175 Total CVEs
155 AI Analyzed
3 CISA KEV
77 Critical
All Vendors
Showing 1-175 of 175 CVEs
CVE-2026-7679
Analyzed
7.3
GitHub yudao-cloud

A security flaw has been discovered in YunaiV yudao-cloud up to 2026

2026-05-04
CVE-2026-76590
Analyzed
9.9
GitHub TEW-755AP

The TRENDnet TEW-755AP file /cgi-bin/wan.cgi is vulnerable to a stack-based buffer overflow via the cameo.wan.wan_pppoe_password_00 argument, allowing...

2026-08-20
CVE-2026-76589
Analyzed
9.9
GitHub TEW-755AP

The TRENDnet TEW-755AP file /sbin/mycli contains a stack-based buffer overflow vulnerability in the function FUN_401000, which can be triggered remote...

2026-08-20
CVE-2026-76584
Analyzed
9.9
GitHub TV-IP751WIC

A stack-based buffer overflow vulnerability in the TRENDnet TV-IP751WIC camera allows remote attackers to execute arbitrary code via the Currenttime a...

2026-08-20
CVE-2026-76008
Analyzed
10
GitHub CF-N1-S

A stack-based buffer overflow in the Comfast CF-N1-S URI parameter parsing component allows remote, unauthenticated attackers to execute arbitrary cod...

2026-08-19
CVE-2026-76004
Analyzed
9.9
GitHub HiPER 1250GW

The UTT HiPER 1250GW router contains a stack-based buffer overflow in the /goform/aspApBasicConfigUrcp component, reachable via the pvid argument, all...

2026-08-19
CVE-2026-76003
Analyzed
9.9
GitHub HiPER 1200GW

The UTT HiPER 1200GW router contains a stack-based buffer overflow vulnerability in the strcpy function, reachable via the timestart argument in /gofo...

2026-08-19
CVE-2026-75976
Analyzed
9.9
GitHub TEW-823DRU

A stack-based buffer overflow exists in the TRENDnet TEW-823DRU router due to improper input validation in the wan_l2tp_password argument within the w...

2026-08-19
CVE-2026-75877
Analyzed
9.9
GitHub TV-IP751WIC

The TRENDnet TV-IP751WIC contains a stack-based buffer overflow vulnerability in the alphapd component that can be triggered remotely by an authentica...

2026-08-19
CVE-2026-75784
Analyzed
10
GitHub TEW-WLC100

A stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote unauthenticated attackers to execute arbitrary code.

2026-08-19
CVE-2026-75094
Analyzed
9.1
GitHub CF-N1-S

A critical OS command injection vulnerability exists in the COMFAST CF-N1-S CGI interface, allowing authenticated attackers to execute arbitrary syste...

2026-08-18
CVE-2026-74843
Analyzed
10
GitHub WN531P3, WN535M1

A stack-based buffer overflow in the Wavlink Export Pingortrace CGI function allows unauthenticated remote attackers to execute arbitrary code via a m...

2026-08-18
CVE-2026-73673
Analyzed
8.8
GitHub Netis NC63 Wireless AC1200 Router

Netis NC63 router firmware V3

2026-08-15
CVE-2026-72584
Analyzed
7.4
GitHub Fastschema

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0

2026-08-11
CVE-2026-72582
Analyzed
7.5
GitHub Fastschema

A NULL pointer dereference vulnerability in fastschema through v0

2026-08-11
CVE-2026-72581
Analyzed
8.6
GitHub xiaoai-patch

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart spea...

2026-08-11
CVE-2026-72573
Analyzed
8.8
GitHub pm2panel

An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on...

2026-08-11
CVE-2026-72572
Analyzed
7.5
GitHub xmysql

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the...

2026-08-11
CVE-2026-72565
Analyzed
9.8
GitHub APIJSON

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass access controls and read database con...

2026-08-11
CVE-2026-71518
Analyzed
7.5
GitHub Typemill

Typemill before 2

2026-08-18
CVE-2026-71259
Analyzed
8.6
GitHub esphome

ESPHome through 2026

2026-08-06
CVE-2026-71256
Analyzed
9.8
GitHub nanoMODBUS

nanoMODBUS contains an out-of-bounds stack read and wild-pointer write vulnerability in its Modbus identification response handling, which can be trig...

2026-08-06
CVE-2026-69703
Analyzed
9.8
GitHub Atals-Livre

Atals-Livre contains an improper access control vulnerability in admin controllers that allows unauthenticated attackers to bypass authentication and...

2026-08-05
CVE-2026-6924
Analyzed
8.7
GitHub Silicon Labs Matter Github

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed

2026-07-24
CVE-2026-69118
Analyzed
8.8
GitHub Cachet

Cachet through 2

2026-08-11
CVE-2026-68005
Analyzed
7.5
GitHub mini_httpd

An issue in ACME mini_httpd 1

2026-08-18
CVE-2026-67975
Analyzed
7.5
GitHub cFS (Core Flight System)

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/...

2026-08-12
CVE-2026-67620
Analyzed
7.7
GitHub Flowise

Flowise through 3

2026-08-09
CVE-2026-67352
Analyzed
7.6
GitHub LuCI

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject...

2026-08-02
CVE-2026-67308
Analyzed
10
GitHub Wazuh

Wazuh workflows contain a shell injection vulnerability in GitHub Actions, allowing attackers to execute arbitrary commands via crafted VERSION.json f...

2026-08-02
CVE-2026-66748
Analyzed
8.8
GitHub camaleon-cms

Camaleon CMS versions 2

2026-07-29
CVE-2026-66731
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66730
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66729
Analyzed
7.5
GitHub facil.io

facil

2026-07-28
CVE-2026-66373
Analyzed
7.5
GitHub Redis

Redis before 8

2026-07-26
CVE-2026-65604
Analyzed
8.2
GitHub Skipper

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies

2026-07-25
CVE-2026-65423
Analyzed
8.8
GitHub open62541

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write

2026-07-31
CVE-2026-63361
Analyzed
8.5
GitHub LimeSurvey

LimeSurvey Community Edition 7

2026-08-15
CVE-2026-63304
Analyzed
8.1
GitHub AVideo

AVideo through 29

2026-07-17
CVE-2026-61876
Analyzed
8.8
GitHub LuCI

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML mar...

2026-07-14
CVE-2026-61556
Analyzed
8.7
GitHub LiquidJS

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-08-21
CVE-2026-58586
Analyzed
9.8
GitHub Image::WebP

The Perl module Image::WebP bundles a vulnerable version of libwebp, which allows remote attackers to trigger heap corruption and potential code execu...

2026-08-02
CVE-2026-57858
Analyzed
8.9
GitHub Cal.com Self-Hosted (Cal.diy)

Cal

2026-08-13
CVE-2026-57074
Analyzed
9.1
GitHub XML::Bare

XML::Bare versions through 0.53 for Perl are susceptible to an out-of-bounds read vulnerability when processing malformed or truncated XML strings.

2026-07-21
CVE-2026-56721
Analyzed
8.8
GitHub CamaleonCMS

CamaleonCMS version 2

2026-08-12
CVE-2026-56699
Analyzed
10
GitHub wazuh

Wazuh Manager fails to sanitize input in the DataValue.index field, allowing unauthenticated agents to perform NDJSON injection attacks against the ma...

2026-07-16
CVE-2026-56677
Analyzed
8.6
GitHub 9router

9Router is an AI router & token saver

2026-08-18
CVE-2026-55579
Analyzed
9.8
GitHub pheditor

Pheditor versions 2.0.1 through 2.0.5 contain hardcoded credentials that allow unauthenticated attackers to gain full administrative access and execut...

2026-07-28
CVE-2026-55575
Analyzed
8.2
GitHub LiquidJS

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-07-09
CVE-2026-54418
Analyzed
8.1
GitHub Leantime

Leantime through 3

2026-08-05
CVE-2026-53513
Analyzed
9.6
GitHub better-auth

The better-auth SSO plugin fails to validate OIDC configuration URLs, allowing authenticated users to perform server-side request forgery and potentia...

2026-07-16
CVE-2026-52656
Analyzed
9.8
GitHub SJ4000-Air

A critical vulnerability in SJCAM SJ4000-Air cameras allows arbitrary code execution through the processing of maliciously crafted FEX files.

2026-07-27
CVE-2026-52472
Analyzed
9.8
GitHub Wgcloud

A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.

2026-07-31
CVE-2026-51821
Analyzed
9.8
GitHub Video Conference System

A SQL injection vulnerability in the /user/getUserLogin endpoint of Shenzhou Shihan Video Conference System v.1.0 allows unauthenticated remote attack...

2026-07-17
CVE-2026-51541
Analyzed
9.1
GitHub OpENer

An out-of-bounds read vulnerability in OpENer 2.3.0 during CIP message parsing allows attackers to crash the service via malformed ENIP SendRRData fra...

2026-07-17
CVE-2026-51538
Analyzed
9.1
GitHub OpENer

OpENer 2.3.0 contains an improper access control vulnerability where the server fails to verify if a session handle belongs to the specific TCP connec...

2026-07-17
CVE-2026-51537
Analyzed
9.1
GitHub OpENer

An out-of-bounds read vulnerability in OpENer 2.3.0 allows unauthenticated attackers to cause a Denial of Service by sending malformed ForwardOpen or...

2026-07-17
CVE-2026-51536
Analyzed
9.1
GitHub OpENer

A stack-based buffer overflow in OpENer 2.3.0 occurs during CIP packet parsing, caused by an integer overflow and truncation when handling length para...

2026-07-17
CVE-2026-51297
Analyzed
8.8
GitHub SQLite

sqlite 3

2026-07-28
CVE-2026-51267
Analyzed
9.8
GitHub ESP32-audioI2S

The schreibfaul1 ESP32-audioI2S 3.4.5 library is susceptible to a heap-based buffer overflow in the URL path concatenation module, allowing for remote...

2026-07-29
CVE-2026-51259
Analyzed
9.8
GitHub ESP32-audioI2S

An integer overflow in the buffer size calculation for schreibfaul1 ESP32-audioI2S 3.4.5 results in heap memory corruption, enabling denial of service...

2026-07-29
CVE-2026-51252
Analyzed
9.8
GitHub ESP32-audioI2S

A buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote attackers to execute code...

2026-07-29
CVE-2026-51244
Analyzed
7.5
GitHub ESP32-audioI2S

schreibfaul1 ESP32-audioI2S 3

2026-08-15
CVE-2026-51235
Analyzed
8.8
GitHub LibRaw

LibRaw 0

2026-07-28
CVE-2026-50086
Analyzed
10
GitHub IAM/SSO gateway

The Aqara IAM/SSO gateway contains a critical flaw that exposes cryptographic signing keys, allowing unauthenticated attackers to perform unauthorized...

2026-06-13
CVE-2026-49352
Analyzed
9.8
GitHub 9router

9Router contains a hardcoded fallback JWT secret in its authentication routing and middleware, allowing unauthenticated attackers to forge authenticat...

2026-07-16
CVE-2026-48168
Analyzed
10
GitHub PraisonAI

PraisonAI versions prior to 4.6.40 contain a command injection vulnerability in its GitHub Actions workflow, allowing unauthenticated attackers to exe...

2026-08-06
CVE-2026-4800
8.1
GitHub Multiple Products

Impact: The fix for CVE-2021-23337 (https://github

2026-04-01
CVE-2026-47670
Analyzed
9.4
GitHub dbgate

DbGate contains an authenticated remote code execution vulnerability in the /runners/load-reader endpoint, allowing attackers with valid credentials t...

2026-07-24
CVE-2026-47668
Analyzed
10
GitHub dbgate

DbGate is vulnerable to unauthenticated remote code execution via the JSON script runner endpoint, allowing attackers to inject and execute arbitrary...

2026-07-24
CVE-2026-4645
7.5
GitHub Multiple Products

A flaw was found in the `github

2026-03-24
CVE-2026-46412
Analyzed
10
GitHub beproduct-org-nestjs-auth

The @beproduct/nestjs-auth package was compromised via a malicious npm publish, leading to the distribution of versions containing code designed to ex...

2026-07-21
CVE-2026-45809
Analyzed
8.7
GitHub opensips

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

2026-08-05
CVE-2026-45556
Analyzed
9.9
GitHub Roxy-WI

Roxy-WI contains an authenticated arbitrary file write vulnerability in its WAF rule saving functionality, allowing for Remote Code Execution on manag...

2026-06-11
CVE-2026-45482
Analyzed
8.4
GitHub Copilot / Visual Studio Code

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information...

2026-06-20
CVE-2026-45321
KEV Analyzed
9.6
GitHub Actions OIDC

GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extracti...

2026-05-12
CVE-2026-45270
Analyzed
8.7
GitHub ci4ms

CI4MS is a CodeIgniter 4-based content management system skeleton

2026-07-21
CVE-2026-45132
Analyzed
10
GitHub Open Source Helm Charts

A GitHub Actions workflow in CloudPirates Helm Charts exposes Personal Access Tokens and SSH signing keys to untrusted code.

2026-06-02
CVE-2026-45131
Analyzed
10
GitHub Open Source Helm Charts

A GitHub Actions workflow in CloudPirates Helm Charts executes attacker-controlled code from forks, exposing repository secrets.

2026-06-02
CVE-2026-44971
Analyzed
8.2
GitHub credentials with

GuardDog is a CLI tool to identify malicious PyPI packages

2026-05-29
CVE-2026-44359
Analyzed
10
GitHub firmware

A code injection vulnerability in the Meshtastic firmware GitHub workflow allows unauthorized execution of attacker-controlled code, leading to potent...

2026-07-20
CVE-2026-42603
Analyzed
8.8
GitHub Multiple Products

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more

2026-05-12
CVE-2026-42298
Analyzed
10
GitHub Postiz

A "Pwn Request" vulnerability in Postiz allows unauthenticated users to execute arbitrary code via malicious pull requests, leading to credential exfi...

2026-05-09
CVE-2026-41500
Analyzed
9.8
GitHub Electerm

A command injection vulnerability in Electerm allows attackers to execute arbitrary code by supplying a malicious release name.

2026-05-08
CVE-2026-41431
Analyzed
8
GitHub release pipeline

Zen is a firefox-based browser

2026-05-12
CVE-2026-41414
7.4
GitHub user can

Skim is a fuzzy finder designed to through files, lines, and commands

2026-04-25
CVE-2026-41311
7.5
GitHub Pages compatible

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

2026-05-10
CVE-2026-41109
Analyzed
8.8
GitHub Copilot and

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unaut...

2026-05-13
CVE-2026-41053
Analyzed
8.8
GitHub Rancher

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access t...

2026-07-01
CVE-2026-40903
Analyzed
9.1
GitHub goshs

The goshs SimpleHTTPServer is affected by an ArtiPACKED vulnerability that can lead to the unauthorized leakage of GITHUB_TOKEN credentials via workfl...

2026-04-22
CVE-2026-40890
7.5
GitHub Multiple Products

The package `github

2026-04-22
CVE-2026-40316
8.8
GitHub Multiple Products

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more

2026-04-16
CVE-2026-38976
Analyzed
7.5
GitHub mrubyc

mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level...

2026-07-11
CVE-2026-38765
Analyzed
7.8
GitHub Protegent 360

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

2026-08-01
CVE-2026-37271
Analyzed
9.8
GitHub Smartwatch FB BGS001

The Fire-Boltt Smartwatch FB BGS001 firmware allows unauthorized access via GATT Write Request commands, enabling replay attacks using captured BLE pa...

2026-07-11
CVE-2026-36590
Analyzed
7.5
GitHub NanoMQ

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

2026-07-20
CVE-2026-36425
Analyzed
7.8
GitHub AppRemover

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send...

2026-07-21
CVE-2026-35580
Analyzed
9.1
GitHub Actions workflow

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-contro...

2026-04-08
CVE-2026-34243
Analyzed
9.8
GitHub Actions workflow

The wenxian GitHub Actions workflow is vulnerable to command injection via untrusted user input in issue comments, allowing arbitrary code execution o...

2026-04-01
CVE-2026-34042
8.2
GitHub actions

act is a project which allows for local running of github actions

2026-03-31
CVE-2026-33475
Analyzed
9.1
GitHub Actions workflows

Unauthenticated remote shell injection in Langflow's GitHub Actions workflows allows attackers to execute arbitrary commands and exfiltrate CI secrets...

2026-03-25
CVE-2026-31945
Analyzed
7.7
GitHub Multiple Products

LibreChat is a ChatGPT clone with additional features

2026-03-28
CVE-2026-31309
Analyzed
7.5
GitHub Mysterium Node

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwri...

2026-07-12
CVE-2026-30920
8.6
GitHub App callback

OneUptime is a solution for monitoring and managing online services

2026-03-11
CVE-2026-29872
8.2
GitHub MCP Agent

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-0...

2026-03-31
CVE-2026-26718
Analyzed
9.1
GitHub xxl-job-admin

A Cross Site Request Forgery vulnerability in the xxl-job-admin web application allows unauthenticated attackers to modify Glue IDE shell scripts.

2026-07-20
CVE-2026-26323
8.8
GitHub login from

OpenClaw is a personal AI assistant

2026-02-21
CVE-2026-26187
Analyzed
8.1
GitHub lakeFS

lakeFS is an open-source tool that transforms object storage into a Git-like repositories

2026-02-14
CVE-2026-25761
8.8
GitHub Action or

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone

2026-02-10
CVE-2026-23654
8.8
GitHub Repo

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network

2026-03-11
CVE-2026-22659
Analyzed
8.1
GitHub FlaskBB

FlaskBB through 2

2026-07-11
CVE-2026-21523
8
GitHub Copilot and

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network

2026-02-11
CVE-2026-21516
8.8
GitHub Copilot allows

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code...

2026-02-11
CVE-2026-21257
8
GitHub Copilot and

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker...

2026-02-11
CVE-2026-21256
8.8
GitHub Copilot and

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke...

2026-02-11
CVE-2026-19983
Analyzed
8.3
GitHub A1300, AX1800, AXT1800, MT2500, MT3000, MT6000

A vulnerability was detected in GL

2026-08-17
CVE-2026-19374
Analyzed
7.3
GitHub api-mcp

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06

2026-08-10
CVE-2026-19348
Analyzed
9.8
GitHub M300 Wi-Fi Repeater

A command injection vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater allows remote attackers to execute arbitrary commands via the /protocol.c...

2026-08-10
CVE-2026-19195
Analyzed
7.8
GitHub V-Secure Jingyun Antivirus

A vulnerability has been found in V-Secure Jingyun Antivirus 2

2026-08-08
CVE-2026-18898
Analyzed
8.8
GitHub HiPER 1200GW

A security flaw has been discovered in UTT HiPER 1200GW up to v2

2026-08-05
CVE-2026-18895
Analyzed
8.8
GitHub HiPER 1250GW

A vulnerability was found in UTT HiPER 1250GW up to 3

2026-08-05
CVE-2026-18787
Analyzed
8.8
GitHub AX1800

A vulnerability was identified in GL

2026-08-05
CVE-2026-18686
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system c...

2026-08-04
CVE-2026-18685
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to...

2026-08-04
CVE-2026-18684
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers...

2026-08-04
CVE-2026-18616
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attacker...

2026-08-04
CVE-2026-18615
Analyzed
9.8
GitHub GL-MT3000

An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.ge...

2026-08-04
CVE-2026-18614
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18613
Analyzed
9.8
GitHub GL-MT3000

A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attacker...

2026-08-04
CVE-2026-18612
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary co...

2026-08-04
CVE-2026-18602
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attacker...

2026-08-04
CVE-2026-18601
Analyzed
9.8
GitHub GL-MT3000

A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via...

2026-08-04
CVE-2026-18599
Analyzed
8
GitHub GL-MT3000

A flaw has been found in GL

2026-08-04
CVE-2026-18589
Analyzed
9.8
GitHub WL-NU516U1

A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the...

2026-08-03
CVE-2026-18588
Analyzed
9.8
GitHub WL-NU516U1

The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CON...

2026-08-03
CVE-2026-18587
Analyzed
7.5
GitHub WL-NU516U1

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628

2026-08-03
CVE-2026-18360
Analyzed
7.6
GitHub iris-web

The IRIS web application in version 2

2026-08-01
CVE-2026-17583
Analyzed
8.4
GitHub Applied Biosystems Genetic Analyzers (Data Collection Software)

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because

2026-08-06
CVE-2026-17556
Analyzed
8.8
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and direc...

2026-08-06
CVE-2026-1699
Analyzed
10
GitHub Multiple Products

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out...

2026-01-31
CVE-2026-16232
KEV Analyzed
9.5
GitHub SmartConsole

An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.

2026-07-23
CVE-2026-16209
Analyzed
7.3
GitHub Gerapy

A vulnerability has been found in Gerapy up to 0

2026-07-19
CVE-2026-15732
Analyzed
9.8
GitHub WGDashboard

A Server-Side Request Forgery (SSRF) vulnerability in WGDashboard allows authenticated attackers to perform arbitrary HTTP requests and retrieve respo...

2026-08-15
CVE-2026-15542
Analyzed
7.3
GitHub Isaiah

A vulnerability has been found in will-moss Isaiah up to 1

2026-07-13
CVE-2026-15541
Analyzed
7.3
GitHub Isaiah

A flaw has been found in will-moss Isaiah up to 1

2026-07-13
CVE-2026-15515
Analyzed
7
GitHub PC Manager

A security vulnerability has been detected in Tencent PC Manager 18

2026-07-13
CVE-2026-15511
Analyzed
9.8
GitHub CF-WR631AX V3

A critical OS command injection vulnerability exists in the Comfast CF-WR631AX V3 router via the FastCGI backend, allowing unauthenticated remote atta...

2026-07-13
CVE-2026-15497
Analyzed
7.3
GitHub sonic-agent

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2

2026-07-13
CVE-2026-15481
Analyzed
8.8
GitHub TEW-635BRM

A security flaw has been discovered in Trendnet TEW-635BRM up to 1

2026-07-12
CVE-2026-15343
Analyzed
8.6
GitHub Enterprise Server

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot update...

2026-07-18
CVE-2026-14871
Analyzed
7.1
GitHub osTicket

osTicket versions v1

2026-07-19
CVE-2026-10667
Analyzed
7.8
GitHub zephyr

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace

2026-07-13
CVE-2026-10649
Analyzed
8.6
GitHub Pacemaker

A flaw was found in Pacemaker

2026-06-17
CVE-2026-0756
Analyzed
9.8
GitHub Multiple Products

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr...

2026-01-23
CVE-2025-66401
Analyzed
9.8
GitHub Multiple Products

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical...

2025-12-02
CVE-2025-66389
Analyzed
7.5
GitHub Copilot

GitHub Copilot 1

2026-06-23
CVE-2025-65637
7.5
GitHub Multiple Products

A denial-of-service vulnerability exists in github

2025-12-06
CVE-2025-62593
KEV Analyzed
9.5
GitHub Ray

Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.

2026-08-18
CVE-2025-60357
Analyzed
8.1
GitHub EPP Management

AhnLab EPP Management v1

2026-07-18
CVE-2025-60021
Analyzed
9.8
GitHub Multiple Products

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to i...

2026-01-17
CVE-2025-59157
Analyzed
9.9
GitHub Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Reposit...

2026-01-06
CVE-2025-56005
Analyzed
9.8
GitHub Multiple Products

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the...

2026-01-21
CVE-2025-55322
7.3
GitHub Multiple Products

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network

2025-09-24
CVE-2025-54594
Analyzed
9.1
GitHub Multiple Products

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml Git...

2025-08-07
CVE-2025-54416
9.1
GitHub Multiple Products

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In version...

2025-07-28
CVE-2025-53773
7.8
GitHub Multiple Products

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacke...

2025-08-13
CVE-2025-53624
Analyzed
10
GitHub Multiple Products

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ver...

2025-07-10
CVE-2025-53546
Analyzed
9.1
GitHub Multiple Products

Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-commit.yml can be exploited by att...

2025-07-10
CVE-2025-51678
Analyzed
7.5
GitHub PicoRV32

An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.

2026-07-23
CVE-2025-45868
Analyzed
8.8
GitHub Enterprise

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to man...

2026-07-21
CVE-2025-45422
Analyzed
8.1
GitHub b-box

Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port fo...

2026-07-12
CVE-2025-27772
Analyzed
7.4
GitHub uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2025-27770
Analyzed
7.4
GitHub uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2024-58354
Analyzed
9.9
GitHub cal.diy

A repository takeover vulnerability exists in the cal.diy GitHub Actions workflow, allowing attackers to execute arbitrary code via malicious pull req...

2026-07-24
CVE-2019-25718
Analyzed
8.4
GitHub Infinity Explorer C700

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying...

2026-06-04