Recent
Edimax BR-6428nC Wireless Wizard formWizSurvey stack-based overflow
Published 2026-09-27 by VulDB
Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
Published 2026-09-27 by VulnCheck
Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
Published 2026-09-27 by VulnCheck
Heym before 0.0.53 Multiple RCE and Authentication Bypass Vulnerabilities
Published 2026-09-27 by VulnCheck
heym before 0.0.91 Remote Code Execution via Expression Engine
Published 2026-09-27 by VulnCheck
Heym before 0.0.91 SSRF via image fetching and IPv6 validation
Published 2026-09-27 by VulnCheck
heym before 0.0.91 Multiple Secrets Plaintext Storage
Published 2026-09-27 by VulnCheck
heym before 0.0.105 SSRF via credential-controlled base URLs
Published 2026-09-27 by VulnCheck
heym before 0.0.105 Authentication Bypass via Redis Node
Published 2026-09-27 by VulnCheck
Heym before 0.0.106 Credential Exfiltration via URL Override
Published 2026-09-27 by VulnCheck
heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.6 Code Injection via Remote Relay Password
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.6 Missing Permission Check via /play
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass
Published 2026-09-27 by VulnCheck
AzuraCast through 0.23.x Command Injection via Streamer Username
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL
Published 2026-09-27 by VulnCheck
AzuraCast before 0.23.8 DQL Injection via sortOrder
Published 2026-09-27 by VulnCheck
MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization
Published 2026-09-27 by VulnCheck
MONAI before 1.6.0 Remote Code Execution via NumpyReader
Published 2026-09-27 by VulnCheck
MONAI before 1.6.0 OS Command Injection via dataset_name_or_id
Published 2026-09-27 by VulnCheck
MONAI before 1.6.0 Remote Code Execution via algo_from_pickle
Published 2026-09-27 by VulnCheck
MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains
Published 2026-09-27 by VulnCheck
MONAI 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache
Published 2026-09-27 by VulnCheck
MONAI through 1.6.0 Remote Code Execution via bundle configuration
Published 2026-09-27 by VulnCheck
Contrast before 1.18.0 AML Injection Remote Code Execution
Published 2026-09-27 by VulnCheck
Contrast before 1.19.1 CopyFile Policy Symlink Subversion
Published 2026-09-27 by VulnCheck
Contrast before 1.16.0 Remote Attestation Relay Attack
Published 2026-09-27 by VulnCheck
http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass
Published 2026-09-27 by VulnCheck
Contrast before 1.23.1 Image Substitution via Policy Generation
Published 2026-09-27 by VulnCheck
http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage
Published 2026-09-27 by VulnCheck
http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy
Published 2026-09-27 by VulnCheck
vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool
Published 2026-09-27 by VulnCheck
vm2 before 3.12.2 Host Process Termination via Construct Trap
Published 2026-09-27 by VulnCheck
vm2 before 3.12.2 Authorization Bypass via Custom Resolver
Published 2026-09-27 by VulnCheck
Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
Published 2026-09-27 by VulnCheck
Contrast before 1.8.1 Information Disclosure via Logging
Published 2026-09-27 by VulnCheck
Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount
Published 2026-09-27 by VulnCheck
Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
Published 2026-09-27 by VulnCheck
Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
Published 2026-09-27 by VulnCheck
coollabsio Coolify Route-Level Middleware CanUpdateResource.php authorization
Published 2026-09-27 by VulDB
D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write
Published 2026-09-27 by VulDB
mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
Published 2026-09-26 by VulDB
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Kibana Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-09-26 by elastic
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-09-26 by elastic
Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
Published 2026-09-26 by elastic
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Published 2026-09-26 by elastic
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation
Published 2026-09-26 by elastic
Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field
Published 2026-09-26 by Wordfence
Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode
Published 2026-09-26 by Wordfence
Load more ↓