-16393 · CVSS 7.8
CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunder
CVE-2026-16445: A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia
EXPLOITED
View CVE report →
CVE-2026-16490 · CVSS 7.8
CVE-2026-16490 - itsourcecode Hospital Management System prescription.php sql injection
CVE-2026-16519: A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on
CVE-2026-17523: A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code with
EXPLOITED
View CVE report →
CVE-2026-23550 · CVSS 7.8
Exploit for CVE-2026-23550 exploit
EXPLOITED
View CVE report →
CVE-2026-28220 · CVSS 7.8
CVE-2026-28220: Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
CVE-2026-34150: Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov
CVE-2026-35198: HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i
CVE-2026-3842: A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond
EXPLOITED
View CVE report →
CVE-2026-39359 · CVSS 7.8
CVE-2026-39359: Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through
Exploit for CVE-2026-42533 exploit
EXPLOITED
View CVE report →
CVE-2026-42566 · CVSS 7.8
CVE-2026-42566: Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User
Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability
EXPLOITED
View CVE report →
CVE-2026-43977 · CVSS 7.8
CVE-2026-43977: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth
CVE-2026-43978: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess
CVE-2026-44231: RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prio
CVE-2026-44359: Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository
Exploit for CVE-2026-44680 exploit
EXPLOITED
View CVE report →
CVE-2026-45162 · CVSS 7.8
CVE-2026-45162: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc
CVE-2026-45793: Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf
Exploit for CVE-2026-46420 exploit
EXPLOITED
View CVE report →
CVE-2026-47129 · CVSS 7.8
CVE-2026-47129: NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co
CVE-2026-47130: NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le
CVE-2026-47198: Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the
CVE-2026-48389: DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in
EXPLOITED
View CVE report →
CVE-2026-50055 · CVSS 7.8
Exploit for CVE-2026-50055 exploit
EXPLOITED
View CVE report →
CVE-2026-50454 · CVSS 7.8
Exploit for CVE-2026-50454 exploit
EXPLOITED
View CVE report →
CVE-2026-52813 · CVSS 7.8
Exploit for CVE-2026-52813 exploit
EXPLOITED
View CVE report →
CVE-2026-52869 · CVSS 7.8
CVE-2026-52869: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2,
CVE-2026-52870: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti
Re: CVE-2026-53362, CVE-2026-53366: OOB write in UDP MSG_SPLICE_PAGES fragment-boundary handling in Linux kernel
Exploit for CVE-2026-53595 exploit
EXPLOITED
View CVE report →
CVE-2026-55544 · CVSS 7.8
CVE-2026-55544: NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose
CVE-2026-55550: NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide
CVE-2026-56687: Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attack
EXPLOITED
View CVE report →
CVE-2026-58480 · CVSS 7.8
Exploit for CVE-2026-58480 exploit
EXPLOITED
View CVE report →
CVE-2026-60122 · CVSS 7.8
CVE-2026-60122: gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility tha
CVE-2026-62349: TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc
CVE-2026-62350: TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit
CVE-2026-63107: LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat
EXPLOITED
View CVE report →
CVE-2026-63263 · CVSS 7.8
CVE-2026-63263 - Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-63429: HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no
CVE-2026-63453: Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab
EXPLOITED
View CVE report →
CVE-2026-63454 · CVSS 7.8
CVE-2026-63454: An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an
EXPLOITED
View CVE report →
CVE-2026-63747 · CVSS 7.8
CVE-2026-63747: SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is
Exploit for CVE-2026-63766 exploit
EXPLOITED
View CVE report →
CVE-2026-63771 · CVSS 7.8
CVE-2026-63771: Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by
EXPLOITED
View CVE report →
CVE-2026-64276 · CVSS 7.8
CVE-2026-64276: In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the
CVE-2026-64277: In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the
CVE-2026-64877: An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor
EXPLOITED
View CVE report →
CVE-2026-65971 · CVSS 7.8
Exploit for CVE-2026-65971 exploit
EXPLOITED
View CVE report →
CVE-2026-66012 · CVSS 7.8
Exploit for CVE-2026-66012 exploit
EXPLOITED
View CVE report →
CVE-2026-8297 · CVSS 7.8
CVE-2026-8297: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En
CVE-2026-9762 - IBM Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control
CVE-2026-12497: The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl
CVE-2026-12989: A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at
CVE-2026-12990: An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simul
CVE-2026-12991: The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Visio
CVE-2026-15783 - Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
CVE-2026-16398: Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-49485 - HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2026-50273 - Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-52746 - JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary file read via file reference expansion
CVE-2026-53712 - SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` bomb protection bypass via PCF font loading
vLLM has Remote DoS via Invalid Recovered Token Reinjection
Exploit for CVE-2026-54900 exploit
EXPLOITED
View CVE report →
CVE-2026-55514 · CVSS 7.5
vLLM denial of service via prompt embeds on M-RoPE models
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
EXPLOITED
View CVE report →
CVE-2026-56755 · CVSS 7.5
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
CVE-2026-59252 - Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
CVE-2026-59694 - Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
CVE-2026-59695 - Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-59950: The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,
CVE-2026-60370: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
EXPLOITED
View CVE report →
CVE-2026-65694 · CVSS 7.5
High-Severity Security Vulnerability [High EPSS] (CVE-2026-65694)
EXPLOITED
View CVE report →
CVE-2026-65893 · CVSS 7.5
CVE-2026-65893: This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta
EXPLOITED
View CVE report →
CVE-2026-65894 · CVSS 7.5
CVE-2026-65894: This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacke
EXPLOITED
View CVE report →
CVE-2026-13760 · CVSS 7.3
aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
CVE-2026-15907: A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=
EXPLOITED
View CVE report →
CVE-2026-16152 · CVSS 7.3
CVE-2026-16152: A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of th
EXPLOITED
View CVE report →
CVE-2026-16200 · CVSS 7.3
CVE-2026-16200: A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file cla
EXPLOITED
View CVE report →
CVE-2026-16209 · CVSS 7.3
CVE-2026-16209: A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/se
EXPLOITED
View CVE report →
CVE-2026-16210 · CVSS 7.3
CVE-2026-16210: A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpl
EXPLOITED
View CVE report →
CVE-2026-16327 · CVSS 7.3
CVE-2026-16327: A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_
EXPLOITED
View CVE report →
CVE-2026-16329 · CVSS 7.3
CVE-2026-16329: A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/up
EXPLOITED
View CVE report →
CVE-2026-16331 · CVSS 7.3
CVE-2026-16331: A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/fu
EXPLOITED
View CVE report →
CVE-2026-16332 · CVSS 7.3
CVE-2026-16332: A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_upload
EXPLOITED
View CVE report →
CVE-2026-44878 · CVSS 7.2
CVE-2026-44878: A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r
EXPLOITED
View CVE report →
CVE-2026-44879 · CVSS 7.2
CVE-2026-44879: A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta
EXPLOITED
View CVE report →
CVE-2026-54559 · CVSS 7.2
PocketSphinx: Buffer overflows in language and acoustic model loading code
CVE-2026-56171 - Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-57370: Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
EXPLOITED
View CVE report →
CVE-2026-50325 · CVSS 7
ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
EXPLOITED
View CVE report →
CVE-2026-54570 · CVSS 6.9
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
EXPLOITED
View CVE report →
CVE-2026-54497 · CVSS 6.8
CVE-2026-54497 - view_component: Reused Component Instances Retain Stale Render Context
Critical: Weekly Cyber Security Newsletter Bulletin Certighost Exploit, Checkpoint 0-day (CVE-2025-56383)
EXPLOITED
View CVE report →
CVE-2026-11763 · CVSS 6.5
CVE-2026-11763: Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D
EXPLOITED
View CVE report →
CVE-2026-15343 · CVSS 6.5
CVE-2026-15343 - Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot depende
CVE-2026-16215: A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone
EXPLOITED
View CVE report →
CVE-2026-17514 · CVSS 6.5
CVE-2026-17514: A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex
EXPLOITED
View CVE report →
CVE-2026-2406 · CVSS 6.5
CVE-2026-2406: Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr
EXPLOITED
View CVE report →
CVE-2026-48022 · CVSS 6.5
CVE-2026-48022 - @hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
Exploit for CVE-2026-61946 exploit
EXPLOITED
View CVE report →
CVE-2026-63099 · CVSS 6.5
CVE-2026-63099: TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t
EXPLOITED
View CVE report →
CVE-2026-63100 · CVSS 6.5
CVE-2026-63100: Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u
EXPLOITED
View CVE report →
CVE-2026-63139 · CVSS 6.5
CVE-2026-63139: Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)
EXPLOITED
View CVE report →
CVE-2026-63144 · CVSS 6.5
CVE-2026-63144 - Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-8075 - Posting a malicious markdown image crashes the Mattermost Desktop App
CVE-2026-9602 - Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods
CVE-2026-16015 - poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
EXPLOITED
View CVE report →
CVE-2026-16131 · CVSS 6.3
CVE-2026-16131: A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f
EXPLOITED
View CVE report →
CVE-2026-16199 · CVSS 6.3
CVE-2026-16199: A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the
EXPLOITED
View CVE report →
CVE-2026-16214 · CVSS 6.3
CVE-2026-16214: A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/das
EXPLOITED
View CVE report →
CVE-2026-16334 · CVSS 6.3
CVE-2026-16334: A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o
EXPLOITED
View CVE report →
CVE-2026-66005 · CVSS 6.3
CVE-2026-66005: Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that
EXPLOITED
View CVE report →
CVE-2026-56087 · CVSS 6.1
CVE-2026-56087: Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with ph
EXPLOITED
View CVE report →
CVE-2026-65756 · CVSS 6.1
High-Severity Remote Code Execution [High EPSS] (CVE-2026-65756)
EXPLOITED
View CVE report →
CVE-2026-13188 · CVSS 5.9
CVE-2026-13188: In Progress Telerik UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potential
EXPLOITED
View CVE report →
CVE-2026-34760 · CVSS 5.9
vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
EXPLOITED
View CVE report →
CVE-2026-9271 · CVSS 5.9
Exploit for CVE-2026-9271 exploit
EXPLOITED
View CVE report →
CVE-2026-57852 · CVSS 5.6
CVE-2026-57852: Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att
EXPLOITED
View CVE report →
CVE-2026-12960 · CVSS 5.5
Exploit for CVE-2026-12960 exploit
EXPLOITED
View CVE report →
CVE-2026-6792 · CVSS 5.5
CVE-2026-6792: Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access
EXPLOITED
View CVE report →
CVE-2026-13156 · CVSS 5.4
Exploit for CVE-2026-13156 exploit
EXPLOITED
View CVE report →
CVE-2026-15003 · CVSS 5.3
CVE-2026-15003: A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125
EXPLOITED
View CVE report →
CVE-2026-16013 · CVSS 5.3
CVE-2026-16013 - liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds
EXPLOITED
View CVE report →
CVE-2026-65650 · CVSS 4.3
Exploit for CVE-2026-65650 exploit
EXPLOITED
View CVE report →
CVE-2026-54541 · CVSS 3.7
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
EXPLOITED
View CVE report →
CVE-2026-50416 · CVSS 3.3
Exploit for CVE-2026-50416 exploit
EXPLOITED
View CVE report →