CVE Tracker
Vulnerabilities in the news. Explore recent activity, known exploitation, severity, and EPSS.
Flowise is a drag & drop user interface to build a customized large language model flow.
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
In Contacts Provider, there is a possible way to access the contacts database due to SQL injection.
N-able N-central Static Code Injection Vulnerability
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library.
MapLibre GL JS is an interactive vector tile map library for web browsers.
Metabase SQL Injection Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Palo Alto Networks PAN-OS Command Injection Vulnerability
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrati
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform.
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform.
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform.
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command In
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injec
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal sec
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive intern
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive intern
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attack
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product.
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking s
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed).
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported.
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business.
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may al
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation.
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrar
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could res
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, whic
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Ivanti Sentry OS Command Injection Vulnerability
A vulnerability has been identified in Opcenter X (All versions < V2604).
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Adobe ColdFusion Path Traversal Vulnerability
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns c
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
Joomlack Page Builder Improper Access Control Vulnerability
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Inje
SimpleHelp Authentication Bypass Vulnerability
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, messag