Tue, May 26 · 02:16 PM CDTCVE-2026-7374
9.9/10 · Must read/watchNVDvuln
Summary
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container r
CVECVE-2026-7374
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 02:16 PM CDT
ModifiedTue, Sep 08 · 05:18 PM CDT
Fri, Dec 19 · 01:16 AM CSTCVE-2025-14733
9.8/10 · Must read/watchNVDvuln
Summary
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was prev
CVECVE-2025-14733
SeverityCRITICAL
TypeUPDATED
PublishedFri, Dec 19 · 01:16 AM CST
ModifiedWed, Sep 09 · 04:17 AM CDT
Wed, Mar 11 · 05:16 PM CDTCVE-2025-67038
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected
CVECVE-2025-67038
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 11 · 05:16 PM CDT
ModifiedTue, Sep 08 · 07:00 PM CDT
Wed, Feb 18 · 05:21 PM CSTCVE-2025-70149
9.8/10 · Must read/watchNVDvuln
Summary
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
CVECVE-2025-70149
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 18 · 05:21 PM CST
ModifiedTue, Sep 08 · 08:17 PM CDT
Wed, Feb 18 · 06:24 PM CSTCVE-2025-70150
9.8/10 · Must read/watchNVDvuln
Summary
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
CVECVE-2025-70150
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 18 · 06:24 PM CST
ModifiedTue, Sep 08 · 08:17 PM CDT
Wed, Feb 18 · 06:24 PM CSTCVE-2025-70152
9.8/10 · Must read/watchNVDvuln
Summary
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password,
CVECVE-2025-70152
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 18 · 06:24 PM CST
ModifiedTue, Sep 08 · 08:17 PM CDT
Tue, Apr 07 · 01:16 PM CDTCVE-2026-28808
9.8/10 · Must read/watchNVDvuln
Summary
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot
CVECVE-2026-28808
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 07 · 01:16 PM CDT
ModifiedTue, Sep 08 · 02:17 PM CDT
Tue, May 26 · 12:16 AM CDTCVE-2026-8376
9.8/10 · Must read/watchNVDvuln
Summary
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. Fo
CVECVE-2026-8376
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 26 · 12:16 AM CDT
ModifiedTue, Sep 08 · 10:19 PM CDT
Wed, Feb 18 · 05:21 PM CSTCVE-2025-70141
9.4/10 · Must read/watchNVDvuln
Summary
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitiv
CVECVE-2025-70141
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 18 · 05:21 PM CST
ModifiedTue, Sep 08 · 08:17 PM CDT
Mon, Jul 20 · 08:16 AM CDTCVE-2026-16242
9.4/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could co
CVECVE-2026-16242
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 20 · 08:16 AM CDT
ModifiedTue, Sep 08 · 08:17 PM CDT
Fri, Jul 10 · 10:16 AM CDTCVE-2026-15378
9.3/10 · Must read/watchNVDvuln
Summary
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from clou
CVECVE-2026-15378
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 10 · 10:16 AM CDT
ModifiedTue, Sep 08 · 10:17 PM CDT
Wed, Feb 18 · 05:21 PM CSTCVE-2025-70146
9.1/10 · Must read/watchNVDvuln
Summary
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.
CVECVE-2025-70146
SeverityCRITICAL
TypeUPDATED
PublishedWed, Feb 18 · 05:21 PM CST
ModifiedTue, Sep 08 · 08:17 PM CDT
Mon, Jul 13 · 05:16 PM CDTCVE-2026-13221
9.1/10 · Must read/watchNVDvuln
Summary
Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the fi
CVECVE-2026-13221
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 13 · 05:16 PM CDT
ModifiedTue, Sep 08 · 10:17 PM CDT
Tue, Jul 14 · 01:16 AM CDTCVE-2026-27690
9.1/10 · Must read/watchNVDvuln
Summary
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confid
CVECVE-2026-27690
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jul 14 · 01:16 AM CDT
ModifiedTue, Sep 08 · 08:22 PM CDT
Tue, Oct 14 · 05:15 PM CDTCVE-2025-54603
9.0/10 · Must read/watchNVDvuln
Summary
An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.
CVECVE-2025-54603
SeverityCRITICAL
TypeUPDATED
PublishedTue, Oct 14 · 05:15 PM CDT
ModifiedTue, Sep 08 · 05:17 PM CDT
Thu, Jan 25 · 09:15 PM CSTCVE-2023-52251
8.8/10 · Worth your timeNVDvuln
Summary
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.
CVECVE-2023-52251
SeverityHIGH
TypeUPDATED
PublishedThu, Jan 25 · 09:15 PM CST
ModifiedTue, Sep 08 · 07:17 PM CDT
Mon, Aug 04 · 07:15 AM CDTCVE-2025-20701
8.8/10 · Worth your timeNVDvuln
Summary
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2025-20701
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 04 · 07:15 AM CDT
ModifiedTue, Sep 08 · 04:17 PM CDT
Wed, Feb 18 · 06:24 PM CSTCVE-2025-70151
8.8/10 · Worth your timeNVDvuln
Summary
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without valida
CVECVE-2025-70151
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 18 · 06:24 PM CST
ModifiedTue, Sep 08 · 08:17 PM CDT
Thu, Jul 30 · 10:16 PM CDTCVE-2026-12562
8.8/10 · Worth your timeNVDvuln
Summary
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allo
CVECVE-2026-12562
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 30 · 10:16 PM CDT
ModifiedTue, Sep 08 · 07:30 PM CDT
Thu, Jul 23 · 11:16 AM CDTCVE-2026-16745
8.8/10 · Worth your timeNVDvuln
Summary
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kuber
CVECVE-2026-16745
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 23 · 11:16 AM CDT
ModifiedTue, Sep 08 · 10:17 PM CDT
Fri, Jul 24 · 07:16 PM CDTCVE-2026-17107
8.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unre
CVECVE-2026-17107
SeverityHIGH
TypeUPDATED
PublishedFri, Jul 24 · 07:16 PM CDT
ModifiedTue, Sep 08 · 01:17 PM CDT
Tue, Jul 28 · 01:18 PM CDTCVE-2026-49332
8.5/10 · Worth your timeNVDvuln
Summary
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated l
CVECVE-2026-49332
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 28 · 01:18 PM CDT
ModifiedTue, Sep 08 · 11:17 AM CDT
Thu, Jul 30 · 10:16 PM CDTCVE-2026-62246
8.5/10 · Worth your timeNVDvuln
Summary
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with collidi
CVECVE-2026-62246
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 30 · 10:16 PM CDT
ModifiedTue, Sep 08 · 08:51 PM CDT
Mon, Mar 02 · 07:16 PM CSTCVE-2026-0008
8.4/10 · Worth your timeNVDvuln
Summary
In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0008
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 02 · 07:16 PM CST
ModifiedTue, Sep 08 · 07:17 PM CDT
Mon, Mar 02 · 07:16 PM CSTCVE-2026-0010
8.4/10 · Worth your timeNVDvuln
Summary
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2026-0010
SeverityHIGH
TypeUPDATED
PublishedMon, Mar 02 · 07:16 PM CST
ModifiedTue, Sep 08 · 07:17 PM CDT