synced 8 MIN AGO
01 Record index

CVE records

398,838 records indexed · sorted by most recently published

Reset

02 Records

CVE IDCVSSEPSSSeverityEXPLOITSummaryVendor / ProductPublished
CVE-2026-1012045.3—Medium—5.3—Medium—FastStone Image Viewer TGA Image FSViewer.exe out-of-boundsfaststone image viewer29 MIN AGO
CVE-2024-420028.6—High—8.6—High—Unsafe use of eval() method in ros2 topic hz toolopen source robotics foundation robot operating system 2 (ros 2)36 MIN AGO
CVE-2026-1012035.3—Medium—5.3—Medium—FastStone Image Viewer 1bpp RLE Decoder out-of-bounds writefaststone image viewer44 MIN AGO
CVE-2026-1022817.5—High—7.5—High—Nest: Remote process termination via a deeply nested microservice message patternnestjs nest53 MIN AGO
CVE-2026-1012025.3—Medium—5.3—Medium—FastStone Image Viewer TGA Image out-of-bounds writefaststone image viewer59 MIN AGO
CVE-2026-1011886.9—Medium—6.9—Medium—Netcore POWER13 ubus routerd.passwd_set password recoverynetcore power131 HR AGO
CVE-2026-1022793.1—Low—3.1—Low—Laravel: XSS in Debug Page Informationlaravel framework1 HR AGO
CVE-2026-1022787.5—High—7.5—High—brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustionjuliangruber brace-expansion1 HR AGO
CVE-2026-970273.6—Low—3.6—Low—Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service filesred hat red hat enterprise linux 10 red hat red hat enterprise linux 7 red hat red hat enterprise linux 8 red hat red hat enterprise linux 91 HR AGO
CVE-2026-970263.9—Low—3.9—Low—Flatpak: flatpak: world-writable temporary child repositories in system-helper cache pathred hat red hat enterprise linux 10 red hat red hat enterprise linux 7 red hat red hat enterprise linux 8 red hat red hat enterprise linux 91 HR AGO
CVE-2026-970253.2—Low—3.2—Low—Flatpak: flatpak: world-readable oci authentication token in system-helper cache pathred hat red hat enterprise linux 10 red hat red hat enterprise linux 7 red hat red hat enterprise linux 8 red hat red hat enterprise linux 91 HR AGO
CVE-2026-1022775.3—Medium—5.3—Medium—brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of servicejuliangruber brace-expansion1 HR AGO
CVE-2026-1022767.5—High—7.5—High—brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustionjuliangruber brace-expansion1 HR AGO
CVE-2026-1022655.3—Medium—5.3—Medium—PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token headerjpadilla pyjwt1 HR AGO
CVE-2026-1020065.5—Medium—5.5—Medium—VxWorks 7 Memory allocationwind river systems inc vxworks 71 HR AGO
CVE-2026-1022756.5—Medium—6.5—Medium—PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusionjpadilla pyjwt1 HR AGO
CVE-2026-1011879.4—Critical—9.4—Critical—Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injectionziroom zhome a01011 HR AGO
CVE-2026-91096——Unrated———Unrated—In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks forfacebook proxygen1 HR AGO
CVE-2026-91095——Unrated———Unrated—In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the streamfacebook proxygen1 HR AGO
CVE-2026-84895——Unrated———Unrated—In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies thefacebook proxygen1 HR AGO
CVE-2026-1022745.9—Medium—5.9—Medium—PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Setjpadilla pyjwt1 HR AGO
CVE-2026-1022737.4—High—7.4—High—PyJWT accepts public JWK containers as HMAC secretsjpadilla pyjwt1 HR AGO
CVE-2026-1022727.4—High—7.4—High—PyJWT BOM Bypassjpadilla pyjwt1 HR AGO
CVE-2026-1022717.4—High—7.4—High—PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guardjpadilla pyjwt1 HR AGO
CVE-2026-1011465.3—Medium—5.3—Medium—Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit information disclosureeleveo quality management1 HR AGO
CVE-2026-1022704.4—Medium—4.4—Medium—PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.jpadilla pyjwt1 HR AGO
CVE-2026-1022694.8—Medium—4.8—Medium—PyJWT: Non-canonical signature segments enable raw-token revocation bypassjpadilla pyjwt1 HR AGO
CVE-2026-1022689.1—Critical—9.1—Critical—PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guardjpadilla pyjwt1 HR AGO
CVE-2026-1022677.4—High—7.4—High—PyJWT: PyJWKClient follows redirects when fetching JWKSjpadilla pyjwt1 HR AGO
CVE-2026-1022667.4—High—7.4—High—PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validationjpadilla pyjwt1 HR AGO
CVE-2026-1003927.0—High—7.0—High—InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization)invoiceplane invoiceplane1 HR AGO
CVE-2026-1020055.5—MediumNONE5.5—MediumNONEVxWorks Memory Allocationwind river inc vxworks 71 HR AGO
CVE-2026-1003718.7—High—8.7—High—InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables Primary Administrator Account Takeover via Email Reassignment and Password Recoveryinvoiceplane invoiceplane1 HR AGO
CVE-2026-1011455.3—Medium—5.3—Medium—Eleveo Call Recording Software User Management userAddAction.do ldap injectioneleveo call recording software1 HR AGO
CVE-2026-1019185.3—Medium—5.3—Medium—PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)jpadilla pyjwt2 HR AGO
CVE-2026-1019175.3—MediumPOC5.3—MediumPOCPyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)jpadilla pyjwt2 HR AGO
CVE-2026-1003704.7—MediumPOC4.7—MediumPOCDOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows Base64-Encoded Payloads to Bypass href and xlink:href Validationrhukster dom-sanitizer2 HR AGO
CVE-2026-1019167.4—High—7.4—High—@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorizedgrpc grpc-node2 HR AGO
CVE-2026-1011445.3—Medium—5.3—Medium—Eleveo Call Recording Software Query Builder searchAction.do access controleleveo call recording software2 HR AGO
CVE-2026-184163.7—Low—3.7—Low—Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)zephyrproject zephyr2 HR AGO
CVE-2026-184156.3—Medium—6.3—Medium—Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frameszephyrproject zephyr2 HR AGO
CVE-2026-184147.8—High—7.8—High—Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size validationzephyrproject zephyr2 HR AGO
CVE-2026-184137.8—High—7.8—High—Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer size validationzephyrproject zephyr2 HR AGO
CVE-2026-165137.8—High—7.8—High—Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allows arbitrary kernel writezephyrproject zephyr2 HR AGO
CVE-2026-877418.8—High—8.8—High—ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Parameterbrainstorm force convertplus2 HR AGO
CVE-2026-1019153.7—Low—3.7—Low—@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messagesgrpc grpc-node2 HR AGO
CVE-2026-1020047.8—High—7.8—High—VxWorks 7wind river systems inc vxworks 72 HR AGO
CVE-2026-1011435.3—Medium—5.3—Medium—Eleveo Quality Management QMBODownload information disclosureeleveo quality management2 HR AGO
CVE-2026-96760——Unrated———Unrated—Authlib library contains a signature‑verification bypass vulnerabilityauthlib authlib2 HR AGO
CVE-2026-1019146.5—Medium—6.5—Medium—@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matchesgrpc grpc-node2 HR AGO