vulnti.work

Vulnerability list

Filter public vulnerability entries by severity / channel / vendor / time.

Clear
Drupal Core SQL Injection Vulnerability
Critical KEV

CVE-2026-9082 · 2026-07-14 · pending_review

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Google Dawn Use-After-Free Vulnerability
High KEV

CVE-2026-5281 · 2026-07-14 · pending_review

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple…

Check Point Security Gateway Improper Authentication Vulnerability
Critical KEV

CVE-2026-50751 · 2026-07-14 · pending_review

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN con…

SimpleHelp Authentication Bypass Vulnerability
High KEV

CVE-2026-48558 · 2026-07-14 · pending_review

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographi…

Adobe ColdFusion Path Traversal Vulnerability
High KEV

CVE-2026-48282 · 2026-07-14 · pending_review

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
High KEV

CVE-2026-48172 · 2026-07-14 · pending_review

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

Nx Console Embedded Malicious Code Vulnerability
High KEV

CVE-2026-48027 · 2026-07-14 · pending_review

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from m…

TanStack Unspecified Vulnerability
High KEV

CVE-2026-45321 · 2026-07-14 · pending_review

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

Microsoft Exchange Server Cross-Site Scripting Vulnerability
High KEV

CVE-2026-42897 · 2026-07-14 · pending_review

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browse…

BerriAI LiteLLM Command Injection Vulnerability
High KEV

CVE-2026-42271 · 2026-07-14 · pending_review

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

BerriAI LiteLLM SQL Injection Vulnerability
High KEV

CVE-2026-42208 · 2026-07-14 · pending_review

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Marimo Remote Code Execution Vulnerability
Critical KEV

CVE-2026-39987 · 2026-07-14 · pending_review

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Google Skia Out-of-Bounds Write Vulnerability
High KEV

CVE-2026-3909 · 2026-07-14 · pending_review

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android,…

TrueConf Client Download of Code Without Integrity Check Vulnerability
High KEV

CVE-2026-3502 · 2026-07-14 · pending_review

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or ins…

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
High KEV

CVE-2026-34926 · 2026-07-14 · pending_review

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affec…

Ubiquiti UniFi OS Path Traversal Vulnerability
High KEV

CVE-2026-34909 · 2026-07-14 · pending_review

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

Ubiquiti UniFi OS Improper Access Control Vulnerability
High KEV

CVE-2026-34908 · 2026-07-14 · pending_review

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

Aquasecurity Trivy Embedded Malicious Code Vulnerability
High KEV

CVE-2026-33634 · 2026-07-14 · pending_review

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwor…

Langflow Code Injection Vulnerability
Critical KEV

CVE-2026-33017 · 2026-07-14 · pending_review

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

Citrix NetScaler Out-of-Bounds Read Vulnerability
High KEV

CVE-2026-3055 · 2026-07-14 · pending_review

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overre…

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
High KEV

CVE-2026-28318 · 2026-07-14 · pending_review

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

Google Chromium CSS Use-After-Free Vulnerability
High KEV

CVE-2026-2441 · 2026-07-14 · pending_review

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that ut…

Next page →