LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials

CVE & Advisory Tracker

Known vulnerabilities and government advisories — public-domain data, free to host in full.

CVE / IDSeverityTitleAdded
CVE-2026-73570criticalU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog1d ago
CVE-2024-3094highConnecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain2d ago
CVE-2026-69836criticalCritical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)2d ago
CVE-2026-19478criticalGitLab Critical GraphQL Flaw Actively Exploited2d ago
CVE-2026-73570criticalPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw2d ago
CVE-2026-19490criticalCitrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)2d ago
CVE-2026-12569criticalCl0p Targets 40+ Organizations Through PTC Windchill Flaw2d ago
CVE-2026-19478criticalGitLab Code Injection Vulnerability Actively Exploited2d ago
CVE-2026-69836highMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution2d ago
CVE-2026-73570Hackers Target Zimbra Servers in Active Exploitation Campaign3d ago
CVE-2026-69414CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days3d ago
CVE-2026-19489criticalCritical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers3d ago
CVE-2026-73570criticalAttackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution3d ago
CVE-2026-14456highCDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification3d ago
CVE-2026-64849criticalU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog3d ago
CVE-2026-19478criticalCritical GitLab Flaw Exploited Shortly After Disclosure3d ago
CVE-2026-32475criticalElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code3d ago
CVE-2024-39943highOperation CameraSwarm Compromised 14,000+ Dahua Cameras4d ago
CVE-2026-19490criticalCVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway4d ago
CVE-2021-33044highHackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P4d ago
CVE-2026-65400criticalCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation4d ago
CVE-2026-76034criticalCritical Chrome Update Fixes Two Buffer Overflow Vulnerabilities4d ago
CVE-2026-33824U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog4d ago
CVE-2026-68820highCVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now5d ago
CVE-2026-19478criticalCritical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)5d ago
CVE-2026-19478criticalCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects6d ago
CVE-2026-15748criticalForminator WordPress Plugin Vulnerable to Remote Code Execution6d ago
CVE-2026-68820high17th August – Threat Intelligence Report6d ago
CVE-2026-69414highShieldBreak bypasses Microsoft’s patch for earlier Defender flaw6d ago
CVE-2026-15826criticalWordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover6d ago
CVE-2026-58231criticalCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure6d ago
CVE-2026-58231highCrooks Buy Expired Domains for Malware Delivery, Other Threats Detailed7d ago
CVE-2026-58231criticalSAP Commerce Cloud CVE-2026-58231 Exploited in the Wild8d ago
CVE-2026-65400criticalmacOS Screen Sharing Flaw Exploited to Deploy Monero Miners8d ago
CVE-2025-3248The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure8d ago
CVE-2026-46300highMetasploit Wrap Up: Lot of summer shells and fit http profiles9d ago
CVE-2026-71362criticalCritical Adobe Commerce Flaw Exploited After Disclosure10d ago
CVE-2026-20349U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog10d ago
CVE-2026-20349criticalU.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog10d ago
CVE-2026-59310criticalCritical VMware vCenter RCE flaw exploited for reverse SSH access10d ago
CVE-2026-71362Adobe Commerce Bug Targeted Immediately After Disclosure10d ago
CVE-2026-55040criticalAttackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)10d ago
CVE-2026-55040criticalSharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit10d ago
CVE-2026-20349highCisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)10d ago
CVE-2026-55040criticalAttackers Exploit SharePoint Authentication Bypass After Public PoC Release10d ago
CVE-2026-20147highCisco Identity Services Engine Vulnerable to Command Injection10d ago
CVE-2026-4890highDnsmasq DNSSEC Vulnerability Leads to Denial-of-Service10d ago
CVE-2026-20215highClamAV Vulnerability Allows Remote Code Execution10d ago
CVE-2026-20148mediumCisco Identity Services Engine Vulnerability Discloses Sensitive Information10d ago
CVE-2026-20181highCisco Identity Services Engine Vulnerable to RCE via Directory Traversal10d ago
CVE-2026-20190highCisco Identity Services Engine Leaks Information Due to Missing Authentication10d ago
CVE-2026-71362criticalHackers exploit critical Adobe Commerce flaw to hijack customer accounts11d ago
CVE-2026-68820highLazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor11d ago
CVE-2026-68820Lazarus hackers exploited Windows zero-day to target defense firms11d ago
CVE-2026-20349Cisco Patches Firewall Zero-Day Exploited for DoS Attacks11d ago
CVE-2026-68820Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack12d ago
CVE-2026-18577N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-1857713d ago
CVE-2026-8037criticalCISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog15d ago
CVE-2023-38646criticalMetabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication15d ago
CVE-2026-18577highN-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist15d ago
CVE-2026-8037criticalProgress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts15d ago
CVE-2026-63077criticalRapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)16d ago
CVE-2026-64638highNew WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP16d ago
CVE-2021-44228highGrowing Up The Hard Way16d ago
CVE-2026-64564high18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers16d ago
CVE-2026-63078highAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day16d ago
CVE-2026-12537criticalClaude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets16d ago
CVE-2008-4128highJuly 2026 CVE Landscape17d ago
CVE-2017-16740highThousands of US water system controllers remain exposed online17d ago
CVE-2026-64561New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts17d ago
CVE-2026-63077criticalHackers Start Exploiting Recent JetBrains TeamCity Vulnerability17d ago
CVE-2026-68742mediumIndian Cybersecurity Firm Uses Homegrown AI to Discover Three Security Flaws in Enterprise Linux18d ago
CVE-2026-18577N-able warns of N-central auth bypass flaw exploited in attacks20d ago
CVE-2026-66066criticalKindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)20d ago
CVE-2026-48449criticalAdobe fixed a maximum-severity vulnerability flaw in Campaign Classic22d ago
CVE-2026-48449Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction22d ago
CVE-2026-33017highChinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits23d ago
CVE-2026-8233highResearchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw23d ago
CVE-2025-66376highRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes31d ago
CVE-2026-16232highNew Check Point Zero-Day Vulnerability Exploited in the Wild31d ago
CVE-2026-8933highCVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections32d ago
CVE-2026-48294Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft32d ago
CVE-2026-64600RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)32d ago
CVE-2026-50522criticalAnother SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)32d ago
CVE-2026-50522criticalPublic PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-5052233d ago
CVE-2026-50522criticalCritical SharePoint RCE flaw exploited to steal machine keys33d ago
CVE-2026-0257highQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access33d ago
CVE-2026-60137'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover34d ago
CVE-2026-42533criticalCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution35d ago
CVE-2026-15409criticalSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access35d ago
CVE-2026-63030criticalAttackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits35d ago
CVE-2026-60137highTwo High-Severity WordPress Vulnerabilities Require Immediate Patching36d ago
CVE-2026-25089criticalCISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List36d ago
CVE-2026-63030criticalCritical RCE Vulnerability in WordPress Core Affects Millions of Sites37d ago
CVE-2026-60137criticalCloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws37d ago
CVE-2026-58644criticalMicrosoft SharePoint Server RCE Vulnerability Exploited in the Wild37d ago
CVE-2026-28739highMultiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM45d ago
CVE-2026-11405criticalTenda Firmware Vulnerability Allows Unauthenticated Admin Access45d ago
CVE-2026-50746criticalUbiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation46d ago
CVE-2026-24858highFortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices46d ago
CVE-2026-55255criticalAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)46d ago
CVE-2026-12958highBug in top AI coding agents shows that Unix-era security headaches never really die46d ago
CVE-2026-48282criticalU.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog46d ago
CVE-2026-43499critical15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros46d ago
CVE-2026-48282highCISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV46d ago
CVE-2026-20896criticalCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets47d ago
CVE-2026-20896criticalCritical Gitea Flaw Under Active Exploitation, Researchers Warn47d ago
CVE-2026-48282criticalCritical Adobe ColdFusion Vulnerability Exploited in Attacks47d ago
CVE-2024-42009highSuspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities47d ago
CVE-2024-42009highSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universities47d ago
CVE-2026-11405highCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware47d ago
CVE-2026-40138criticalBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA47d ago
CVE-2026-5335916-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems48d ago
CVE-2026-20896criticalThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure48d ago
CVE-2025-3248criticalSysdig clocks first documented case of agentic ransomware48d ago
CVE-2026-46817highRansomware Attacks Hit Financial, Defense, and Manufacturing Firms48d ago
CVE-2026-46242New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android51d ago
CVE-2025-5777Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials52d ago
CVE-2026-20245highTexas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches53d ago
CVE-2026-48558critical'Djinn' Stealer Targets Cloud, AI Credentials55d ago
CVE-2026-20245high29th June – Threat Intelligence Report55d ago
CVE-2024-21762highAI Creates 457 Million Security Issues for Organizations60d ago
CVE-2026-35273criticalOracle Releases June Patch Update Addressing 243 Vulnerabilities66d ago
CVE-2025-54957criticalA 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens102d ago
CVE-2025-55182highEtherRat and TukTuk Malware Campaigns Lead to The Gentleman Ransomware104d ago
CVE-2025-29927highCloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts108d ago
CVE-2024-27227highBringing Rust to the Pixel Baseband135d ago
CVE-2026-33538highCVE-2026-33538: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33527mediumCVE-2026-33527: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33508highCVE-2026-33508: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33498highCVE-2026-33498: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33429mediumCVE-2026-33429: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33421mediumCVE-2026-33421: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33417mediumCVE-2026-33417: Wallos is an open-source, self-hostable personal subscription tracker.152d ago
CVE-2026-33409criticalCVE-2026-33409: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-33323mediumCVE-2026-33323: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.152d ago
CVE-2026-30932highCVE-2026-30932: Froxlor is open source server administration software.152d ago
CVE-2026-2417CVE-2026-2417: A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware ver152d ago
CVE-2026-29772mediumCVE-2026-29772: Astro is a web framework.152d ago
CVE-2026-23924CVE-2026-23924: Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding the152d ago
CVE-2026-23923CVE-2026-23923: An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classe152d ago
CVE-2026-23921CVE-2026-23921: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api152d ago
CVE-2026-23920CVE-2026-23920: Host and event action script input is validated with a regex (set by the administrator), but the validation runs i152d ago
CVE-2026-23919CVE-2026-23919: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript152d ago
CVE-2026-1995highCVE-2026-1995: IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\P152d ago
CVE-2026-33407criticalCVE-2026-33407: Wallos is an open-source, self-hostable personal subscription tracker.152d ago
CVE-2026-33401mediumCVE-2026-33401: Wallos is an open-source, self-hostable personal subscription tracker.152d ago
CVE-2026-33400mediumCVE-2026-33400: Wallos is an open-source, self-hostable personal subscription tracker.152d ago
CVE-2026-33399highCVE-2026-33399: Wallos is an open-source, self-hostable personal subscription tracker.152d ago
CVE-2026-33162mediumCVE-2026-33162: Craft CMS is a content management system (CMS).152d ago
CVE-2026-33161mediumCVE-2026-33161: Craft CMS is a content management system (CMS).152d ago
CVE-2026-33160mediumCVE-2026-33160: Craft CMS is a content management system (CMS).152d ago
CVE-2026-33159mediumCVE-2026-33159: Craft CMS is a content management system (CMS).152d ago
CVE-2026-33158mediumCVE-2026-33158: Craft CMS is a content management system (CMS).152d ago
CVE-2026-33157highCVE-2026-33157: Craft CMS is a content management system (CMS).152d ago
CVE-2026-32854highCVE-2026-32854: LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities 152d ago
CVE-2026-32853highCVE-2026-32853: LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability i152d ago
CVE-2026-26809CVE-2026-26809: Rejected reason: DO NOT USE THIS CVE RECORD.152d ago
CVE-2026-33340criticalCVE-2026-33340: LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems.152d ago
CVE-2025-11571CVE-2025-11571: Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution.152d ago
CVE-2026-33700mediumCVE-2026-33700: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33680highCVE-2026-33680: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33679mediumCVE-2026-33679: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33678highCVE-2026-33678: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33677mediumCVE-2026-33677: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33676mediumCVE-2026-33676: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33675mediumCVE-2026-33675: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33668highCVE-2026-33668: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33474mediumCVE-2026-33474: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33473mediumCVE-2026-33473: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33336highCVE-2026-33336: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33335highCVE-2026-33335: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33334criticalCVE-2026-33334: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-29840mediumCVE-2026-29840: JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function with152d ago
CVE-2026-29839highCVE-2026-29839: DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.152d ago
CVE-2025-71275CVE-2025-71275: Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.152d ago
CVE-2026-4775highCVE-2026-4775: A flaw was found in the libtiff library.152d ago
CVE-2026-33554highCVE-2026-33554: ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages.152d ago
CVE-2026-33316highCVE-2026-33316: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33315mediumCVE-2026-33315: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-33313mediumCVE-2026-33313: Vikunja is an open-source self-hosted task management platform.152d ago
CVE-2026-32647highCVE-2026-32647: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an atta152d ago
CVE-2026-30662mediumCVE-2026-30662: ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component.152d ago
CVE-2026-30661mediumCVE-2026-30661: iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically wit152d ago
CVE-2026-30655mediumCVE-2026-30655: SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remot152d ago
CVE-2026-30653highCVE-2026-30653: An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function Hand152d ago
CVE-2026-28755mediumCVE-2026-28755: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper hand152d ago
CVE-2026-28753lowCVE-2026-28753: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handl152d ago
CVE-2026-27784highCVE-2026-27784: The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might 152d ago
CVE-2026-27654highCVE-2026-27654: NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attack152d ago
CVE-2026-27651highCVE-2026-27651: When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can 152d ago
CVE-2026-33497highCVE-2026-33497: Langflow is a tool for building and deploying AI-powered agents and workflows.152d ago
CVE-2026-33484highCVE-2026-33484: Langflow is a tool for building and deploying AI-powered agents and workflows.152d ago
CVE-2026-33418highCVE-2026-33418: DiceBear is an avatar library for designers and developers.152d ago
CVE-2026-33311mediumCVE-2026-33311: DiceBear is an avatar library for designers and developers.152d ago
CVE-2026-33310highCVE-2026-33310: Intake is a package for finding, investigating, loading and disseminating data.152d ago
CVE-2026-4729criticalCVE-2026-4729: Memory safety bugs present in Firefox 148 and Thunderbird 148.152d ago
CVE-2026-4728mediumCVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking component.152d ago
CVE-2026-4727highCVE-2026-4727: Denial-of-service in the Libraries component in NSS.152d ago
CVE-2026-4726highCVE-2026-4726: Denial-of-service in the XML component.152d ago
CVE-2026-4725criticalCVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component.152d ago
CVE-2026-4724criticalCVE-2026-4724: Undefined behavior in the Audio/Video component.152d ago
CVE-2026-4723criticalCVE-2026-4723: Use-after-free in the JavaScript Engine component.152d ago
CVE-2026-4722highCVE-2026-4722: Privilege escalation in the IPC component.152d ago
CVE-2026-4721criticalCVE-2026-4721: Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunder152d ago
CVE-2026-4720criticalCVE-2026-4720: Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148.152d ago
CVE-2026-4719highCVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component.152d ago
CVE-2026-4718highCVE-2026-4718: Undefined behavior in the WebRTC: Signaling component.152d ago
CVE-2026-4717criticalCVE-2026-4717: Privilege escalation in the Netmonitor component.152d ago
CVE-2026-4716criticalCVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component.152d ago
CVE-2026-4715criticalCVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component.152d ago
CVE-2026-4714highCVE-2026-4714: Incorrect boundary conditions in the Audio/Video component.152d ago
CVE-2026-4713highCVE-2026-4713: Incorrect boundary conditions in the Graphics component.152d ago
CVE-2026-4712highCVE-2026-4712: Information disclosure in the Widget: Cocoa component.152d ago
CVE-2026-4711criticalCVE-2026-4711: Use-after-free in the Widget: Cocoa component.152d ago
CVE-2026-4710criticalCVE-2026-4710: Incorrect boundary conditions in the Audio/Video component.152d ago
CVE-2026-4709highCVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component.152d ago
CVE-2026-4708highCVE-2026-4708: Incorrect boundary conditions in the Graphics component.152d ago
CVE-2026-4707highCVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component.152d ago
CVE-2026-4706highCVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component.152d ago
CVE-2026-4705criticalCVE-2026-4705: Undefined behavior in the WebRTC: Signaling component.152d ago
CVE-2026-4704highCVE-2026-4704: Denial-of-service in the WebRTC: Signaling component.152d ago
CVE-2026-4702criticalCVE-2026-4702: JIT miscompilation in the JavaScript Engine component.152d ago
CVE-2026-4701criticalCVE-2026-4701: Use-after-free in the JavaScript Engine component.152d ago
CVE-2026-4700criticalCVE-2026-4700: Mitigation bypass in the Networking: HTTP component.152d ago
CVE-2026-4699highCVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component.152d ago
CVE-2026-4698criticalCVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component.152d ago
CVE-2026-4697highCVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component.152d ago
CVE-2026-4696criticalCVE-2026-4696: Use-after-free in the Layout: Text and Fonts component.152d ago
CVE-2026-4695highCVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component.152d ago
CVE-2026-4694highCVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component.152d ago
CVE-2026-4693highCVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component.152d ago
CVE-2026-4692criticalCVE-2026-4692: Sandbox escape in the Responsive Design Mode component.152d ago
CVE-2026-4691criticalCVE-2026-4691: Use-after-free in the CSS Parsing and Computation component.152d ago
CVE-2026-4690highCVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component.152d ago
CVE-2026-4689criticalCVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component.152d ago
CVE-2026-4688criticalCVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component.152d ago
CVE-2026-4687highCVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component.152d ago
CVE-2026-4686highCVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component.152d ago
CVE-2026-4685highCVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component.152d ago
CVE-2026-4684highCVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component.152d ago
CVE-2026-33475criticalCVE-2026-33475: Langflow is a tool for building and deploying AI-powered agents and workflows.152d ago
CVE-2026-33309criticalCVE-2026-33309: Langflow is a tool for building and deploying AI-powered agents and workflows.152d ago
CVE-2025-64998highCVE-2025-64998: Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote s152d ago
CVE-2019-25647highCVE-2019-25647: PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated152d ago
CVE-2019-25646criticalCVE-2019-25646: Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote 152d ago
CVE-2019-25645mediumCVE-2019-25645: WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to 152d ago
CVE-2019-25644mediumCVE-2019-25644: WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog t152d ago
CVE-2019-25643highCVE-2019-25643: eNdonesia Portal v8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to exec152d ago
CVE-2019-25642highCVE-2019-25642: Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arb152d ago
CVE-2019-25641highCVE-2019-25641: Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulat152d ago
CVE-2019-25640highCVE-2019-25640: Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate d152d ago
CVE-2019-25639highCVE-2019-25639: Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attacke152d ago
CVE-2019-25638highCVE-2019-25638: Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to e152d ago
CVE-2019-25637highCVE-2019-25637: X-NetStat Pro 5.63 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary152d ago
CVE-2019-25636highCVE-2019-25636: Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da152d ago
CVE-2019-25635highCVE-2019-25635: Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to mani152d ago
CVE-2019-25634highCVE-2019-25634: Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute a152d ago
CVE-2019-25633highCVE-2019-25633: AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local 152d ago
CVE-2019-25632mediumCVE-2019-25632: phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read a152d ago
CVE-2019-25631highCVE-2019-25631: AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local152d ago
CVE-2019-25630highCVE-2019-25630: PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows au152d ago
CVE-2019-25629highCVE-2019-25629: AIDA64 Extreme 5.99.4900 contains a structured exception handler buffer overflow vulnerability in the logging func152d ago
CVE-2019-25628criticalCVE-2019-25628: Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that 152d ago
CVE-2019-25627highCVE-2019-25627: FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers t152d ago
CVE-2019-25626highCVE-2019-25626: River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that all152d ago
CVE-2026-4649CVE-2026-4649: Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages152d ago
CVE-2026-3509highCVE-2026-3509: An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log 152d ago
CVE-2026-32642mediumCVE-2026-32642: Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an applicat152d ago
CVE-2025-41660highCVE-2025-41660: A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system152d ago
CVE-2026-4756highCVE-2026-4756: Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: be152d ago
CVE-2026-4755criticalCVE-2026-4755: CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11152d ago
CVE-2026-4754mediumCVE-2026-4754: CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11152d ago
CVE-2026-33852highCVE-2026-33852: Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue 152d ago
CVE-2026-4753criticalCVE-2026-4753: Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.152d ago
CVE-2026-4752mediumCVE-2026-4752: Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329.152d ago
CVE-2026-4751mediumCVE-2026-4751: NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.152d ago
CVE-2026-4750criticalCVE-2026-4750: Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.152d ago
CVE-2026-4749mediumCVE-2026-4749: NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0.152d ago
CVE-2026-33856highCVE-2026-33856: Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue 152d ago
CVE-2026-33855mediumCVE-2026-33855: Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-Imag152d ago
CVE-2026-33854highCVE-2026-33854: Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: b152d ago
CVE-2026-33853mediumCVE-2026-33853: NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagic152d ago
CVE-2026-33851highCVE-2026-33851: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in joncampbell123 doslib.Thi152d ago
CVE-2026-33850highCVE-2026-33850: Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.152d ago
CVE-2026-33849highCVE-2026-33849: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th152d ago
CVE-2026-33848highCVE-2026-33848: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th152d ago
CVE-2026-33847highCVE-2026-33847: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.Th152d ago
CVE-2026-4746CVE-2026-4746: Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules).152d ago
CVE-2026-4745CVE-2026-4745: Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua 152d ago
CVE-2026-4662highCVE-2026-4662: The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all ve152d ago
CVE-2026-4640highCVE-2026-4640: Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticat152d ago
CVE-2026-4639highCVE-2026-4639: Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticate152d ago
CVE-2026-4632highCVE-2026-4632: A weakness has been identified in itsourcecode Online Enrollment System 1.0.152d ago
CVE-2026-4627highCVE-2026-4627: A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1.152d ago
CVE-2026-4283criticalCVE-2026-4283: The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up152d ago
CVE-2026-3260CVE-2026-3260: Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit.152d ago
CVE-2026-3138mediumCVE-2026-3138: The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a mis152d ago
CVE-2026-4744CVE-2026-4744: Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules).152d ago
CVE-2026-4743CVE-2026-4743: NULL Pointer Dereference vulnerability in taurusxin ncmdump (‎src/utils‎ modules).152d ago
CVE-2026-4742CVE-2026-4742: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide 152d ago
CVE-2026-4741CVE-2026-4741: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid152d ago
CVE-2026-4739CVE-2026-4739: Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat 152d ago
CVE-2026-4738CVE-2026-4738: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/con152d ago
CVE-2026-4737CVE-2026-4737: Use After Free vulnerability in No-Chicken Echo-Mate (‎SDK/rv1106-sdk/sysdrv/source/kernel/mm modules).152d ago
CVE-2026-4736CVE-2026-4736: Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/152d ago
CVE-2026-4735CVE-2026-4735: Deserialization of Untrusted Data vulnerability in DTStack chunjun (‎chunjun-core/src/main/java/com/dtstack/chunjun152d ago
CVE-2026-4734CVE-2026-4734: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libop152d ago
CVE-2026-4733mediumCVE-2026-4733: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue a152d ago
CVE-2026-4732CVE-2026-4732: Out-of-bounds Read vulnerability in tildearrow furnace (‎extern/libsndfile-modified/src modules).152d ago
CVE-2026-4731CVE-2026-4731: Integer Overflow or Wraparound vulnerability in artraweditor ART (‎rtengine‎ modules).152d ago
CVE-2026-4626lowCVE-2026-4626: A vulnerability has been found in projectworlds Lawyer Management System 1.0.152d ago
CVE-2026-4625highCVE-2026-4625: A flaw has been found in SourceCodester Online Admission System 1.0.152d ago
CVE-2026-4624highCVE-2026-4624: A vulnerability was detected in SourceCodester Online Library Management System 1.0.152d ago
CVE-2026-4623highCVE-2026-4623: A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b152d ago
CVE-2026-33308mediumCVE-2026-33308: Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS.152d ago
CVE-2026-3079mediumCVE-2026-3079: The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_ord152d ago
CVE-2026-33307highCVE-2026-33307: Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS.152d ago
CVE-2026-4680highCVE-2026-4680: Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary cod153d ago
CVE-2026-4679highCVE-2026-4679: Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of b153d ago
CVE-2026-4678highCVE-2026-4678: Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary co153d ago
CVE-2026-4677highCVE-2026-4677: Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perf153d ago
CVE-2026-4676highCVE-2026-4676: Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a 153d ago
CVE-2026-4675highCVE-2026-4675: Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out 153d ago
CVE-2026-4674highCVE-2026-4674: Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of boun153d ago
CVE-2026-4673highCVE-2026-4673: Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an o153d ago
CVE-2026-4617highCVE-2026-4617: A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0.153d ago
CVE-2026-4616lowCVE-2026-4616: A security flaw has been discovered in bolo-blog up to 2.6.4.153d ago
CVE-2026-33320mediumCVE-2026-33320: Dasel is a command-line tool and library for querying, modifying, and transforming data structures.153d ago
CVE-2026-33306highCVE-2026-33306: bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm.153d ago
CVE-2026-33298highCVE-2026-33298: llama.cpp is an inference of several LLM models in C/C++.153d ago
CVE-2026-33290mediumCVE-2026-33290: WPGraphQL provides a GraphQL API for WordPress sites.153d ago
CVE-2026-22739highCVE-2026-22739: Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Conf153d ago
CVE-2026-4615highCVE-2026-4615: A vulnerability was identified in SourceCodester Online Catering Reservation 1.0.153d ago
CVE-2026-4614mediumCVE-2026-4614: A vulnerability was determined in itsourcecode sanitize or validate this input 1.0.153d ago
CVE-2026-4613highCVE-2026-4613: A vulnerability was found in SourceCodester E-Commerce Site 1.0.153d ago
CVE-2026-4056mediumCVE-2026-4056: The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a153d ago
CVE-2026-4021highCVE-2026-4021: The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeove153d ago
CVE-2026-4001criticalCVE-2026-4001: The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versio153d ago
CVE-2026-3533highCVE-2026-3533: The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on impor153d ago
CVE-2026-33286criticalCVE-2026-33286: Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface.153d ago
CVE-2026-33283mediumCVE-2026-33283: Ella Core is a 5G core designed for private networks.153d ago
CVE-2026-33282highCVE-2026-33282: Ella Core is a 5G core designed for private networks.153d ago
CVE-2026-33281mediumCVE-2026-33281: Ella Core is a 5G core designed for private networks.153d ago
CVE-2026-33252highCVE-2026-33252: The Go MCP SDK used Go's standard encoding/json.153d ago
CVE-2026-33250highCVE-2026-33250: Freeciv21 is a free open source, turn-based, empire-building strategy game.153d ago
CVE-2026-33242highCVE-2026-33242: Salvo is a Rust web framework.153d ago
CVE-2026-33241highCVE-2026-33241: Salvo is a Rust web framework.153d ago
CVE-2026-33211criticalCVE-2026-33211: Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines.153d ago
CVE-2026-33202criticalCVE-2026-33202: Active Storage allows users to attach cloud and local files in Rails applications.153d ago
CVE-2026-33195criticalCVE-2026-33195: Active Storage allows users to attach cloud and local files in Rails applications.153d ago
CVE-2026-33176highCVE-2026-33176: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework.153d ago
CVE-2026-33174highCVE-2026-33174: Active Storage allows users to attach cloud and local files in Rails applications.153d ago
CVE-2026-33173mediumCVE-2026-33173: Active Storage allows users to attach cloud and local files in Rails applications.153d ago
CVE-2026-33170mediumCVE-2026-33170: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework.153d ago
CVE-2026-33169mediumCVE-2026-33169: Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework.153d ago
CVE-2026-4306highCVE-2026-4306: The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up153d ago
CVE-2026-4066mediumCVE-2026-4066: The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili153d ago
CVE-2026-3225mediumCVE-2026-3225: The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question 153d ago
CVE-2026-33168CVE-2026-33168: Action View provides conventions and helpers for building web pages with the Rails framework.153d ago
CVE-2026-33167CVE-2026-33167: Action Pack is a Rubygem for building web applications on the Rails framework.153d ago
CVE-2026-33046highCVE-2026-33046: Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.153d ago
CVE-2026-2412mediumCVE-2026-2412: The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' para153d ago
CVE-2026-4681CVE-2026-4681: A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM.153d ago
CVE-2026-4612highCVE-2026-4612: A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0.153d ago
CVE-2026-4611highCVE-2026-4611: A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826.153d ago
CVE-2026-33634highCVE-2026-33634: Trivy is a security scanner.153d ago
CVE-2026-32913criticalCVE-2026-32913: OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards 153d ago
CVE-2026-32912CVE-2026-32912: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32911CVE-2026-32911: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32910CVE-2026-32910: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32909CVE-2026-32909: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32908CVE-2026-32908: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32907CVE-2026-32907: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32904CVE-2026-32904: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32903CVE-2026-32903: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32902CVE-2026-32902: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32901CVE-2026-32901: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32900CVE-2026-32900: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32300highCVE-2026-32300: Connect-CMS is a content management system.153d ago
CVE-2026-32299highCVE-2026-32299: Connect-CMS is a content management system.153d ago
CVE-2026-32279mediumCVE-2026-32279: Connect-CMS is a content management system.153d ago
CVE-2026-32278highCVE-2026-32278: Connect-CMS is a content management system.153d ago
CVE-2026-32277highCVE-2026-32277: Connect-CMS is a content management system.153d ago
CVE-2026-32276highCVE-2026-32276: Connect-CMS is a content management system.153d ago
CVE-2026-32066CVE-2026-32066: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32047CVE-2026-32047: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-32012CVE-2026-32012: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-29111mediumCVE-2026-29111: systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC AP153d ago
CVE-2026-28483CVE-2026-28483: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-28455CVE-2026-28455: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-27646mediumCVE-2026-27646: OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows a153d ago
CVE-2026-27183mediumCVE-2026-27183: OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wr153d ago
CVE-2026-22173CVE-2026-22173: Rejected reason: This CVE ID has been rejected.153d ago
CVE-2026-1940mediumCVE-2026-1940: An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function.153d ago
CVE-2025-60949criticalCVE-2025-60949: Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments.153d ago
CVE-2025-60948mediumCVE-2025-60948: Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields.153d ago
CVE-2025-60947highCVE-2025-60947: Census CSWeb 8.0.1 allows arbitrary file upload.153d ago
CVE-2025-60946highCVE-2025-60946: Census CSWeb 8.0.1 allows arbitrary file path input.153d ago
CVE-2026-4597mediumCVE-2026-4597: A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4.153d ago
CVE-2026-4368CVE-2026-4368: Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, 153d ago
CVE-2026-3055criticalCVE-2026-3055: Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memor153d ago
CVE-2026-23882highCVE-2026-23882: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23488mediumCVE-2026-23488: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23487mediumCVE-2026-23487: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23486mediumCVE-2026-23486: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23485mediumCVE-2026-23485: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23484mediumCVE-2026-23484: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23483mediumCVE-2026-23483: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23482highCVE-2026-23482: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23481mediumCVE-2026-23481: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-23480highCVE-2026-23480: Blinko is an AI-powered card note-taking project.153d ago
CVE-2026-4596lowCVE-2026-4596: A vulnerability was identified in projectworlds Lawyer Management System 1.0.153d ago
CVE-2026-33548mediumCVE-2026-33548: Mantis Bug Tracker (MantisBT) is an open source issue tracker.153d ago
CVE-2026-33517mediumCVE-2026-33517: Mantis Bug Tracker (MantisBT) is an open source issue tracker.153d ago
CVE-2026-32879mediumCVE-2026-32879: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system.153d ago
CVE-2026-32852mediumCVE-2026-32852: MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface153d ago
CVE-2026-32851mediumCVE-2026-32851: MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface153d ago
CVE-2026-32850mediumCVE-2026-32850: MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface153d ago
CVE-2026-30886mediumCVE-2026-30886: New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system.153d ago
CVE-2026-30849criticalCVE-2026-30849: Mantis Bug Tracker (MantisBT) is an open source issue tracker.153d ago
CVE-2026-2298criticalCVE-2026-2298: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Mark153d ago
CVE-2026-27131mediumCVE-2026-27131: The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS.153d ago
CVE-2025-52204mediumCVE-2025-52204: A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCus153d ago
CVE-2024-46879mediumCVE-2024-46879: A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.153d ago
CVE-2024-46878mediumCVE-2024-46878: A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 153d ago
CVE-2026-4595lowCVE-2026-4595: A vulnerability was determined in code-projects Exam Form Submission 1.0.153d ago
CVE-2026-33723highCVE-2026-33723: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33719highCVE-2026-33719: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33717highCVE-2026-33717: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33716criticalCVE-2026-33716: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33690mediumCVE-2026-33690: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33688mediumCVE-2026-33688: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33685mediumCVE-2026-33685: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33683mediumCVE-2026-33683: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33681highCVE-2026-33681: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33651highCVE-2026-33651: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33650highCVE-2026-33650: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33649highCVE-2026-33649: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33648highCVE-2026-33648: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33647highCVE-2026-33647: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33513highCVE-2026-33513: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33512highCVE-2026-33512: WWBN AVideo is an open source video platform.153d ago
CVE-2026-26209highCVE-2026-26209: cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format.153d ago
CVE-2026-25075highCVE-2026-25075: strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser tha153d ago
CVE-2026-0898CVE-2026-0898: An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are 153d ago
CVE-2025-15606highCVE-2025-15606: A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input s153d ago
CVE-2026-4594highCVE-2026-4594: A vulnerability has been found in erupts erupt up to 1.13.3.153d ago
CVE-2025-15605highCVE-2025-15605: A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 e153d ago
CVE-2025-15519highCVE-2025-15519: Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and153d ago
CVE-2025-15518highCVE-2025-15518: Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and153d ago
CVE-2025-15517highCVE-2025-15517: A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi e153d ago
CVE-2026-4593mediumCVE-2026-4593: A flaw has been found in erupts erupt bis 1.13.3.153d ago
CVE-2026-33507highCVE-2026-33507: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33502criticalCVE-2026-33502: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33501mediumCVE-2026-33501: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33500mediumCVE-2026-33500: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33499mediumCVE-2026-33499: WWBN AVideo is an open source video platform.153d ago
CVE-2026-30007mediumCVE-2026-30007: XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file153d ago
CVE-2026-30006mediumCVE-2026-30006: XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.153d ago
CVE-2026-26829highCVE-2026-26829: A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allow153d ago
CVE-2026-26828highCVE-2026-26828: A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652153d ago
CVE-2026-24516highCVE-2026-24516: A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2.153d ago
CVE-2026-4592mediumCVE-2026-4592: A security vulnerability has been detected in kalcaddle kodbox 1.64.153d ago
CVE-2026-4591mediumCVE-2026-4591: A weakness has been identified in kalcaddle kodbox 1.64.153d ago
CVE-2026-33493highCVE-2026-33493: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33492highCVE-2026-33492: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33488highCVE-2026-33488: WWBN AVideo is an open source video platform.153d ago
CVE-2026-32845highCVE-2026-32845: cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when valid153d ago
CVE-2024-51226mediumCVE-2024-51226: A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle153d ago
CVE-2024-51225mediumCVE-2024-51225: A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Reco153d ago
CVE-2024-51224mediumCVE-2024-51224: Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle153d ago
CVE-2024-51223mediumCVE-2024-51223: A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record153d ago
CVE-2024-51222mediumCVE-2024-51222: A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record153d ago
CVE-2026-4590lowCVE-2026-4590: A security flaw has been discovered in kalcaddle kodbox 1.64.153d ago
CVE-2026-4404criticalCVE-2026-4404: Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default pass153d ago
CVE-2026-33485highCVE-2026-33485: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33483highCVE-2026-33483: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33482highCVE-2026-33482: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33480highCVE-2026-33480: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33479highCVE-2026-33479: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33478criticalCVE-2026-33478: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33354highCVE-2026-33354: WWBN AVideo is an open source video platform.153d ago
CVE-2026-4647mediumCVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object 153d ago
CVE-2026-4645CVE-2026-4645: Rejected reason: Duplicate of CVE-2026-32287153d ago
CVE-2026-4589mediumCVE-2026-4589: A vulnerability was identified in kalcaddle kodbox 1.64.153d ago
CVE-2026-3635mediumCVE-2026-3635: Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0153d ago
CVE-2026-33352criticalCVE-2026-33352: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33351criticalCVE-2026-33351: WWBN AVideo is an open source video platform.153d ago
CVE-2026-33297criticalCVE-2026-33297: WWBN AVideo is an open source video platform.153d ago
CVE-2025-41008CVE-2025-41008: SQL injection vulnerability in Sinturno.153d ago
CVE-2019-25625mediumCVE-2019-25625: Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application b153d ago
CVE-2019-25624mediumCVE-2019-25624: Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application153d ago
CVE-2019-25623mediumCVE-2019-25623: Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the applicat153d ago
CVE-2019-25622mediumCVE-2019-25622: Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application 153d ago
CVE-2019-25621mediumCVE-2019-25621: Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application 153d ago
CVE-2019-25620mediumCVE-2019-25620: Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application b153d ago
CVE-2026-4588lowCVE-2026-4588: A vulnerability was determined in kalcaddle kodbox 1.64.153d ago
CVE-2026-4587lowCVE-2026-4587: A vulnerability was found in HybridAuth up to 3.12.2.153d ago
CVE-2026-4586mediumCVE-2026-4586: A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7.153d ago