986 items
Unread (2112) All Dismissed
HIGH
CVE-2026-8889 (CVSS 7.5) — Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matchin...
NVD CVE-2026-8889 2d ago
HIGH
CVE-2026-8888 (CVSS 7.5) — Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-pr...
NVD CVE-2026-8888 2d ago
HIGH
CVE-2026-20230 (CVSS 8.6) — A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication...
NVD CVE-2026-20230 +1 2d ago
INFO
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
The Hacker News 1d ago
HIGH
CVE-2022-49042 (CVSS 7.8) — An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in ...
NVD CVE-2022-49042 2d ago
HIGH
CVE-2022-49036 (CVSS 7.8) — An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration i...
NVD CVE-2022-49036 2d ago
HIGH
CVE-2026-35085 (CVSS 8.8) — A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to ga...
NVD CVE-2026-35085 2d ago
HIGH
CVE-2026-35084 (CVSS 8.8) — A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain...
NVD CVE-2026-35084 2d ago
HIGH
CVE-2026-35083 (CVSS 8.8) — A remote attacker with user privileges can exploit a stack buffer overflow to gain full system acces...
NVD CVE-2026-35083 2d ago
HIGH
CVE-2026-35082 (CVSS 8.8) — The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files...
NVD CVE-2026-35082 2d ago
HIGH
CVE-2026-35081 (CVSS 8.1) — The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processe...
NVD CVE-2026-35081 2d ago
HIGH
CVE-2026-35080 (CVSS 8.1) — The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local f...
NVD CVE-2026-35080 2d ago
HIGH
CVE-2026-35079 (CVSS 8.1) — The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files...
NVD CVE-2026-35079 2d ago
HIGH
CVE-2026-35078 (CVSS 8.1) — The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local file...
NVD CVE-2026-35078 2d ago
HIGH
CVE-2026-35077 (CVSS 8.1) — The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local ...
NVD CVE-2026-35077 2d ago
HIGH
CVE-2026-35076 (CVSS 8.1) — The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local fi...
NVD CVE-2026-35076 2d ago
HIGH
CVE-2026-41032 (CVSS 7.5) — It is possible for an unauthenticated adjacent attacker to download log files of the controller, whi...
NVD CVE-2026-41032 2d ago
HIGH
CVE-2026-4035 (CVSS 7.7) — A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment v...
NVD CVE-2026-4035 2d ago
HIGH
CVE-2026-10704 (CVSS 7.3) — A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulne...
NVD CVE-2026-10704 2d ago
HIGH
CVE-2026-10694 (CVSS 7.3) — A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this iss...
NVD CVE-2026-10694 2d ago
HIGH
CVE-2026-44654 (CVSS 8.1) — LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and in...
NVD CVE-2026-44654 3d ago
HIGH
CVE-2026-10620 (CVSS 7.3) — A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function...
NVD CVE-2026-10620 3d ago
HIGH
CVE-2026-10619 (CVSS 7.3) — A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93...
NVD CVE-2026-10619 3d ago
HIGH
CVE-2026-8036 (CVSS 7.1) — Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system ...
NVD CVE-2026-8036 3d ago
HIGH
CVE-2026-5073 (CVSS 7.5) — The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter o...
NVD CVE-2026-5073 3d ago
HIGH
CVE-2026-49120 (CVSS 8.5) — Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worke...
NVD CVE-2026-49120 3d ago
HIGH
CVE-2026-47265 (CVSS 7.5) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.1...
NVD CVE-2026-47265 3d ago
HIGH
CVE-2026-41577 (CVSS 7.5) — authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML so...
NVD CVE-2026-41577 3d ago
HIGH
CVE-2026-28299 (CVSS 8.2) — SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when ex...
NVD CVE-2026-28299 3d ago
HIGH
CVE-2026-1829 (CVSS 8.8) — The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution ...
NVD CVE-2026-1829 3d ago
HIGH
CVE-2026-10617 (CVSS 7.3) — A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the...
NVD CVE-2026-10617 3d ago
HIGH
CVE-2026-30652 (CVSS 8.8) — A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin i...
NVD CVE-2026-30652 3d ago
HIGH
CVE-2026-7195 (CVSS 8.8) — CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4...
NVD CVE-2026-7195 3d ago
HIGH
CVE-2026-5422 (CVSS 8.1) — A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root dire...
NVD CVE-2026-5422 3d ago
HIGH
CVE-2026-24782 (CVSS 7.6) — Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilit...
NVD CVE-2026-24782 4d ago
HIGH
CVE-2025-32348 (CVSS 7.8) — In multiple locations, there is a possible background activity launch due to a missing permission ch...
NVD CVE-2025-32348 4d ago
HIGH
CVE-2025-22424 (CVSS 7.8) — In multiple locations, there is a possible way to reveal images across users due to improper input v...
NVD CVE-2025-22424 4d ago
HIGH
CVE-2026-9330 (CVSS 8.5) — IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied...
NVD CVE-2026-9330 4d ago
HIGH
CVE-2026-47294 (CVSS 8) — Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex...
NVD CVE-2026-47294 4d ago
HIGH
CVE-2026-0072 (CVSS 7.8) — In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a mi...
NVD CVE-2026-0072 4d ago
HIGH
CVE-2026-10270 (CVSS 8.8) — A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprin...
NVD CVE-2026-10270 4d ago
HIGH
CVE-2026-10263 (CVSS 7.3) — A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affect...
NVD CVE-2026-10263 4d ago
HIGH
CVE-2026-10262 (CVSS 7.3) — A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown fun...
NVD CVE-2026-10262 4d ago
HIGH
CVE-2026-10261 (CVSS 7.3) — A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the fi...
NVD CVE-2026-10261 4d ago
HIGH
CVE-2026-10260 (CVSS 7.3) — A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown ...
NVD CVE-2026-10260 4d ago
HIGH
CVE-2026-10259 (CVSS 8.8) — A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is th...
NVD CVE-2026-10259 4d ago
HIGH
CVE-2026-10253 (CVSS 7.3) — A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown...
NVD CVE-2026-10253 4d ago
HIGH
CVE-2026-10252 (CVSS 7.3) — A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affe...
NVD CVE-2026-10252 4d ago
HIGH
CVE-2026-10251 (CVSS 7.3) — A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element ...
NVD CVE-2026-10251 4d ago
HIGH
CVE-2026-10250 (CVSS 7.3) — A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The aff...
NVD CVE-2026-10250 4d ago
HIGH
CVE-2026-10249 (CVSS 7.3) — A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is ...
NVD CVE-2026-10249 4d ago
TL;DR
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vu…
CVE-2026-20230
Read full story ↗