CVE-2026-18897 |
UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-18895 |
UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-46334 |
OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning |
high |
cve |
0 |
0 |
|
|
|
TF-1868565 |
Unknown malware: ip:port combination that delivery a malware payload 46.226.162.241:80 |
high |
Unknown malware |
2 |
0 |
|
|
|
CVE-2026-45809 |
OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-45537 |
OpenSIPS: Global Buffer Overflow in construct_uri |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-45103 |
OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-45100 |
OpenSIPS: Buffer Overflow in Base64 Encode Transformation |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-45084 |
OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70619 |
Odysseus Missing Admin Authorization via Embedding Endpoint Routes |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-18814 |
H3C NX15 esps reload.reload_config command injection |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-18813 |
H3C NX15 esps delete command injection |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70494 |
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-13227 |
ERPNext v16.25.0 - Improper authorization in Prospect opportunities API |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70492 |
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-45538 |
OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-18812 |
H3C NX15 esps esps.ipv6.wan command injection |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-18811 |
H3C NX15 esps add command injection |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-65986 |
CVAT has stored XSS via annotation guide assets |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70554 |
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-70486 |
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-47682 |
CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70485 |
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70482 |
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-16793 |
Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-16792 |
Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70479 |
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-18657 |
Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70553 |
MaxSite CMS Unauthenticated RCE via Install Endpoint |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-70478 |
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-18656 |
Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70477 |
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-70552 |
MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-70476 |
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70475 |
Flowise: Missing Authorization on Execution Update Endpoint |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-49435 |
Keysight IxChariot-related products stack-based buffer overflow |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-69704 |
Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-47781 |
pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-69703 |
Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit |
critical |
cve |
0 |
0 |
|
|
|
CVE-2026-13229 |
Zammad 7.0.1 - Improper authorization in ticket article attachment cloning |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70474 |
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-47764 |
pdm: Path traversal in wheel installation via overridden write_to_fs |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70473 |
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70472 |
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-69702 |
SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70471 |
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-18830 |
Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-47623 |
CVE-2026-47623 |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-47618 |
CVE-2026-47618 |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-47617 |
CVE-2026-47617 |
high |
cve |
0 |
0 |
|
|
|