Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
29,437 matching · page 407/589Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-1529(opens NVD record) | High | 8.1 | A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access. | Feb 9, 2026 |
| CVE-2026-1486(opens NVD record) | High | 8.8 | A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens. | Feb 9, 2026 |
| CVE-2026-24678(opens NVD record) | High | 7.5 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This vulnerability is fixed in 3.22.0. | Feb 9, 2026 |
| CVE-2026-1615(opens NVD record) | Critical | 9.8 | Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects, including .query, .nodes, .paths, .value, .parent, and .apply. | Feb 9, 2026 |
| CVE-2026-2141(opens NVD record) | Medium | 6.3 | A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | Feb 8, 2026 |
| CVE-2026-25859(opens NVD record) | High | 8.8 | Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations. | Feb 7, 2026 |
| CVE-2026-25858(opens NVD record) | Critical | 9.1 | macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number. | Feb 7, 2026 |
| CVE-2026-25568(opens NVD record) | Medium | 4.3 | WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement. | Feb 7, 2026 |
| CVE-2026-25567(opens NVD record) | Medium | 4.3 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier. | Feb 7, 2026 |
| CVE-2026-25566(opens NVD record) | Medium | 5.4 | WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves. | Feb 7, 2026 |
| CVE-2026-25565(opens NVD record) | Medium | 6.5 | WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access. | Feb 7, 2026 |
| CVE-2026-25564(opens NVD record) | High | 7.5 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers. | Feb 7, 2026 |
| CVE-2026-25563(opens NVD record) | High | 7.5 | WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers. | Feb 7, 2026 |
| CVE-2026-25562(opens NVD record) | Medium | 4.3 | WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users. | Feb 7, 2026 |
| CVE-2026-25561(opens NVD record) | High | 7.5 | WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachments with mismatched object relationships. | Feb 7, 2026 |
| CVE-2026-25560(opens NVD record) | Critical | 9.8 | WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication. | Feb 7, 2026 |
| CVE-2026-1731(opens NVD record) | Critical | 9.8 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user. | Feb 6, 2026 |
| CVE-2026-25580(opens NVD record) | High | 8.6 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include malicious URLs that cause the server to make HTTP requests to internal network resources, potentially accessing internal services or cloud credentials. This vulnerability only affects applications that accept message history from external users. This vulnerability is fixed in 1.56.0. | Feb 6, 2026 |
| CVE-2026-25640(opens NVD record) | High | 7.1 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript in the context of the application by crafting a malicious URL. In affected versions, the CDN URL is constructed using a version query parameter from the request URL. This parameter is not validated, allowing path traversal sequences that cause the server to fetch and serve attacker-controlled HTML/JavaScript from an arbitrary source on the same CDN, instead of the legitimate chat UI package. If a victim clicks the link or visits it via an iframe, attacker-controlled code executes in their browser, enabling theft of chat history and other client-side data. This vulnerability only affects applications that use Agent.to_web to serve a chat interface and clai web to serve a chat interface from the CLI. These are typically run locally (on localhost), but may also be deployed on a remote server. This vulnerability is fixed in 1.51.0. | Feb 6, 2026 |
| CVE-2026-1709(opens NVD record) | Critical | 9.4 | A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate. | Feb 6, 2026 |
| CVE-2026-1769(opens NVD record) | Medium | 5.3 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6. Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com | Feb 6, 2026 |
| CVE-2026-25556(opens NVD record) | High | 7.5 | MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes. | Feb 6, 2026 |
| CVE-2026-24928(opens NVD record) | Medium | 5.8 | Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Feb 6, 2026 |
| CVE-2026-24927(opens NVD record) | Medium | 5.5 | Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24924(opens NVD record) | Medium | 6.1 | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Feb 6, 2026 |
| CVE-2026-24920(opens NVD record) | Medium | 6.2 | Permission control vulnerability in the AMS module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24931(opens NVD record) | Medium | 5.9 | Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Feb 6, 2026 |
| CVE-2026-24930(opens NVD record) | High | 8.4 | UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24929(opens NVD record) | Medium | 5.9 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24926(opens NVD record) | High | 8.4 | Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24925(opens NVD record) | High | 7.3 | Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24923(opens NVD record) | Medium | 6.3 | Permission control vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Feb 6, 2026 |
| CVE-2026-24922(opens NVD record) | Medium | 6.9 | Buffer overflow vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24921(opens NVD record) | Medium | 4.8 | Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | Feb 6, 2026 |
| CVE-2026-24919(opens NVD record) | Medium | 6.0 | Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24918(opens NVD record) | Medium | 6.8 | Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24917(opens NVD record) | Medium | 6.5 | UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-24916(opens NVD record) | Medium | 5.9 | Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Feb 6, 2026 |
| CVE-2026-24915(opens NVD record) | Medium | 6.2 | Out-of-bounds read issue in the media subsystem. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | Feb 6, 2026 |
| CVE-2026-24914(opens NVD record) | Medium | 4.0 | Type confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability. | Feb 6, 2026 |
| CVE-2026-21643(opens NVD record) | Critical | 9.8 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Feb 6, 2026 |
| CVE-2026-24302(opens NVD record) | High | 8.6 | Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | Feb 5, 2026 |
| CVE-2026-24300(opens NVD record) | Critical | 9.8 | Azure Front Door Elevation of Privilege Vulnerability | Feb 5, 2026 |
| CVE-2026-21532(opens NVD record) | High | 8.2 | Azure Function Information Disclosure Vulnerability | Feb 5, 2026 |
| CVE-2026-0391(opens NVD record) | Medium | 6.5 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | Feb 5, 2026 |
| CVE-2025-69619(opens NVD record) | Medium | 5.5 | A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | Feb 5, 2026 |
| CVE-2025-13379(opens NVD record) | High | 8.6 | IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | Feb 5, 2026 |
| CVE-2025-10258(opens NVD record) | Medium | 6.3 | Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information. | Feb 5, 2026 |
| CVE-2025-61732(opens NVD record) | High | 8.6 | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. | Feb 5, 2026 |
| CVE-2026-25536(opens NVD record) | High | 7.1 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0. | Feb 4, 2026 |