226 Total CVEs
225 AI Analyzed
6 CISA KEV
99 Critical
All Vendors
Showing 1-226 of 226 CVEs
CVE-2026-85426
Analyzed
9.8
GitHub moos-ivp

The MOOS-IvP uMemWatch component fails to sanitize MOOS client names, allowing attackers to inject shell metacharacters and execute arbitrary system c...

2026-09-04
CVE-2026-84482
Analyzed
8.8
GitHub AVideo

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to...

2026-09-02
CVE-2026-82856
Analyzed
9.8
GitHub policies

A security bypass in @hulumi/policies versions before 1.3.2 allows unauthenticated attackers to evade IAM condition guardrails via malicious OIDC trus...

2026-08-31
CVE-2026-82815
Analyzed
7.3
GitHub EaseProbe

A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This m...

2026-09-01
CVE-2026-82648
Analyzed
7.1
GitHub AVideo

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses w...

2026-09-04
CVE-2026-82630
Analyzed
7.3
GitHub PowerJob

A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server...

2026-08-31
CVE-2026-82621
Analyzed
7.3
GitHub StudentManagement

A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function Adm...

2026-08-31
CVE-2026-82608
Analyzed
7.4
GitHub Kamailio

A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_av...

2026-08-31
CVE-2026-82543
Analyzed
7.3
GitHub FileCodeBox

A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py...

2026-08-31
CVE-2026-82526
Analyzed
9.8
GitHub R2R

SciPhi-AI R2R contains a stacked SQL injection vulnerability in the vector index creation endpoint, allowing unauthenticated attackers to execute arbi...

2026-09-04
CVE-2026-82473
Analyzed
8.2
GitHub CloudCore

KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudC...

2026-08-30
CVE-2026-82286
Analyzed
8.6
GitHub gpt-crawler

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbi...

2026-08-29
CVE-2026-82284
Analyzed
8.1
GitHub Quivr

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/qu...

2026-08-29
CVE-2026-82282
Analyzed
8
GitHub atlantis

Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Att...

2026-08-30
CVE-2026-78161
Analyzed
7.3
GitHub libwebsockets

A vulnerability was found in warmcat libwebsockets 4

2026-08-24
CVE-2026-78156
Analyzed
7.4
GitHub Open5GS

A security vulnerability has been detected in Open5GS 2

2026-08-24
CVE-2026-78154
Analyzed
7.3
GitHub open-wearables

A vulnerability was identified in the-momentum open-wearables up to 0

2026-08-24
CVE-2026-77945
Analyzed
7.4
GitHub TEW-821DAP

A vulnerability was found in TRENDnet TEW-821DAP 2

2026-08-23
CVE-2026-7679
Analyzed
7.3
GitHub yudao-cloud

A security flaw has been discovered in YunaiV yudao-cloud up to 2026

2026-05-04
CVE-2026-76639
Analyzed
8.8
GitHub G1 EDU

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execut...

2026-08-28
CVE-2026-76590
Analyzed
9.9
GitHub TEW-755AP

The TRENDnet TEW-755AP file /cgi-bin/wan.cgi is vulnerable to a stack-based buffer overflow via the cameo.wan.wan_pppoe_password_00 argument, allowing...

2026-08-20
CVE-2026-76589
Analyzed
9.9
GitHub TEW-755AP

The TRENDnet TEW-755AP file /sbin/mycli contains a stack-based buffer overflow vulnerability in the function FUN_401000, which can be triggered remote...

2026-08-20
CVE-2026-76584
Analyzed
9.9
GitHub TV-IP751WIC

A stack-based buffer overflow vulnerability in the TRENDnet TV-IP751WIC camera allows remote attackers to execute arbitrary code via the Currenttime a...

2026-08-20
CVE-2026-76070
Analyzed
9.8
GitHub NC63

Netis NC63 firmware is vulnerable to a stack-based buffer overflow via the login handler, allowing unauthenticated remote attackers to achieve remote...

2026-08-25
CVE-2026-76008
Analyzed
10
GitHub CF-N1-S

A stack-based buffer overflow in the Comfast CF-N1-S URI parameter parsing component allows remote, unauthenticated attackers to execute arbitrary cod...

2026-08-19
CVE-2026-76004
Analyzed
9.9
GitHub HiPER 1250GW

The UTT HiPER 1250GW router contains a stack-based buffer overflow in the /goform/aspApBasicConfigUrcp component, reachable via the pvid argument, all...

2026-08-19
CVE-2026-76003
Analyzed
9.9
GitHub HiPER 1200GW

The UTT HiPER 1200GW router contains a stack-based buffer overflow vulnerability in the strcpy function, reachable via the timestart argument in /gofo...

2026-08-19
CVE-2026-75976
Analyzed
9.9
GitHub TEW-823DRU

A stack-based buffer overflow exists in the TRENDnet TEW-823DRU router due to improper input validation in the wan_l2tp_password argument within the w...

2026-08-19
CVE-2026-75877
Analyzed
9.9
GitHub TV-IP751WIC

The TRENDnet TV-IP751WIC contains a stack-based buffer overflow vulnerability in the alphapd component that can be triggered remotely by an authentica...

2026-08-19
CVE-2026-75784
Analyzed
10
GitHub TEW-WLC100

A stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote unauthenticated attackers to execute arbitrary code.

2026-08-19
CVE-2026-75094
Analyzed
9.1
GitHub CF-N1-S

A critical OS command injection vulnerability exists in the COMFAST CF-N1-S CGI interface, allowing authenticated attackers to execute arbitrary syste...

2026-08-18
CVE-2026-74843
Analyzed
10
GitHub WN531P3, WN535M1

A stack-based buffer overflow in the Wavlink Export Pingortrace CGI function allows unauthenticated remote attackers to execute arbitrary code via a m...

2026-08-18
CVE-2026-73673
Analyzed
8.8
GitHub Netis NC63 Wireless AC1200 Router

Netis NC63 router firmware V3

2026-08-15
CVE-2026-72584
Analyzed
7.4
GitHub Fastschema

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0

2026-08-11
CVE-2026-72582
Analyzed
7.5
GitHub Fastschema

A NULL pointer dereference vulnerability in fastschema through v0

2026-08-11
CVE-2026-72581
Analyzed
8.6
GitHub xiaoai-patch

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart spea...

2026-08-11
CVE-2026-72573
Analyzed
8.8
GitHub pm2panel

An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on...

2026-08-11
CVE-2026-72572
Analyzed
7.5
GitHub xmysql

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the...

2026-08-11
CVE-2026-72565
Analyzed
9.8
GitHub APIJSON

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass access controls and read database con...

2026-08-11
CVE-2026-71518
Analyzed
7.5
GitHub Typemill

Typemill before 2

2026-08-18
CVE-2026-71259
Analyzed
8.6
GitHub esphome

ESPHome through 2026

2026-08-06
CVE-2026-71256
Analyzed
9.8
GitHub nanoMODBUS

nanoMODBUS contains an out-of-bounds stack read and wild-pointer write vulnerability in its Modbus identification response handling, which can be trig...

2026-08-06
CVE-2026-69703
Analyzed
9.8
GitHub Atals-Livre

Atals-Livre contains an improper access control vulnerability in admin controllers that allows unauthenticated attackers to bypass authentication and...

2026-08-05
CVE-2026-6924
Analyzed
8.7
GitHub Silicon Labs Matter Github

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed

2026-07-24
CVE-2026-69118
Analyzed
8.8
GitHub Cachet

Cachet through 2

2026-08-11
CVE-2026-68005
Analyzed
7.5
GitHub mini_httpd

An issue in ACME mini_httpd 1

2026-08-18
CVE-2026-67975
Analyzed
7.5
GitHub cFS (Core Flight System)

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/...

2026-08-12
CVE-2026-67974
Analyzed
7.5
GitHub cFS (Core Flight System)

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause...

2026-08-27
CVE-2026-67973
Analyzed
7.5
GitHub cFS

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

2026-08-27
CVE-2026-67919
Analyzed
9.8
GitHub Halo

A remote code execution vulnerability in Halo 2.25.4 exists due to insecure handling of plugin artifacts and insufficient validation of external plugi...

2026-08-26
CVE-2026-67917
Analyzed
9.8
GitHub ZuraCast

A SQL injection vulnerability in ZuraCast allows unauthenticated, remote attackers to execute arbitrary SQL statements during the backup restoration p...

2026-08-27
CVE-2026-67868
Analyzed
9.8
GitHub S2OPC

A heap-based out-of-bounds write in S2OPC 1.7.3 during EventFilter handling allows remote, unauthenticated attackers to execute arbitrary code.

2026-08-26
CVE-2026-67687
Analyzed
8.8
GitHub Smart Park Management System

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleControl...

2026-08-27
CVE-2026-67678
Analyzed
9.8
GitHub DocSys

A critical file upload vulnerability in RainyGao-GitHub DocSys v.2.02.80 allows remote, unauthenticated attackers to execute arbitrary code on the hos...

2026-08-25
CVE-2026-67620
Analyzed
7.7
GitHub Flowise

Flowise through 3

2026-08-09
CVE-2026-67352
Analyzed
7.6
GitHub LuCI

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject...

2026-08-02
CVE-2026-67308
Analyzed
10
GitHub Wazuh

Wazuh workflows contain a shell injection vulnerability in GitHub Actions, allowing attackers to execute arbitrary commands via crafted VERSION.json f...

2026-08-02
CVE-2026-66748
Analyzed
8.8
GitHub camaleon-cms

Camaleon CMS versions 2

2026-07-29
CVE-2026-66731
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66730
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66729
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66373
Analyzed
7.5
GitHub Redis

Redis before 8

2026-07-26
CVE-2026-65643
Analyzed
8.7
GitHub cPanel

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

2026-09-01
CVE-2026-65604
Analyzed
8.2
GitHub Skipper

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies

2026-07-25
CVE-2026-65423
Analyzed
8.8
GitHub open62541

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write

2026-07-31
CVE-2026-63361
Analyzed
8.5
GitHub LimeSurvey

LimeSurvey Community Edition 7

2026-08-15
CVE-2026-63304
Analyzed
8.1
GitHub AVideo

AVideo through 29

2026-07-17
CVE-2026-62675
Analyzed
8.8
GitHub omnigent

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

2026-08-22
CVE-2026-61876
Analyzed
8.8
GitHub LuCI

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML mar...

2026-07-14
CVE-2026-61556
Analyzed
8.7
GitHub LiquidJS

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-08-21
CVE-2026-60004
KEV Analyzed
9.5
GitHub Gitea

A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.

2026-08-26
CVE-2026-58586
Analyzed
9.8
GitHub Image::WebP

The Perl module Image::WebP bundles a vulnerable version of libwebp, which allows remote attackers to trigger heap corruption and potential code execu...

2026-08-02
CVE-2026-58003
Analyzed
7.1
GitHub AVideo

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow

2026-08-23
CVE-2026-57858
Analyzed
8.9
GitHub Cal.com Self-Hosted (Cal.diy)

Cal

2026-08-13
CVE-2026-57074
Analyzed
9.1
GitHub XML::Bare

XML::Bare versions through 0.53 for Perl are susceptible to an out-of-bounds read vulnerability when processing malformed or truncated XML strings.

2026-07-21
CVE-2026-5706
Analyzed
8.9
GitHub BT Mesh SDK

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote cod...

2026-08-28
CVE-2026-56721
Analyzed
8.8
GitHub CamaleonCMS

CamaleonCMS version 2

2026-08-12
CVE-2026-56699
Analyzed
10
GitHub wazuh

Wazuh Manager fails to sanitize input in the DataValue.index field, allowing unauthenticated agents to perform NDJSON injection attacks against the ma...

2026-07-16
CVE-2026-56677
Analyzed
8.6
GitHub 9router

9Router is an AI router & token saver

2026-08-18
CVE-2026-56100
Analyzed
8.1
GitHub SpringBlade

SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrat...

2026-08-29
CVE-2026-55579
Analyzed
9.8
GitHub pheditor

Pheditor versions 2.0.1 through 2.0.5 contain hardcoded credentials that allow unauthenticated attackers to gain full administrative access and execut...

2026-07-28
CVE-2026-55575
Analyzed
8.2
GitHub LiquidJS

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-07-09
CVE-2026-54418
Analyzed
8.1
GitHub Leantime

Leantime through 3

2026-08-05
CVE-2026-53513
Analyzed
9.6
GitHub better-auth

The better-auth SSO plugin fails to validate OIDC configuration URLs, allowing authenticated users to perform server-side request forgery and potentia...

2026-07-16
CVE-2026-53507
Analyzed
8.3
GitHub oasdiff-action

oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the o...

2026-09-01
CVE-2026-52656
Analyzed
9.8
GitHub SJ4000-Air

A critical vulnerability in SJCAM SJ4000-Air cameras allows arbitrary code execution through the processing of maliciously crafted FEX files.

2026-07-27
CVE-2026-52472
Analyzed
9.8
GitHub Wgcloud

A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.

2026-07-31
CVE-2026-52134
Analyzed
9.8
GitHub libiec61850

The libiec61850 library contains an authentication bypass vulnerability in the parseGoosePayload function that allows unauthenticated attackers to man...

2026-08-27
CVE-2026-51977
Analyzed
9.1
GitHub T18061 WiFi 3MP Robot Pan-Tilt Security Camera

A privilege escalation vulnerability in Trueview T18061 WiFi 3MP security cameras allows physically proximate attackers to compromise the device via a...

2026-08-26
CVE-2026-51821
Analyzed
9.8
GitHub Video Conference System

A SQL injection vulnerability in the /user/getUserLogin endpoint of Shenzhou Shihan Video Conference System v.1.0 allows unauthenticated remote attack...

2026-07-17
CVE-2026-51584
Analyzed
9.8
GitHub memos

The usememos application contains an authentication flaw in the SSO handler that allows unauthenticated remote attackers to perform full account takeo...

2026-08-27
CVE-2026-51541
Analyzed
9.1
GitHub OpENer

An out-of-bounds read vulnerability in OpENer 2.3.0 during CIP message parsing allows attackers to crash the service via malformed ENIP SendRRData fra...

2026-07-17
CVE-2026-51538
Analyzed
9.1
GitHub OpENer

OpENer 2.3.0 contains an improper access control vulnerability where the server fails to verify if a session handle belongs to the specific TCP connec...

2026-07-17
CVE-2026-51537
Analyzed
9.1
GitHub OpENer

An out-of-bounds read vulnerability in OpENer 2.3.0 allows unauthenticated attackers to cause a Denial of Service by sending malformed ForwardOpen or...

2026-07-17
CVE-2026-51536
Analyzed
9.1
GitHub OpENer

A stack-based buffer overflow in OpENer 2.3.0 occurs during CIP packet parsing, caused by an integer overflow and truncation when handling length para...

2026-07-17
CVE-2026-51297
Analyzed
8.8
GitHub SQLite

sqlite 3

2026-07-28
CVE-2026-51267
Analyzed
9.8
GitHub ESP32-audioI2S

The schreibfaul1 ESP32-audioI2S 3.4.5 library is susceptible to a heap-based buffer overflow in the URL path concatenation module, allowing for remote...

2026-07-29
CVE-2026-51259
Analyzed
9.8
GitHub ESP32-audioI2S

An integer overflow in the buffer size calculation for schreibfaul1 ESP32-audioI2S 3.4.5 results in heap memory corruption, enabling denial of service...

2026-07-29
CVE-2026-51252
Analyzed
9.8
GitHub ESP32-audioI2S

A buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote attackers to execute code...

2026-07-29
CVE-2026-51244
Analyzed
7.5
GitHub ESP32-audioI2S

schreibfaul1 ESP32-audioI2S 3

2026-08-15
CVE-2026-51235
Analyzed
8.8
GitHub LibRaw

LibRaw 0

2026-07-28
CVE-2026-51190
Analyzed
9.8
GitHub Serverless-Devs (s)

The Serverless-Devs command line tool is vulnerable to OS command injection via the s init command, which fails to sanitize user input before passing...

2026-08-27
CVE-2026-51152
Analyzed
9.1
GitHub QD

An unauthenticated server-side request forgery (SSRF) vulnerability in the /har/test endpoint allows attackers to force the server to send arbitrary H...

2026-09-04
CVE-2026-50086
Analyzed
10
GitHub IAM/SSO gateway

The Aqara IAM/SSO gateway contains a critical flaw that exposes cryptographic signing keys, allowing unauthenticated attackers to perform unauthorized...

2026-06-13
CVE-2026-49352
Analyzed
9.8
GitHub 9router

9Router contains a hardcoded fallback JWT secret in its authentication routing and middleware, allowing unauthenticated attackers to forge authenticat...

2026-07-16
CVE-2026-48710
KEV Analyzed
9.5
GitHub Starlette

A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security...

2026-09-03
CVE-2026-48168
Analyzed
10
GitHub PraisonAI

PraisonAI versions prior to 4.6.40 contain a command injection vulnerability in its GitHub Actions workflow, allowing unauthenticated attackers to exe...

2026-08-06
CVE-2026-4800
Analyzed
8.1
GitHub Multiple Products

Impact: The fix for CVE-2021-23337 (https://github

2026-04-01
CVE-2026-47670
Analyzed
9.4
GitHub dbgate

DbGate contains an authenticated remote code execution vulnerability in the /runners/load-reader endpoint, allowing attackers with valid credentials t...

2026-07-24
CVE-2026-47668
Analyzed
10
GitHub dbgate

DbGate is vulnerable to unauthenticated remote code execution via the JSON script runner endpoint, allowing attackers to inject and execute arbitrary...

2026-07-24
CVE-2026-4645
Analyzed
7.5
GitHub Multiple Products

A flaw was found in the `github

2026-03-24
CVE-2026-46412
Analyzed
10
GitHub beproduct-org-nestjs-auth

The @beproduct/nestjs-auth package was compromised via a malicious npm publish, leading to the distribution of versions containing code designed to ex...

2026-07-21
CVE-2026-45809
Analyzed
8.7
GitHub opensips

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

2026-08-05
CVE-2026-45556
Analyzed
9.9
GitHub Roxy-WI

Roxy-WI contains an authenticated arbitrary file write vulnerability in its WAF rule saving functionality, allowing for Remote Code Execution on manag...

2026-06-11
CVE-2026-45482
Analyzed
8.4
GitHub Copilot / Visual Studio Code

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information...

2026-06-20
CVE-2026-45321
KEV Analyzed
9.6
GitHub Actions OIDC

GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extracti...

2026-05-12
CVE-2026-45270
Analyzed
8.7
GitHub ci4ms

CI4MS is a CodeIgniter 4-based content management system skeleton

2026-07-21
CVE-2026-45132
Analyzed
10
GitHub Open Source Helm Charts

A GitHub Actions workflow in CloudPirates Helm Charts exposes Personal Access Tokens and SSH signing keys to untrusted code.

2026-06-02
CVE-2026-45131
Analyzed
10
GitHub Open Source Helm Charts

A GitHub Actions workflow in CloudPirates Helm Charts executes attacker-controlled code from forks, exposing repository secrets.

2026-06-02
CVE-2026-44971
Analyzed
8.2
GitHub credentials with

GuardDog is a CLI tool to identify malicious PyPI packages

2026-05-29
CVE-2026-44359
Analyzed
10
GitHub firmware

A code injection vulnerability in the Meshtastic firmware GitHub workflow allows unauthorized execution of attacker-controlled code, leading to potent...

2026-07-20
CVE-2026-42603
Analyzed
8.8
GitHub Multiple Products

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more

2026-05-12
CVE-2026-42298
Analyzed
10
GitHub Postiz

A "Pwn Request" vulnerability in Postiz allows unauthenticated users to execute arbitrary code via malicious pull requests, leading to credential exfi...

2026-05-09
CVE-2026-41500
Analyzed
9.8
GitHub Electerm

A command injection vulnerability in Electerm allows attackers to execute arbitrary code by supplying a malicious release name.

2026-05-08
CVE-2026-41431
Analyzed
8
GitHub release pipeline

Zen is a firefox-based browser

2026-05-12
CVE-2026-41414
Analyzed
7.4
GitHub user can

Skim is a fuzzy finder designed to through files, lines, and commands

2026-04-25
CVE-2026-41311
Analyzed
7.5
GitHub Pages compatible

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-05-10
CVE-2026-41109
Analyzed
8.8
GitHub Copilot and

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unaut...

2026-05-13
CVE-2026-41053
Analyzed
8.8
GitHub Rancher

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access t...

2026-07-01
CVE-2026-40903
Analyzed
9.1
GitHub goshs

The goshs SimpleHTTPServer is affected by an ArtiPACKED vulnerability that can lead to the unauthorized leakage of GITHUB_TOKEN credentials via workfl...

2026-04-22
CVE-2026-40890
Analyzed
7.5
GitHub Multiple Products

The package `github

2026-04-22
CVE-2026-40345
Analyzed
8.2
GitHub deepmerge-ts

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects

2026-08-22
CVE-2026-40316
Analyzed
8.8
GitHub Multiple Products

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more

2026-04-16
CVE-2026-38976
Analyzed
7.5
GitHub mrubyc

mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level...

2026-07-11
CVE-2026-38765
Analyzed
7.8
GitHub Protegent 360

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

2026-08-01
CVE-2026-38165
Analyzed
9.8
GitHub xdocreport

A Server-Side Template Injection (SSTI) vulnerability in the xdocreport Velocity template engine configuration allows unauthenticated remote attackers...

2026-08-26
CVE-2026-37751
Analyzed
9.8
GitHub ai-maestro

A critical OS command injection vulnerability in the ai-maestro killSessionSync function allows unauthenticated attackers to execute arbitrary system...

2026-08-29
CVE-2026-37271
Analyzed
9.8
GitHub Smartwatch FB BGS001

The Fire-Boltt Smartwatch FB BGS001 firmware allows unauthorized access via GATT Write Request commands, enabling replay attacks using captured BLE pa...

2026-07-11
CVE-2026-36851
Analyzed
7.5
GitHub UnPoller

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

2026-09-01
CVE-2026-36590
Analyzed
7.5
GitHub NanoMQ

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

2026-07-20
CVE-2026-36425
Analyzed
7.8
GitHub AppRemover

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send...

2026-07-21
CVE-2026-35580
Analyzed
9.1
GitHub Actions workflow

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-contro...

2026-04-08
CVE-2026-34243
Analyzed
9.8
GitHub Actions workflow

The wenxian GitHub Actions workflow is vulnerable to command injection via untrusted user input in issue comments, allowing arbitrary code execution o...

2026-04-01
CVE-2026-34042
Analyzed
8.2
GitHub actions

act is a project which allows for local running of github actions

2026-03-31
CVE-2026-33475
Analyzed
9.1
GitHub Actions workflows

Unauthenticated remote shell injection in Langflow's GitHub Actions workflows allows attackers to execute arbitrary commands and exfiltrate CI secrets...

2026-03-25
CVE-2026-31945
Analyzed
7.7
GitHub Multiple Products

LibreChat is a ChatGPT clone with additional features

2026-03-28
CVE-2026-31309
Analyzed
7.5
GitHub Mysterium Node

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwri...

2026-07-12
CVE-2026-30920
Analyzed
8.6
GitHub App callback

OneUptime is a solution for monitoring and managing online services

2026-03-11
CVE-2026-29872
Analyzed
8.2
GitHub MCP Agent

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-0...

2026-03-31
CVE-2026-26718
Analyzed
9.1
GitHub xxl-job-admin

A Cross Site Request Forgery vulnerability in the xxl-job-admin web application allows unauthenticated attackers to modify Glue IDE shell scripts.

2026-07-20
CVE-2026-26323
Analyzed
8.8
GitHub login from

OpenClaw is a personal AI assistant

2026-02-21
CVE-2026-26187
Analyzed
8.1
GitHub lakeFS

lakeFS is an open-source tool that transforms object storage into a Git-like repositories

2026-02-14
CVE-2026-25761
Analyzed
8.8
GitHub Action or

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone

2026-02-10
CVE-2026-23654
Analyzed
8.8
GitHub Repo

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network

2026-03-11
CVE-2026-22659
Analyzed
8.1
GitHub FlaskBB

FlaskBB through 2

2026-07-11
CVE-2026-21523
Analyzed
8
GitHub Copilot and

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network

2026-02-11
CVE-2026-21516
Analyzed
8.8
GitHub Copilot allows

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code...

2026-02-11
CVE-2026-21257
Analyzed
8
GitHub Copilot and

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker...

2026-02-11
CVE-2026-21256
Analyzed
8.8
GitHub Copilot and

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke...

2026-02-11
CVE-2026-19983
Analyzed
8.3
GitHub A1300, AX1800, AXT1800, MT2500, MT3000, MT6000

A vulnerability was detected in GL

2026-08-17
CVE-2026-19754
Analyzed
8.6
GitHub Baserow

Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify for...

2026-09-02
CVE-2026-19374
Analyzed
7.3
GitHub api-mcp

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06

2026-08-10
CVE-2026-19348
Analyzed
9.8
GitHub M300 Wi-Fi Repeater

A command injection vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater allows remote attackers to execute arbitrary commands via the /protocol.c...

2026-08-10
CVE-2026-19195
Analyzed
7.8
GitHub V-Secure Jingyun Antivirus

A vulnerability has been found in V-Secure Jingyun Antivirus 2

2026-08-08
CVE-2026-18898
Analyzed
8.8
GitHub HiPER 1200GW

A security flaw has been discovered in UTT HiPER 1200GW up to v2

2026-08-05
CVE-2026-18895
Analyzed
8.8
GitHub HiPER 1250GW

A vulnerability was found in UTT HiPER 1250GW up to 3

2026-08-05
CVE-2026-18787
Analyzed
8.8
GitHub AX1800

A vulnerability was identified in GL

2026-08-05
CVE-2026-18686
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system c...

2026-08-04
CVE-2026-18685
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to...

2026-08-04
CVE-2026-18684
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers...

2026-08-04
CVE-2026-18616
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attacker...

2026-08-04
CVE-2026-18615
Analyzed
9.8
GitHub GL-MT3000

An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.ge...

2026-08-04
CVE-2026-18614
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18613
Analyzed
9.8
GitHub GL-MT3000

A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attacker...

2026-08-04
CVE-2026-18612
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary co...

2026-08-04
CVE-2026-18602
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attacker...

2026-08-04
CVE-2026-18601
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via...

2026-08-04
CVE-2026-18599
Analyzed
8
GitHub GL-MT3000

A flaw has been found in GL

2026-08-04
CVE-2026-18589
Analyzed
9.8
GitHub WL-NU516U1

A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the...

2026-08-03
CVE-2026-18588
Analyzed
9.8
GitHub WL-NU516U1

The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CON...

2026-08-03
CVE-2026-18587
Analyzed
7.5
GitHub WL-NU516U1

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628

2026-08-03
CVE-2026-18360
Analyzed
7.6
GitHub iris-web

The IRIS web application in version 2

2026-08-01
CVE-2026-17583
Analyzed
8.4
GitHub Applied Biosystems Genetic Analyzers (Data Collection Software)

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because

2026-08-06
CVE-2026-17556
Analyzed
8.8
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and direc...

2026-08-06
CVE-2026-1699
Analyzed
10
GitHub Multiple Products

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out...

2026-01-31
CVE-2026-16232
KEV Analyzed
9.5
GitHub SmartConsole

An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.

2026-07-23
CVE-2026-16209
Analyzed
7.3
GitHub Gerapy

A vulnerability has been found in Gerapy up to 0

2026-07-19
CVE-2026-15734
Analyzed
9.8
GitHub WGDashboard

A Server-Side Template Injection (SSTI) vulnerability in WGDashboard allows authenticated attackers to execute arbitrary code as root.

2026-08-27
CVE-2026-15732
Analyzed
9.8
GitHub WGDashboard

A Server-Side Request Forgery (SSRF) vulnerability in WGDashboard allows authenticated attackers to perform arbitrary HTTP requests and retrieve respo...

2026-08-15
CVE-2026-15542
Analyzed
7.3
GitHub Isaiah

A vulnerability has been found in will-moss Isaiah up to 1

2026-07-13
CVE-2026-15541
Analyzed
7.3
GitHub Isaiah

A flaw has been found in will-moss Isaiah up to 1

2026-07-13
CVE-2026-15515
Analyzed
7
GitHub PC Manager

A security vulnerability has been detected in Tencent PC Manager 18

2026-07-13
CVE-2026-15511
Analyzed
9.8
GitHub CF-WR631AX V3

A critical OS command injection vulnerability exists in the Comfast CF-WR631AX V3 router via the FastCGI backend, allowing unauthenticated remote atta...

2026-07-13
CVE-2026-15497
Analyzed
7.3
GitHub sonic-agent

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2

2026-07-13
CVE-2026-15481
Analyzed
8.8
GitHub TEW-635BRM

A security flaw has been discovered in Trendnet TEW-635BRM up to 1

2026-07-12
CVE-2026-15343
Analyzed
8.6
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot update...

2026-07-18
CVE-2026-14871
Analyzed
7.1
GitHub osTicket

osTicket versions v1

2026-07-19
CVE-2026-10667
Analyzed
7.8
GitHub zephyr

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace

2026-07-13
CVE-2026-10649
Analyzed
8.6
GitHub Pacemaker

A flaw was found in Pacemaker

2026-06-17
CVE-2026-0756
Analyzed
9.8
GitHub Multiple Products

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr...

2026-01-23
CVE-2025-70290
Analyzed
9.8
GitHub U-Boot

Denx U-Boot contains an integer overflow vulnerability in its ZFS filesystem support, which can be triggered by malformed metadata to cause memory cor...

2026-09-01
CVE-2025-66401
Analyzed
9.8
GitHub Multiple Products

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical...

2025-12-02
CVE-2025-66389
Analyzed
7.5
GitHub Copilot

GitHub Copilot 1

2026-06-23
CVE-2025-65637
Analyzed
7.5
GitHub Multiple Products

A denial-of-service vulnerability exists in github

2025-12-06
CVE-2025-62593
KEV Analyzed
9.5
GitHub Ray

Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.

2026-08-18
CVE-2025-61165
Analyzed
9.8
GitHub North AI

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of Cohere North AI v1.1.5 allows unauthenticated attackers to execut...

2026-08-31
CVE-2025-60357
Analyzed
8.1
GitHub EPP Management

AhnLab EPP Management v1

2026-07-18
CVE-2025-60021
Analyzed
9.8
GitHub Multiple Products

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to i...

2026-01-17
CVE-2025-59157
Analyzed
9.9
GitHub Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Reposit...

2026-01-06
CVE-2025-56005
Analyzed
9.8
GitHub Multiple Products

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the...

2026-01-21
CVE-2025-55322
Analyzed
7.3
GitHub Multiple Products

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network

2025-09-24
CVE-2025-54594
Analyzed
9.1
GitHub Multiple Products

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml Git...

2025-08-07
CVE-2025-54416
9.1
GitHub Multiple Products

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In version...

2025-07-28
CVE-2025-53773
Analyzed
7.8
GitHub Multiple Products

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke...

2025-08-13
CVE-2025-53624
Analyzed
10
GitHub Multiple Products

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ver...

2025-07-10
CVE-2025-53546
Analyzed
9.1
GitHub Multiple Products

Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-commit.yml can be exploited by att...

2025-07-10
CVE-2025-51679
Analyzed
9.1
GitHub OR1200

A mismatch between RTL and netlist in openRISC OR1200 commit 83ac6b can lead to unexpected behavior, potentially allowing unauthorized data access or...

2026-09-02
CVE-2025-51678
Analyzed
7.5
GitHub PicoRV32

An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.

2026-07-23
CVE-2025-45868
Analyzed
8.8
GitHub Enterprise

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to man...

2026-07-21
CVE-2025-45422
Analyzed
8.1
GitHub b-box

Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port fo...

2026-07-12
CVE-2025-27772
Analyzed
7.4
GitHub uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2025-27770
Analyzed
7.4
GitHub uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2024-58354
Analyzed
9.9
GitHub cal.diy

A repository takeover vulnerability exists in the cal.diy GitHub Actions workflow, allowing attackers to execute arbitrary code via malicious pull req...

2026-07-24
CVE-2024-39024
Analyzed
8.8
GitHub PacketFence

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

2026-08-27
CVE-2023-49105
KEV Analyzed
9.5
GitHub ownCloud Core

An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no s...

2026-08-28
CVE-2019-25718
Analyzed
8.4
GitHub Infinity Explorer C700

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying...

2026-06-04