Filter and search through 392,104 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-24307 | Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 9.3 | 577 | Neutral | No |
| No |
| CVE-2026-24306 | Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. | 9.8 | 639 | Neutral | No | No |
| CVE-2026-24305 | Azure Entra ID Elevation of Privilege Vulnerability | 9.3 | 627 | Neutral | No | No |
| CVE-2026-24304 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 9.9 | 636 | Neutral | No | No |
| CVE-2026-24140 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settin... | 2.7 | 92 | Neutral | No | No |
| CVE-2026-24139 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, all... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24138 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vul... | 7.5 | 394 | Neutral | No | No |
| CVE-2026-24137 | ## Summary The legacy TUF client `pkg/tuf/client.go`, which supports caching target files to disk, constructs a filesystem path by joining a cache ba... | 5.8 | 260 | Neutral | No | Yes |
| CVE-2026-24136 | Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct ... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24132 | I am reporting a code injection vulnerability in Orval’s mock generation pipeline affecting @orval/mock in both the 7.x and 8.x series. This issue is ... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-24130 | ### Impact Instances of Moonraker configured with the `ldap` component enabled are vulnerable to LDAP search filter injection techniques via the logi... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-24129 | Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an a... | 8.0 | 467 | Neutral | No | No |
| CVE-2026-24128 | ### Impact A reflected cross site scripting (XSS) vulnerability in XWiki allows an attacker to execute arbitrary actions in XWiki with the rights of t... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-24127 | Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the lo... | 5.4 | 129 | Neutral | No | No |
| CVE-2026-24124 | ## Summary Dragonfly Manager's Job REST API endpoints lack authentication, allowing unauthenticated attackers to create, query, modify, and delete jo... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-24117 | ## Summary `/api/v1/index/retrieve` supports retrieving a public key via a user-provided URL, allowing attackers to trigger SSRF to arbitrary interna... | 5.3 | 253 | Neutral | No | Yes |
| CVE-2026-24061 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | 9.8 | 690 | Viral | Yes | Yes |
| CVE-2026-24058 | ### Impact _What kind of vulnerability is it? Who is impacted?_ This issue impacts every Soft Serve instance. A critical authentication bypass allow... | 0.0 | 0 | Neutral | No | Yes |
| CVE-2026-24055 | Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates ... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24049 | ### Summary - **Vulnerability Type:** Path Traversal (CWE-22) leading to Arbitrary File Permission Modification. - **Root Cause Component:** wheel... | 7.1 | 427 | Neutral | No | Yes |