Security advisories — page 4
- CVE-2021-27561unknownYealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
- CVE-2021-27562unknownArm Trusted Firmware Out-of-Bounds Write Vulnerability
- CVE-2021-28310unknownMicrosoft Win32k Privilege Escalation Vulnerability
- CVE-2021-28550unknownAdobe Acrobat and Reader Use-After-Free Vulnerability
- CVE-2021-28663unknownArm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
- CVE-2021-28664unknownArm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability
- CVE-2020-1147unknownMicrosoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
- CVE-2019-19781criticalCVE-2019-19781 updated by NVD
- CVE-2021-30116criticalCVE-2021-30116 updated by NVD
- CVE-2018-6789unknownExim Buffer Overflow Vulnerability
- CVE-2019-20085unknownTVT NVMS-1000 Directory Traversal Vulnerability
- CVE-2021-30551unknownGoogle Chromium V8 Type Confusion Vulnerability
- CVE-2021-30554unknownGoogle Chromium WebGL Use-After-Free Vulnerability
- CVE-2021-30563unknownGoogle Chromium V8 Type Confusion Vulnerability
- CVE-2021-30632unknownGoogle Chromium V8 Out-of-Bounds Write Vulnerability
- CVE-2021-30633unknownGoogle Chromium Indexed DB API Use-After-Free Vulnerability
- CVE-2021-30657unknownApple macOS Unspecified Vulnerability
- CVE-2021-30661unknownApple Multiple Products WebKit Storage Use-After-Free Vulnerability
- CVE-2021-30663unknownApple Multiple Products WebKit Integer Overflow Vulnerability
- CVE-2021-30665unknownApple Multiple Products WebKit Memory Corruption Vulnerability
- CVE-2021-30666unknownApple iOS WebKit Buffer Overflow Vulnerability
- CVE-2021-30713unknownApple macOS Unspecified Vulnerability
- CVE-2021-30761unknownApple iOS WebKit Memory Corruption Vulnerability
- CVE-2021-30762unknownApple iOS WebKit Use-After-Free Vulnerability
- CVE-2021-30807unknownApple Multiple Products Memory Corruption Vulnerability
- CVE-2021-30858unknownApple iOS, iPadOS, macOS Use-After-Free Vulnerability
- CVE-2021-30860unknownApple Multiple Products Integer Overflow Vulnerability
- CVE-2021-30869unknownApple iOS, iPadOS, and macOS Type Confusion Vulnerability
- CVE-2021-31199unknownMicrosoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
- CVE-2021-31201unknownMicrosoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability
- CVE-2019-2215unknownAndroid Kernel Use-After-Free Vulnerability
- CVE-2021-31207unknownMicrosoft Exchange Server Security Feature Bypass Vulnerability
- CVE-2021-31755unknownTenda AC11 Router Stack Buffer Overflow Vulnerability
- CVE-2021-31955unknownMicrosoft Windows Kernel Information Disclosure Vulnerability
- CVE-2021-31956unknownMicrosoft Windows NTFS Privilege Escalation Vulnerability
- CVE-2021-31979highCVE-2021-31979 updated by NVD
- CVE-2020-11651unknownSaltStack Salt Authentication Bypass Vulnerability
- CVE-2020-11652unknownSaltStack Salt Path Traversal Vulnerability
- CVE-2020-11738unknownWordPress Snap Creek Duplicator Plugin File Download Vulnerability
- CVE-2021-33739unknownMicrosoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
- CVE-2021-33742unknownMicrosoft Windows MSHTML Platform Remote Code Execution Vulnerability
- CVE-2018-7600unknownDrupal Core Remote Code Execution Vulnerability
- CVE-2020-12271unknownSophos SFOS SQL Injection Vulnerability
- CVE-2020-12812criticalCVE-2020-12812 updated by NVD
- CVE-2020-1350unknownMicrosoft Windows DNS Server Remote Code Execution Vulnerability
- CVE-2020-1380unknownMicrosoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
- CVE-2021-33771highCVE-2021-33771 updated by NVD
- CVE-2020-1464unknownMicrosoft Windows Spoofing Vulnerability
- CVE-2020-1472unknownMicrosoft Netlogon Privilege Escalation Vulnerability
- CVE-2020-14750unknownOracle WebLogic Server Remote Code Execution Vulnerability
- CVE-2020-14871unknownOracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
- CVE-2020-14882unknownOracle WebLogic Server Remote Code Execution Vulnerability
- CVE-2020-14883unknownOracle WebLogic Server Unspecified Vulnerability
- CVE-2020-15505unknownIvanti MobileIron Multiple Products Remote Code Execution Vulnerability
- CVE-2021-34448mediumCVE-2021-34448 updated by NVD
- CVE-2018-8653unknownMicrosoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
- CVE-2019-0211unknownApache HTTP Server Privilege Escalation Vulnerability
- CVE-2019-0541unknownMicrosoft MSHTML Remote Code Execution Vulnerability
- CVE-2020-15999unknownGoogle Chrome FreeType Heap Buffer Overflow Vulnerability
- CVE-2020-16009unknownGoogle Chromium V8 Type Confusion Vulnerability
- CVE-2020-16010unknownGoogle Chrome for Android UI Heap Buffer Overflow Vulnerability
- CVE-2020-16013unknownGoogle Chromium V8 Incorrect Implementation Vulnerabililty
- CVE-2020-16017unknownGoogle Chrome Use-After-Free Vulnerability
- CVE-2020-16846unknownSaltStack Salt Shell Injection Vulnerability
- CVE-2020-17087unknownMicrosoft Windows Kernel Privilege Escalation Vulnerability
- CVE-2020-17144unknownMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-34473criticalCVE-2021-34473 updated by NVD
- CVE-2020-17496unknownvBulletin PHP Module Remote Code Execution Vulnerability
- CVE-2019-0604unknownMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2020-17530unknownApache Struts Remote Code Execution Vulnerability
- CVE-2019-0708unknownMicrosoft Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2019-0797unknownMicrosoft Win32k Privilege Escalation Vulnerability
- CVE-2019-0803unknownMicrosoft Win32k Privilege Escalation Vulnerability
- CVE-2019-0808unknownMicrosoft Win32k Privilege Escalation Vulnerability
- CVE-2019-0859unknownMicrosoft Win32k Privilege Escalation Vulnerability
- CVE-2020-24557unknownTrend Micro Multiple Products Improper Access Control Vulnerability
- CVE-2019-0863unknownMicrosoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
- CVE-2020-25213unknownWordPress File Manager Plugin Remote Code Execution Vulnerability
- CVE-2020-25506unknownD-Link DNS-320 Device Command Injection Vulnerability
- CVE-2020-2555unknownOracle Multiple Products Remote Code Execution Vulnerability
- CVE-2020-26919unknownNetgear JGS516PE Devices Missing Function Level Access Control Vulnerability
- CVE-2021-34523criticalCVE-2021-34523 updated by NVD
- CVE-2021-34527highCVE-2021-34527 updated by NVD
- CVE-2020-27930unknownApple Multiple Products Memory Corruption Vulnerability
- CVE-2020-27932unknownApple Multiple Products Type Confusion Vulnerability
- CVE-2020-27950unknownApple Multiple Products Memory Initialization Vulnerability
- CVE-2020-29557unknownD-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
- CVE-2020-29583unknownZyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
- CVE-2020-3118unknownCisco IOS XR Software Discovery Protocol Format String Vulnerability
- CVE-2020-3161unknownCisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
- CVE-2021-35211unknownSolarWinds Serv-U Remote Code Execution Vulnerability
- CVE-2021-35395unknownRealtek AP-Router SDK Buffer Overflow Vulnerability
- CVE-2021-35464unknownForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability
- CVE-2021-36741unknownTrend Micro Multiple Products Improper Input Validation Vulnerability
- CVE-2021-36742unknownTrend Micro Multiple Products Improper Input Validation Vulnerability
- CVE-2021-36942highCVE-2021-36942 updated by NVD
- CVE-2019-11510unknownIvanti Pulse Connect Secure Arbitrary File Read Vulnerability
- CVE-2019-11539unknownIvanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
- CVE-2019-11580unknownAtlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability
- CVE-2021-36948highCVE-2021-36948 updated by NVD
- CVE-2019-11634criticalCVE-2019-11634 updated by NVD
- CVE-2019-1214unknownMicrosoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability
- CVE-2021-36955highCVE-2021-36955 updated by NVD
- CVE-2019-1215unknownMicrosoft Windows Privilege Escalation Vulnerability
- CVE-2020-3452highCVE-2020-3452 updated by NVD
- CVE-2019-3396unknownAtlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability
- CVE-2019-3398unknownAtlassian Confluence Server and Data Center Path Traversal Vulnerability
- CVE-2021-37973unknownGoogle Chromium Portals Use-After-Free Vulnerability
- CVE-2021-37975unknownGoogle Chromium V8 Use-After-Free Vulnerability
- CVE-2021-37976unknownGoogle Chromium Information Disclosure Vulnerability
- CVE-2021-38000unknownGoogle Chromium Intents Improper Input Validation Vulnerability
- CVE-2021-38003unknownGoogle Chromium V8 Memory Corruption Vulnerability
- CVE-2020-3566unknownCisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
- CVE-2020-3569unknownCisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
- CVE-2019-4716unknownIBM Planning Analytics Remote Code Execution Vulnerability
- CVE-2019-5544unknownVMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
- CVE-2020-3580mediumCVE-2020-3580 updated by NVD
- CVE-2019-5591mediumCVE-2019-5591 updated by NVD
- CVE-2019-6223unknownApple iOS and macOS Group Facetime Vulnerability
- CVE-2021-38645highCVE-2021-38645 updated by NVD
- CVE-2021-38647criticalCVE-2021-38647 updated by NVD
- CVE-2021-38648highCVE-2021-38648 updated by NVD
- CVE-2021-38649highCVE-2021-38649 updated by NVD
- CVE-2019-7481highCVE-2019-7481 updated by NVD
- CVE-2019-8394unknownZoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
- CVE-2020-3950unknownVMware Multiple Products Privilege Escalation Vulnerability
- CVE-2020-3952unknownVMware vCenter Server Information Disclosure Vulnerability
- CVE-2020-3992criticalCVE-2020-3992 updated by NVD
- CVE-2020-4006unknownMultiple VMware Products Command Injection Vulnerability
- CVE-2020-4427unknownIBM Data Risk Manager Security Bypass Vulnerability
- CVE-2021-40444highCVE-2021-40444 updated by NVD
- CVE-2020-4428unknownIBM Data Risk Manager Remote Code Execution Vulnerability
- CVE-2020-4430unknownIBM Data Risk Manager Directory Traversal Vulnerability
- CVE-2021-40539unknownZoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
- CVE-2020-5735unknownAmcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
- CVE-2020-5847unknownUnraid Remote Code Execution Vulnerability
- CVE-2020-5849unknownUnraid Authentication Bypass Vulnerability
- CVE-2020-5902unknownF5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
- CVE-2020-6207unknownSAP Solution Manager Missing Authentication for Critical Function Vulnerability
- CVE-2020-6287unknownSAP NetWeaver Missing Authentication for Critical Function Vulnerability
- CVE-2020-6418unknownGoogle Chromium V8 Type Confusion Vulnerability
- CVE-2020-6819unknownMozilla Firefox And Thunderbird Use-After-Free Vulnerability
- CVE-2020-6820unknownMozilla Firefox And Thunderbird Use-After-Free Vulnerability
- CVE-2019-9082unknownThinkPHP Remote Code Execution Vulnerability
- CVE-2021-41773unknownApache HTTP Server Path Traversal Vulnerability
- CVE-2021-42013unknownApache HTTP Server Path Traversal Vulnerability
- CVE-2021-42258unknownBQE BillQuick Web Suite SQL Injection Vulnerability
- CVE-2020-7961unknownLiferay Portal Deserialization of Untrusted Data Vulnerability
- CVE-2020-8193unknownCitrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
- CVE-2020-8195unknownCitrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
- CVE-2020-8196unknownCitrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
- CVE-2020-8243unknownIvanti Pulse Connect Secure Code Execution Vulnerability
- CVE-2020-8260unknownIvanti Pulse Connect Secure Code Execution Vulnerability
- CVE-2020-8467unknownTrend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
- CVE-2020-8468unknownTrend Micro Multiple Products Content Validation Escape Vulnerability
- CVE-2020-8515unknownMultiple DrayTek Vigor Routers Web Management Page Vulnerability
- CVE-2020-8599unknownTrend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
- CVE-2020-8644unknownPlaySMS Server-Side Template Injection Vulnerability
- CVE-2020-8655unknownEyesOfNetwork Improper Privilege Management Vulnerability
- CVE-2020-8657unknownEyesOfNetwork Use of Hard-Coded Credentials Vulnerability
- CVE-2020-9818unknownApple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability
- CVE-2020-9819unknownApple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
- CVE-2020-9859unknownApple Multiple Products Code Execution Vulnerability
- CVE-2019-9978unknownWordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
- CVE-2021-1497unknownCisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability
- CVE-2021-1498unknownCisco HyperFlex HX Data Platform Command Injection Vulnerability
- CVE-2020-0041unknownAndroid Kernel Out-of-Bounds Write Vulnerability
- CVE-2020-0069unknownMediatek Multiple Chipsets Insufficient Input Validation Vulnerability
- CVE-2020-0601unknownMicrosoft Windows CryptoAPI Spoofing Vulnerability
- CVE-2021-1647unknownMicrosoft Defender Remote Code Execution Vulnerability
- CVE-2021-1675highCVE-2021-1675 updated by NVD
- CVE-2021-1732highCVE-2021-1732 updated by NVD
- CVE-2021-1782unknownApple Multiple Products Race Condition Vulnerability
- CVE-2021-1870unknownApple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
- CVE-2021-1871unknownApple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability
- CVE-2021-1905unknownQualcomm Multiple Chipsets Use-After-Free Vulnerability
- CVE-2015-1641unknownMicrosoft Office Memory Corruption Vulnerability
- CVE-2017-7269unknownMicrosoft Windows Server Buffer Overflow Vulnerability
- CVE-2016-4437unknownApache Shiro Code Execution Vulnerability
- CVE-2017-0143unknownMicrosoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
- CVE-2018-0798unknownMicrosoft Office Memory Corruption Vulnerability
- CVE-2018-0802unknownMicrosoft Office Memory Corruption Vulnerability
- CVE-2018-13379unknownFortinet FortiOS SSL VPN Path Traversal Vulnerability
- CVE-2017-0199unknownMicrosoft Office and WordPad Remote Code Execution Vulnerability
- CVE-2012-3152unknownOracle Fusion Middleware Unspecified Vulnerability
- CVE-2018-20062unknownThinkPHP "noneCms" Remote Code Execution Vulnerability
- CVE-2018-11776unknownApache Struts Remote Code Execution Vulnerability
- CVE-2016-0167unknownMicrosoft Win32k Privilege Escalation Vulnerability
- CVE-2018-18325unknownDotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
- CVE-2015-4852unknownOracle WebLogic Server Deserialization of Untrusted Data Vulnerability
- CVE-2018-2380unknownSAP Customer Relationship Management (CRM) Path Traversal Vulnerability
- CVE-2018-14558unknownTenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
- CVE-2018-0171unknownCisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
- CVE-2010-5326unknownSAP NetWeaver Remote Code Execution Vulnerability
- CVE-2018-0296highCVE-2018-0296 updated by NVD
- CVE-2017-11774unknownMicrosoft Office Outlook Security Feature Bypass Vulnerability
- CVE-2017-16651unknownRoundcube Webmail File Disclosure Vulnerability
- CVE-2017-11882unknownMicrosoft Office Memory Corruption Vulnerability
- CVE-2017-6327unknownSymantec Messaging Gateway Remote Code Execution Vulnerability
- CVE-2016-0185unknownMicrosoft Windows Media Center Remote Code Execution Vulnerability
- CVE-2017-9822unknownDotNetNuke (DNN) Remote Code Execution Vulnerability
- CVE-2016-3976unknownSAP NetWeaver Directory Traversal Vulnerability
- CVE-2016-3718unknownImageMagick Server-Side Request Forgery (SSRF) Vulnerability
- CVE-2017-5638unknownApache Struts Remote Code Execution Vulnerability
- CVE-2016-3715unknownImageMagick Arbitrary File Deletion Vulnerability
- CVE-2016-9563unknownSAP NetWeaver XML External Entity (XXE) Vulnerability
- CVE-2016-3643unknownSolarWinds Virtualization Manager Privilege Escalation Vulnerability
- CVE-2017-9805unknownApache Struts Deserialization of Untrusted Data Vulnerability
- CVE-2012-0158unknownMicrosoft MSCOMCTL.OCX Remote Code Execution Vulnerability
- CVE-2016-7255highCVE-2016-7255 updated by NVD
- CVE-2016-3235unknownMicrosoft Office OLE DLL Side Loading Vulnerability
- CVE-2017-9248unknownProgress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
- CVE-2017-8759unknownMicrosoft .NET Framework Remote Code Execution Vulnerability
- CVE-2014-1812unknownMicrosoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
- CVE-2018-15811unknownDotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
- CVE-2018-15961unknownAdobe ColdFusion Unrestricted File Upload Vulnerability
- CVE-2020-13935highCVE-2020-13935 updated by NVD
- CVE-2024-56325criticalApache Pinot Vulnerable to Authentication Bypass
- CVE-2020-9484highCVE-2020-9484 updated by NVD
- CVE-2026-53435highCVE-2026-53435 updated by NVD
- CVE-2019-19576criticalRemote code execution in verot/class.upload.php
- CVE-2024-7959highWithdrawn Advisory: Open WebUI has SSRF in /openai/models
- CVE-2021-25122highCVE-2021-25122 updated by NVD
- CVE-2024-21626highCVE-2024-21626 updated by NVD
- CVE-2025-61686criticalReact Router has Path Traversal in File Session Storage
- CVE-2015-3221mediumOpenStack Neutron Improper Input Validation vulnerability
- CVE-2026-34040highMoby has AuthZ plugin bypass when provided oversized request bodies
- CVE-2024-11392highDeserialization of Untrusted Data in Hugging Face Transformers
- CVE-2026-38360criticaldash-uploader has a directory traversal vulnerability
- CVE-2020-16845highWithdrawn Advisory: Infinite loop in xz
- CVE-2020-7624criticalWithdrawn Advisory: OS Command Injection in effect
- CVE-2019-19634criticalclass.upload.php in verot.net omits .pht from the set of dangerous file extensions
- CVE-2026-18963criticalCVE-2026-18963 updated by NVD
- CVE-2026-59865criticalCVE-2026-59865 updated by NVD
- CVE-2020-36326criticalObject injection in PHPMailer/PHPMailer
- CVE-2024-11393highDeserialization of Untrusted Data in Hugging Face Transformers
- CVE-2026-31843criticalCVE-2026-31843 updated by NVD
- CVE-2026-56265criticalCrawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API ser
- CVE-2020-36939highCassandra Web - Remote File Read
- CVE-2024-7034mediumWithdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
- CVE-2024-11394highDeserialization of Untrusted Data in Hugging Face Transformers
- CVE-2026-40047criticalApache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path trav
- CVE-2026-55584highCVE-2026-55584 updated by NVD
- CVE-2018-1000164highGunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
- CVE-2025-59340criticaljinjava has Sandbox Bypass via JavaType-Based Deserialization
- CVE-2024-7387criticalCVE-2024-7387 updated by NVD
- CVE-2024-43202criticalApache Dolphinscheduler Code Injection vulnerability
- CVE-2026-59867highCVE-2026-59867 updated by NVD
- CVE-2026-67325highCVE-2026-67325 updated by NVD
- CVE-2024-38821criticalSpring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
- CVE-2026-66066criticalCVE-2026-66066 updated by NVD
- CVE-2026-33264criticalApache Airflow allows code execution through unsafe serialized DAG deserialization
- CVE-2026-41293criticalApache Tomcat - HTTP/2 request headers not validated
- CVE-2026-32203highMicrosoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
- CVE-2026-61459criticalmcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
- CVE-2023-39533highCVE-2023-39533 updated by NVD
- CVE-2026-73851mediumCVE-2026-73851 updated by NVD
- CVE-2026-59861highCVE-2026-59861 updated by NVD
- CVE-2022-23327highDenial of Service in Go-Ethereum
- CVE-2026-59866criticalCVE-2026-59866 updated by NVD
- CVE-2024-11958criticalLlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
- CVE-2026-28672criticalCVE-2026-28672 updated by NVD
- CVE-2026-44939criticalRancher vulnerable to command injection through unsanitized YAML parameter
- CVE-2026-59864criticalCVE-2026-59864 updated by NVD
- CVE-2026-40860criticalCVE-2026-40860 updated by NVD
- CVE-2026-79657criticalCVE-2026-79657 updated by NVD
- CVE-2026-2332highCVE-2026-2332 updated by NVD
- CVE-2021-34532mediumCVE-2021-34532 updated by NVD
- CVE-2026-48746criticalCVE-2026-48746 updated by NVD
- CVE-2026-62898highCVE-2026-62898 updated by NVD
- CVE-2024-7033mediumWithdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
- CVE-2026-59863highCVE-2026-59863 updated by NVD
- CVE-2023-1370highjson-smart Uncontrolled Recursion vulnerability
- CVE-2026-69084criticalCVE-2026-69084 updated by NVD
- CVE-2026-52815mediumGogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
- CVE-2024-11831mediumCVE-2024-11831 updated by NVD
- CVE-2026-62901highCVE-2026-62901 updated by NVD
- CVE-2025-9566highCVE-2025-9566 updated by NVD
- CVE-2026-75604criticalCVE-2026-75604 updated by NVD
- CVE-2026-55175highCVE-2026-55175 updated by NVD
- CVE-2026-53598highPrompty: Arbitrary file read via file reference expansion
- CVE-2026-11572highCVE-2026-11572 updated by NVD
- CVE-2026-67323highCVE-2026-67323 updated by NVD
- CVE-2024-42467criticalCVE-2024-42467 updated by NVD
- CVE-2026-22244highCVE-2026-22244 updated by NVD
- CVE-2026-52806criticalGogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
- CVE-2026-59862highCVE-2026-59862 updated by NVD
- CVE-2026-12773mediumLiteLLM: MCP Proxy Has Improper Authentication
- CVE-2026-59859highCVE-2026-59859 updated by NVD
- CVE-2026-59860highCVE-2026-59860 updated by NVD
- CVE-2026-44795highCVE-2026-44795 updated by NVD
- CVE-2023-6484mediumKeycloak vulnerable to log Injection during WebAuthn authentication or registration
- CVE-2026-67438mediumCVE-2026-67438 updated by NVD
- CVE-2026-49297highApache Airflow Google provider allows path traversal through GCS object names
- CVE-2026-43865highApache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables
- CVE-2026-43003highCVE-2026-43003 updated by NVD
- CVE-2026-62815criticalCVE-2026-62815 updated by NVD
- CVE-2026-45140criticalCVE-2026-45140 updated by NVD
- CVE-2026-50646highCVE-2026-50646 updated by NVD
- CVE-2026-84452highCVE-2026-84452 updated by NVD
- CVE-2026-33701criticalCVE-2026-33701 updated by NVD
- CVE-2026-43867criticalApache Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.
- CVE-2024-58351highFlowise OverrideConfig security vulnerability
- CVE-2025-4318criticalCVE-2025-4318 updated by NVD
- CVE-2026-52813criticalGogs has Path Traversal in organization name that results in RCE through Git hooks
- CVE-2026-47429criticalCVE-2026-47429 updated by NVD
- CVE-2026-41523highCVE-2026-41523 updated by NVD
- CVE-2026-54513highCVE-2026-54513 updated by NVD
- CVE-2026-40859highApache Camel-Vertx-Http and Camel-Netty-Http: Unsafe Java deserialization of HTTP response bodies via a raw Ob
- CVE-2026-25119highGogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
- CVE-2026-50633highCVE-2026-50633 updated by NVD
- CVE-2026-55993highApache Camel-Atmosphere-Websocket: The inbound consumer maps externally-supplied WebSocket query parameters in
- CVE-2026-46726highApache Camel-Vertx-Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameter
- CVE-2026-65608highCVE-2026-65608 updated by NVD
- CVE-2026-50527highCVE-2026-50527 updated by NVD
- CVE-2026-46590highApache Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key
- CVE-2026-46454criticalApache Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrateg
- CVE-2023-26051mediumSaleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
- CVE-2026-47302highCVE-2026-47302 updated by NVD
- CVE-2026-54753medium`nx graph` dev server permissive CORS policy
- CVE-2026-42258mediumCVE-2026-42258 updated by NVD
- CVE-2026-69522highCVE-2026-69522 updated by NVD
- CVE-2026-30922highCVE-2026-30922 updated by NVD
- CVE-2026-56170highCVE-2026-56170 updated by NVD
- CVE-2026-12795mediumLiteLLM: SSO Debug Flow Has Improper Authentication
- CVE-2026-40984highCVE-2026-40984 updated by NVD
- CVE-2026-46456criticalApache Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilter
- CVE-2026-40938highCVE-2026-40938 updated by NVD
- CVE-2026-71513highCVE-2026-71513 updated by NVD
- CVE-2026-20896criticalGitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X
- CVE-2026-62902mediumCVE-2026-62902 updated by NVD
- CVE-2026-75827criticalCVE-2026-75827 updated by NVD
- CVE-2026-54569criticalCVE-2026-54569 updated by NVD
- CVE-2026-48020highCVE-2026-48020 updated by NVD
- CVE-2026-49970highLaravel-Mediable: path traversal vulnerability in the File::sanitizePath()
- CVE-2026-65905criticalCVE-2026-65905 updated by NVD
- CVE-2026-69304mediumCVE-2026-69304 updated by NVD
- CVE-2026-40912highTraefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
- CVE-2026-47751mediumClaude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltr
- CVE-2026-56811highPhoenix: Unbounded channel joins per transport enables DoS over few connections
- CVE-2026-55407mediumBuffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
- CVE-2026-48043mediumCVE-2026-48043 updated by NVD
- CVE-2023-26052lowSaleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
- CVE-2026-53913criticalApache Camel: KeycloakSecurityPolicy has Improper Authentication, Missing Authentication for Critical Function
- CVE-2026-8634criticalCrabbox: environment variable exposure vulnerability
- CVE-2026-48006highCVE-2026-48006 updated by NVD
- CVE-2026-69439highCVE-2026-69439 updated by NVD
- CVE-2026-56140criticalApache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy
- CVE-2026-22807highCVE-2026-22807 updated by NVD
- CVE-2026-54718highCVE-2026-54718 updated by NVD
- CVE-2025-29923lowCVE-2025-29923 updated by NVD
- CVE-2026-62899mediumCVE-2026-62899 updated by NVD
- CVE-2026-76218highCVE-2026-76218 updated by NVD
- CVE-2026-5807highHashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
- CVE-2025-71351mediumPicklescan missing detection when calling built-in python library function timeit.timeit()
- CVE-2026-42027criticalCVE-2026-42027 updated by NVD
- CVE-2026-44017highCVE-2026-44017 updated by NVD
- CVE-2026-43868mediumCVE-2026-43868 updated by NVD
- CVE-2026-23490highCVE-2026-23490 updated by NVD
- CVE-2026-61560criticalCVE-2026-61560 updated by NVD
- CVE-2025-66455criticalCVE-2025-66455 updated by NVD
- CVE-2026-67434highCVE-2026-67434 updated by NVD
- CVE-2026-49980criticalCVE-2026-49980 updated by NVD
- CVE-2026-56397mediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
- CVE-2026-88060highCVE-2026-88060 updated by NVD
- CVE-2026-49818mediumCVE-2026-49818 updated by NVD
- CVE-2026-49042highApache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
- CVE-2026-46587highApache Camel-Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation ove
- CVE-2026-46588highApache Camel-CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation overr
- CVE-2026-50628criticalCVE-2026-50628 updated by NVD
- CVE-2026-46455criticalApache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing
- CVE-2026-33646criticalMise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
- CVE-2025-59250highJDBC Driver for SQL Server has improper input validation issue
- CVE-2026-59902highCVE-2026-59902 updated by NVD
- CVE-2026-63126highCVE-2026-63126 updated by NVD
- CVE-2026-55511criticalCVE-2026-55511 updated by NVD
- CVE-2026-27690criticalCVE-2026-27690 updated by NVD
- CVE-2026-49086mediumApache Camel-Dapr: The Dapr Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into produ
- CVE-2026-52816mediumGogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
- CVE-2026-45360highCVE-2026-45360 updated by NVD
- CVE-2025-13590criticalcarbon-apimgt does not properly restrict uploaded files
- CVE-2025-59953criticalCVE-2025-59953 updated by NVD
- CVE-2026-49097mediumApache Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names tha
- CVE-2026-55629highWhistle vulnerable to path traversal
- CVE-2026-42527highApache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based informatio
- CVE-2026-85731highCVE-2026-85731 updated by NVD
- CVE-2026-55207highPimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin
- CVE-2026-55833highCVE-2026-55833 updated by NVD
- CVE-2026-55831highCVE-2026-55831 updated by NVD
- CVE-2026-59880highImmutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
- CVE-2026-49487mediumCVE-2026-49487 updated by NVD
- CVE-2026-48828mediumCVE-2026-48828 updated by NVD
- CVE-2026-48892mediumCVE-2026-48892 updated by NVD
- CVE-2025-54949criticalExecuTorch heap buffer overflow vulnerability
- CVE-2025-54951criticalExecuTorch vulnerable to Heap-based Buffer Overflow
- CVE-2026-44914highApache NiFi: Missing authorization when replacing Process Groups with restricted components
- CVE-2026-46457highApache Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilter
- CVE-2026-57173mediumCVE-2026-57173 updated by NVD
- CVE-2026-61539criticalCVE-2026-61539 updated by NVD
- CVE-2026-43866highApache Camel JMS deserialization filter bypass
- CVE-2026-45018criticalCVE-2026-45018 updated by NVD
- CVE-2024-58368highCVE-2024-58368 updated by NVD
- CVE-2026-26292criticalGitea LFS mirror operations bypass migration HTTP transport protections
- CVE-2024-7039highWithdrawn Advisory: Open WebUI Allows Admin Deletion via API Endpoint
- CVE-2026-9335mediumCVE-2026-9335 updated by NVD
- CVE-2026-44913mediumApache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
- CVE-2026-50632highCVE-2026-50632 updated by NVD
- CVE-2026-73653criticalCVE-2026-73653 updated by NVD
- CVE-2026-56340highvLLM introduced enhanced protection for CVE-2025-62164
- CVE-2026-14257highCVE-2026-14257 updated by NVD
- CVE-2025-53837criticalCVE-2025-53837 updated by NVD
- CVE-2024-45479criticalApache Ranger UI vulnerable to Server Side Request Forgery
- CVE-2026-27780criticalGitea pre-receive hook scanner errors allow branch-protection bypass
- CVE-2024-58362highCVE-2024-58362 updated by NVD
- CVE-2026-48891mediumCVE-2026-48891 updated by NVD
- CVE-2026-68525criticalCVE-2026-68525 updated by NVD
- CVE-2026-40983highCVE-2026-40983 updated by NVD
- CVE-2026-81876highCVE-2026-81876 updated by NVD
- CVE-2026-81875highCVE-2026-81875 updated by NVD
- CVE-2026-15895highjsii-diff: Command Injection via npm: package argument
- CVE-2026-46585highApache Camel-Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that
- CVE-2026-26307highGitea git grep searches allow server resource exhaustion
- CVE-2026-48059highCVE-2026-48059 updated by NVD
- CVE-2026-22864highDeno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
- CVE-2026-53622highCVE-2026-53622 updated by NVD
- CVE-2026-69201mediumCVE-2026-69201 updated by NVD
- CVE-2026-55994highApache Camel-Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange w
- CVE-2026-46592highApache Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operation
- CVE-2026-77360mediumCVE-2026-77360 updated by NVD
- CVE-2026-69152highCVE-2026-69152 updated by NVD
- CVE-2026-11407highPimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
- CVE-2026-88975highCVE-2026-88975 updated by NVD
- CVE-2026-16629mediumCVE-2026-16629 updated by NVD
- CVE-2026-35397highCVE-2026-35397 updated by NVD
- CVE-2026-39830criticalCVE-2026-39830 updated by NVD
- CVE-2026-32274highCVE-2026-32274 updated by NVD
- CVE-2026-11748mediumCentral Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit lo
- CVE-2026-50525highCVE-2026-50525 updated by NVD
- CVE-2026-50648highCVE-2026-50648 updated by NVD
- CVE-2026-73667highCVE-2026-73667 updated by NVD
- CVE-2026-49757criticalAshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
- CVE-2026-55477high3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
- CVE-2026-56346mediumAVideo has Unauthenticated PGP Message Decryption via Public Endpoint
- CVE-2026-55638high9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
- CVE-2026-54348highCVE-2026-54348 updated by NVD
- CVE-2026-13760highaws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
- CVE-2026-82399highCVE-2026-82399 updated by NVD
- CVE-2026-59724highSocket.IO: Engine.IO WebTransport SID DoS
- CVE-2026-56816highCVE-2026-56816 updated by NVD
- CVE-2026-49098mediumApache Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-pref
- CVE-2026-41608highCVE-2026-41608 updated by NVD
- CVE-2026-43871highCVE-2026-43871 updated by NVD
- CVE-2026-42294highCVE-2026-42294 updated by NVD
- CVE-2026-55874highSeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
- CVE-2026-55605medium@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
- CVE-2025-27597highVue I18n Allows Prototype Pollution in `handleFlatJson`
- CVE-2026-44020highCVE-2026-44020 updated by NVD
- CVE-2026-59193mediumGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
- CVE-2026-48203criticalApache Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that b
- CVE-2026-39832criticalCVE-2026-39832 updated by NVD
- CVE-2026-56741highCVE-2026-56741 updated by NVD
- CVE-2026-52887criticalNocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
- CVE-2025-30404criticalExecuTorch integer overflow vulnerability
- CVE-2025-30405criticalExecuTorch integer overflow vulnerability
- CVE-2025-54950criticalExecuTorch out-of-bounds access vulnerability
- CVE-2026-56740highCVE-2026-56740 updated by NVD
- CVE-2026-65182criticalCVE-2026-65182 updated by NVD
- CVE-2026-55469lowSnipe-IT has a path traversal vulnerability via CSV import `image` field
- CVE-2026-54428highCVE-2026-54428 updated by NVD
- CVE-2026-62988criticalCVE-2026-62988 updated by NVD
- CVE-2026-71328highCVE-2026-71328 updated by NVD
- CVE-2026-12243highnltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
- CVE-2026-67422highCVE-2026-67422 updated by NVD
- CVE-2026-71476highCVE-2026-71476 updated by NVD
- CVE-2026-47303highCVE-2026-47303 updated by NVD
- CVE-2026-27779highGitea forwarded-proto validation allows canonical URL spoofing
- CVE-2025-1793criticalllama_index vulnerable to SQL Injection
- CVE-2026-65595highCVE-2026-65595 updated by NVD
- CVE-2026-66907highCVE-2026-66907 updated by NVD
- CVE-2026-69264criticalCVE-2026-69264 updated by NVD
- CVE-2026-53633criticalCVE-2026-53633 updated by NVD
- CVE-2026-82410highCVE-2026-82410 updated by NVD
- CVE-2026-53571highvite: `server.fs.deny` bypass on Windows alternate paths
- CVE-2026-85756highCVE-2026-85756 updated by NVD
- CVE-2026-73415highCVE-2026-73415 updated by NVD
- CVE-2026-49844mediumApache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization
- CVE-2026-56139mediumApache Camel-Undertow: The muteException consumer option defaulted to false, so a processing error returned th
- CVE-2026-49365mediumApache Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned
- CVE-2026-48853criticalgRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
- CVE-2026-76825highCVE-2026-76825 updated by NVD
- CVE-2026-84374highCVE-2026-84374 updated by NVD
- CVE-2026-76220highCVE-2026-76220 updated by NVD
- CVE-2026-12796lowBerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
- CVE-2026-50159mediumCVE-2026-50159 updated by NVD
- CVE-2026-52801highGogs has the ability to import local repositories via Mirror Settings
- CVE-2026-12770lowLiteLLM: Admin Key Handler Has Improper Authorization
- CVE-2026-72695highCVE-2026-72695 updated by NVD
- CVE-2026-55108highCVE-2026-55108 updated by NVD
- CVE-2026-54399highCVE-2026-54399 updated by NVD
- CVE-2026-62384highCVE-2026-62384 updated by NVD