10
    Critical

    CVE-2026-21962

    Last Modified: 25 Aug 2026

    Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

    Published:20 Jan 2026
    8.2
    High

    CVE-2026-21955

    Last Modified: 18 Apr 2026

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

    Published:20 Jan 2026
    9.3
    Critical

    CVE-2026-21902

    Last Modified: 16 Apr 2026

    An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

    Published:25 Feb 2026
    10
    Critical

    CVE-2026-21877

    Last Modified: 18 Apr 2026

    n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Cloud instances. This issue is fixed in version 1.121.3. Administrators can reduce exposure by disabling the Git node and limiting access for untrusted users, but upgrading to the latest version is recommended.

    Published:8 Jan 2026
    9.3
    Critical

    CVE-2026-21876

    Last Modified: 13 May 2026

    The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like `MULTIPART_PART_HEADERS`), the capture variables (`TX:0`, `TX:1`) get overwritten with each iteration. Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has a legitimate charset. Versions 4.22.0 and 3.3.8 patch the issue.

    Source:anonimicerum
    Published:8 Jan 2026
    10
    Critical

    CVE-2026-21858

    Last Modified: 18 Apr 2026

    n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.

    Published:7 Jan 2026
    8.3
    High

    CVE-2026-21857

    Last Modified: 18 Apr 2026

    REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backup addon does not validate the `EXPDIR` POST parameter against the UI-generated allowlist of permitted directories. An attacker can supply relative paths containing `../` sequences (or even absolute paths inside the document root) to include any readable file in the generated `.tar.gz` archive. Version 5.20.2 fixes this issue.

    Published:7 Jan 2026
    5.3
    Medium

    CVE-2026-21852

    Last Modified: 18 Apr 2026

    Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a settings file that sets ANTHROPIC_BASE_URL to an attacker-controlled endpoint and when the repository was opened, Claude Code would read the configuration and immediately issue API requests before showing the trust prompt, potentially leaking the user's API keys. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.0.65, which contains a patch, or to the latest version.

    Published:21 Jan 2026
    8.1
    High

    CVE-2026-21721

    Last Modified: 24 Apr 2026

    The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

    Published:27 Jan 2026
    5.9
    Medium

    CVE-2026-21717

    Last Modified: 19 Aug 2026

    A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.

    Published:30 Mar 2026
    7.5
    High

    CVE-2026-21710

    Last Modified: 19 Aug 2026

    A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**

    Published:30 Mar 2026
    9.1
    Critical

    CVE-2026-21643

    Last Modified: 16 Jun 2026

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

    Published:6 Feb 2026
    10
    Critical

    CVE-2026-21636

    Last Modified: 18 Apr 2026

    A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to arbitrary local sockets via net, tls, or undici/fetch. This breaks the intended security boundary of the permission model and enables access to privileged local services, potentially leading to privilege escalation, data exposure, or local code execution. * The issue affects users of the Node.js permission model on version v25. In the moment of this vulnerability, network permissions (`--allow-net`) are still in the experimental phase.

    Published:20 Jan 2026
    10
    Critical

    CVE-2026-21628

    Last Modified: 17 Apr 2026

    A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

    Published:5 Mar 2026
    9.5
    Critical

    CVE-2026-21627

    Last Modified: 17 Apr 2026

    The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.

    Published:20 Feb 2026
    7.8
    High

    CVE-2026-21533

    Last Modified: 22 Apr 2026

    Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

    Published:10 Feb 2026
    9.8
    Critical

    CVE-2026-21531

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

    Published:10 Feb 2026
    7.8
    High

    CVE-2026-21514

    Last Modified: 15 Apr 2026

    Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

    Published:10 Feb 2026
    8.8
    High

    CVE-2026-21510

    Last Modified: 15 Apr 2026

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

    Published:10 Feb 2026
    7.8
    High

    CVE-2026-21509

    Last Modified: 22 Apr 2026

    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

    Published:26 Jan 2026
    7
    High

    CVE-2026-21508

    Last Modified: 15 Apr 2026

    Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

    Published:10 Feb 2026
    8.8
    High

    CVE-2026-21445

    Last Modified: 18 Apr 2026

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. This affects endpoints handling personal data and system operations that should require proper authorization. Version 1.7.0.dev45 contains a patch.

    Published:2 Jan 2026
    9.2
    Critical

    CVE-2026-21440

    Last Modified: 18 Apr 2026

    AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease versions prior to 11.0.0-next.6. This issue has been patched in @adonisjs/bodyparser versions 10.1.2 and 11.0.0-next.6.

    Published:2 Jan 2026
    2
    Low

    CVE-2026-21437

    Last Modified: 18 Apr 2026

    eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by `lseopkg` and related tools. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected.

    Published:1 Jan 2026
    5.8
    Medium

    CVE-2026-21436

    Last Modified: 18 Apr 2026

    eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape the directory set by `--destdir`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be installed in the path given by `--destdir`, but on a different location on the host. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected.

    Published:1 Jan 2026
    7.8
    High

    CVE-2026-21385

    Last Modified: 18 Apr 2026

    Memory corruption while using alignments for memory allocation.

    Published:2 Mar 2026
    7.8
    High

    CVE-2026-21250

    Last Modified: 4 May 2026

    Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

    Source:3302509675
    Published:10 Feb 2026
    7.3
    High

    CVE-2026-21248

    Last Modified: 30 Apr 2026

    Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

    Source:nu11secur1ty
    Published:10 Feb 2026
    7.3
    High

    CVE-2026-21244

    Last Modified: 30 Apr 2026

    Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

    Source:nu11secur1ty
    Published:10 Feb 2026
    8.5
    High

    CVE-2026-21055

    Last Modified: 5 Aug 2026

    Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.

    Published:10 Jul 2026
    8.4
    High

    CVE-2026-21045

    Last Modified: 3 Aug 2026

    Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.

    Published:10 Jul 2026
    5.1
    Medium

    CVE-2026-21020

    Last Modified: 13 May 2026

    Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.

    Published:13 May 2026
    8.9
    High

    CVE-2026-21019

    Last Modified: 13 May 2026

    Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.

    Published:13 May 2026
    6.8
    Medium

    CVE-2026-21018

    Last Modified: 14 May 2026

    Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.

    Published:13 May 2026
    4.6
    Medium

    CVE-2026-21017

    Last Modified: 6 Jun 2026

    Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

    Published:5 Jun 2026
    5.1
    Medium

    CVE-2026-21016

    Last Modified: 13 May 2026

    Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

    Published:13 May 2026
    6.8
    Medium

    CVE-2026-21015

    Last Modified: 13 May 2026

    Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.

    Published:13 May 2026
    5.1
    Medium

    CVE-2026-21014

    Last Modified: 18 Apr 2026

    Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.

    Published:13 Apr 2026
    6.9
    Medium

    CVE-2026-21013

    Last Modified: 17 Apr 2026

    Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.

    Published:13 Apr 2026
    6.8
    Medium

    CVE-2026-21012

    Last Modified: 15 Apr 2026

    External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

    Published:13 Apr 2026
    5.4
    Medium

    CVE-2026-21011

    Last Modified: 15 Apr 2026

    Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

    Published:13 Apr 2026
    6.6
    Medium

    CVE-2026-21010

    Last Modified: 15 Apr 2026

    Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.

    Published:13 Apr 2026
    4.1
    Medium

    CVE-2026-21009

    Last Modified: 17 Apr 2026

    Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.

    Published:13 Apr 2026
    5.1
    Medium

    CVE-2026-21008

    Last Modified: 15 Apr 2026

    Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.

    Published:13 Apr 2026
    4.4
    Medium

    CVE-2026-21007

    Last Modified: 15 Apr 2026

    Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.

    Published:13 Apr 2026
    4.7
    Medium

    CVE-2026-21006

    Last Modified: 15 Apr 2026

    Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.

    Published:13 Apr 2026
    7.1
    High

    CVE-2026-21005

    Last Modified: 2 Apr 2026

    Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

    Published:16 Mar 2026
    6.9
    Medium

    CVE-2026-21004

    Last Modified: 2 Apr 2026

    Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

    Published:16 Mar 2026
    5.2
    Medium

    CVE-2026-21003

    Last Modified: 17 Apr 2026

    Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.

    Published:13 Apr 2026
    5.9
    Medium

    CVE-2026-21002

    Last Modified: 9 Apr 2026

    Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

    Published:16 Mar 2026
    Items Per Page