5.7
    Medium

    CVE-2026-0273

    Last Modified: 11 Jun 2026

    A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.

    Published:10 Jun 2026
    2.7
    Low

    CVE-2026-0265

    Last Modified: 9 Jun 2026

    An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

    Published:13 May 2026
    7.8
    High

    CVE-2026-0257

    Last Modified: 9 Jun 2026

    Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

    Published:13 May 2026
    6.6
    Medium

    CVE-2026-0227

    Last Modified: 18 Apr 2026

    A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

    Published:15 Jan 2026
    9.8
    Critical

    CVE-2026-0163

    Last Modified: 4 Aug 2026

    In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:4 Aug 2026
    Unknown

    CVE-2026-0101

    https://github.com/George0Papasotiriou/CVE-2026-0101-BLE-Address-Spoofing-via-Weak-Resolvable-Private-Address

    10
    Critical

    CVE-2026-0092

    Last Modified: 18 Jun 2026

    In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:17 Jun 2026
    7.8
    High

    CVE-2026-0091

    Last Modified: 3 Jun 2026

    In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:1 Jun 2026
    7.8
    High

    CVE-2026-0075

    Last Modified: 3 Jun 2026

    In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:1 Jun 2026
    8.8
    High

    CVE-2026-0073

    Last Modified: 5 May 2026

    In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:4 May 2026
    8
    High

    CVE-2026-0059

    Last Modified: 3 Jun 2026

    In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:1 Jun 2026
    6.2
    Medium

    CVE-2026-0049

    Last Modified: 13 Apr 2026

    In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:6 Apr 2026
    8.4
    High

    CVE-2026-0047

    Last Modified: 16 Apr 2026

    In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:2 Mar 2026
    Unknown

    CVE-2026-30

    https://github.com/itsismarcos/ICS-MoxieManager-FileUpload-PoC

    7.8
    High

    CVE-2026-0023

    Last Modified: 16 Apr 2026

    In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:2 Mar 2026
    8.4
    High

    CVE-2026-0013

    Last Modified: 26 Aug 2026

    In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:2 Mar 2026
    8.4
    High

    CVE-2026-0010

    Last Modified: 8 Sept 2026

    In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:2 Mar 2026
    7.8
    High

    CVE-2026-0009

    Last Modified: 26 Aug 2026

    In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:1 Jun 2026
    9.8
    Critical

    CVE-2026-0006

    Last Modified: 16 Apr 2026

    In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:2 Mar 2026
    4.4
    Medium

    CVE-2026-0001

    Last Modified: 8 Sept 2026

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.

    Published:8 Sept 2026
    Unknown

    CVE-2025-505050

    https://github.com/aljoharasubaie/CVE-2025-505050

    Unknown

    CVE-2025-471812

    https://github.com/d3vn0mi/CVE-2025-471812-POC

    Unknown

    CVE-2025-99999

    https://github.com/24520597-blip/CVE-2025-99999

    Unknown

    CVE-2025-81110

    https://github.com/BridgerAlderson/CVE-2025-81110-PoC

    10
    Critical

    CVE-2025-71389

    Last Modified: 28 Jul 2026

    Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

    Published:23 Jul 2026
    Unknown

    CVE-2025-71384

    https://github.com/Scorpion-Security-Labs/CVE-2025-71384

    10
    Critical

    CVE-2025-71338

    Last Modified: 26 Jun 2026

    Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.

    Published:25 Jun 2026
    8.7
    High

    CVE-2025-71329

    Last Modified: 14 Jul 2026

    image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

    Published:10 Jun 2026
    6.9
    Medium

    CVE-2025-71257

    Last Modified: 22 Apr 2026

    BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and gain unauthorized access to application data and modify system resources. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

    Published:19 Mar 2026
    9.3
    Critical

    CVE-2025-71243

    Last Modified: 5 Mar 2026

    The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or later.

    Published:19 Feb 2026
    8.8
    High

    CVE-2025-70995

    Last Modified: 22 Apr 2026

    An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, which is processed by the ASP.NET runtime. The uploaded configuration file alters the execution context of the upload directory, enabling compilation and execution of attacker-controlled code (e.g., generation of an .aspx webshell). This allows remote command execution on the server without user interaction beyond authentication, impacting both On-Premise and SaaS deployments. The vendor has fixed the issue in Aranda Service Desk V8 8.30.6.

    Published:5 Mar 2026
    7.3
    High

    CVE-2025-70994

    Last Modified: 28 Apr 2026

    Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmission, allowing for complete unauthorized vehicle operation via a replay attack.

    Published:23 Apr 2026
    7.5
    High

    CVE-2025-70962

    Last Modified: 7 Aug 2026

    Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage.

    Published:5 Aug 2026
    6.5
    Medium

    CVE-2025-70899

    Last Modified: 2 Feb 2026

    PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.

    Published:22 Jan 2026
    7.5
    High

    CVE-2025-70886

    Last Modified: 18 Feb 2026

    An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

    Published:12 Feb 2026
    6.1
    Medium

    CVE-2025-70849

    Last Modified: 11 Feb 2026

    Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).

    Published:3 Feb 2026
    9.9
    Critical

    CVE-2025-70830

    Last Modified: 15 Apr 2026

    A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

    Published:17 Feb 2026
    5.7
    Medium

    CVE-2025-70829

    Last Modified: 23 Feb 2026

    An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

    Published:17 Feb 2026
    8.8
    High

    CVE-2025-70828

    Last Modified: 3 Apr 2026

    An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

    Published:17 Feb 2026
    5.5
    Medium

    CVE-2025-70795

    Last Modified: 18 Apr 2026

    STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform those actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications. Unauthorized processes load the driver and send a crafted IOCTL request (0xB822200C) to terminate processes protected by a third-party implementation. This action exploits insufficient caller validation in the driver's IOCTL handler, allowing unauthorized processes to perform termination operations in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications.

    Published:17 Apr 2026
    Unknown

    CVE-2025-70600

    https://github.com/gpheheise/CVE-2025-70600---Urve-Smart-Office---Stored-XSS-in-iOS-App

    6.5
    Medium

    CVE-2025-70559

    Last Modified: 15 Apr 2026

    pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

    Published:3 Feb 2026
    6.1
    Medium

    CVE-2025-70545

    Last Modified: 11 Feb 2026

    A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.

    Published:4 Feb 2026
    5.4
    Medium

    CVE-2025-70368

    Last Modified: 13 Feb 2026

    Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An attacker can submit a malicious payload in the Updates text field which is then rendered in the reporting view without proper sanitization. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.

    Published:26 Jan 2026
    6.6
    Medium

    CVE-2025-70342

    Last Modified: 9 Mar 2026

    erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe.

    Published:4 Mar 2026
    7.8
    High

    CVE-2025-70341

    Last Modified: 5 Mar 2026

    Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.

    Published:4 Mar 2026
    4.8
    Medium

    CVE-2025-70336

    Last Modified: 2 Sept 2026

    A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.

    Source:Sahil Arya
    Published:28 Jan 2026
    3.3
    Low

    CVE-2025-70330

    Last Modified: 20 Mar 2026

    Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds memory read during parsing. This results in an unhandled access violation and application crash, leading to a local denial-of-service condition when the crafted file is opened by a user.

    Published:11 Mar 2026
    9.8
    Critical

    CVE-2025-70149

    Last Modified: 8 Sept 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

    Published:18 Feb 2026
    6.1
    Medium

    CVE-2025-69993

    Last Modified: 21 Apr 2026

    Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

    Published:14 Apr 2026
    Items Per Page