Thu, Mar 02 · 12:15 PM CSTCVE-2021-3854
9.8/10 · Must read/watchNVDvuln
Summary
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.
CVECVE-2021-3854
SeverityCRITICAL
TypeUPDATED
PublishedThu, Mar 02 · 12:15 PM CST
ModifiedMon, May 18 · 12:16 PM CDT
Fri, Feb 24 · 12:15 PM CSTCVE-2021-4105
9.8/10 · Must read/watchNVDvuln
Summary
Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.
CVECVE-2021-4105
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 24 · 12:15 PM CST
ModifiedMon, May 18 · 01:16 PM CDT
Fri, Feb 18 · 02:15 PM CSTCVE-2022-0664
9.8/10 · Must read/watchNVDvuln
Summary
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
CVECVE-2022-0664
SeverityCRITICAL
TypeUPDATED
PublishedFri, Feb 18 · 02:15 PM CST
ModifiedMon, May 18 · 04:44 PM CDT
Sun, Feb 12 · 04:15 AM CSTCVE-2022-45088
9.8/10 · Must read/watchNVDvuln
Summary
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01.
CVECVE-2022-45088
SeverityCRITICAL
TypeUPDATED
PublishedSun, Feb 12 · 04:15 AM CST
ModifiedMon, May 18 · 04:16 PM CDT
Sun, Feb 12 · 04:15 AM CSTCVE-2022-4557
9.8/10 · Must read/watchNVDvuln
Summary
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
CVECVE-2022-4557
SeverityCRITICAL
TypeUPDATED
PublishedSun, Feb 12 · 04:15 AM CST
ModifiedMon, May 18 · 04:16 PM CDT
Tue, Apr 28 · 04:16 PM CDTCVE-2025-60889
9.8/10 · Must read/watchNVDvuln
Summary
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
CVECVE-2025-60889
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 28 · 04:16 PM CDT
ModifiedMon, May 18 · 06:23 PM CDT
Thu, Mar 05 · 07:16 AM CSTCVE-2026-2743
9.8/10 · Must read/watchNVDvuln
Summary
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before
CVECVE-2026-2743
SeverityCRITICAL
TypeUPDATED
PublishedThu, Mar 05 · 07:16 AM CST
ModifiedMon, May 18 · 05:16 PM CDT
Tue, Apr 21 · 09:16 PM CDTCVE-2026-33518
9.8/10 · Must read/watchNVDvuln
Summary
An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
CVECVE-2026-33518
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 21 · 09:16 PM CDT
ModifiedMon, May 18 · 06:20 PM CDT
Tue, Apr 21 · 09:16 PM CDTCVE-2026-33519
9.8/10 · Must read/watchNVDvuln
Summary
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
CVECVE-2026-33519
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 21 · 09:16 PM CDT
ModifiedMon, May 18 · 06:19 PM CDT
Fri, May 01 · 05:16 PM CDTCVE-2026-37531
9.8/10 · Must read/watchNVDvuln
Summary
AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it onl
CVECVE-2026-37531
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 01 · 05:16 PM CDT
ModifiedMon, May 18 · 05:12 PM CDT
Wed, Apr 29 · 12:16 PM CDTCVE-2026-42248
9.8/10 · Must read/watchNVDvuln
Summary
Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update p
CVECVE-2026-42248
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 29 · 12:16 PM CDT
ModifiedMon, May 18 · 06:22 PM CDT
Wed, Apr 29 · 12:16 PM CDTCVE-2026-42249
9.8/10 · Must read/watchNVDvuln
Summary
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers without validation. These values are passed direct
CVECVE-2026-42249
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 29 · 12:16 PM CDT
ModifiedMon, May 18 · 06:23 PM CDT
Sat, May 09 · 08:16 PM CDTCVE-2026-42257
9.8/10 · Must read/watchNVDvuln
Summary
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain
CVECVE-2026-42257
SeverityCRITICAL
TypeUPDATED
PublishedSat, May 09 · 08:16 PM CDT
ModifiedMon, May 18 · 05:59 PM CDT
Sat, May 09 · 08:16 PM CDTCVE-2026-42258
9.8/10 · Must read/watchNVDvuln
Summary
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0
CVECVE-2026-42258
SeverityCRITICAL
TypeUPDATED
PublishedSat, May 09 · 08:16 PM CDT
ModifiedMon, May 18 · 06:02 PM CDT
Sat, Apr 25 · 06:16 AM CDTCVE-2026-6951
9.8/10 · Must read/watchNVDvuln
Summary
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed t
CVECVE-2026-6951
SeverityCRITICAL
TypeUPDATED
PublishedSat, Apr 25 · 06:16 AM CDT
ModifiedMon, May 18 · 06:20 PM CDT
Fri, May 08 · 11:16 PM CDTCVE-2026-42354
9.1/10 · Must read/watchNVDvuln
Summary
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organiz
CVECVE-2026-42354
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 08 · 11:16 PM CDT
ModifiedMon, May 18 · 02:43 PM CDT
Fri, May 08 · 11:16 PM CDTCVE-2026-42556
8.9/10 · Worth your timeNVDvuln
Summary
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/ ?share=true to another user. The preview page renders that stored HTM
CVECVE-2026-42556
SeverityHIGH
TypeUPDATED
PublishedFri, May 08 · 11:16 PM CDT
ModifiedMon, May 18 · 02:27 PM CDT
Wed, Mar 01 · 08:15 AM CSTCVE-2021-3855
8.8/10 · Worth your timeNVDvuln
Summary
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462.
CVECVE-2021-3855
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 01 · 08:15 AM CST
ModifiedMon, May 18 · 01:16 PM CDT
Fri, Sep 09 · 08:15 PM CDTCVE-2022-36110
8.8/10 · Worth your timeNVDvuln
Summary
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, they can use their auth tokens to run admin-level functions via the API. This prob
CVECVE-2022-36110
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 09 · 08:15 PM CDT
ModifiedMon, May 18 · 04:44 PM CDT
Sun, Feb 12 · 04:15 AM CSTCVE-2022-45089
8.8/10 · Worth your timeNVDvuln
Summary
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
CVECVE-2022-45089
SeverityHIGH
TypeUPDATED
PublishedSun, Feb 12 · 04:15 AM CST
ModifiedMon, May 18 · 04:16 PM CDT
Sun, Feb 12 · 04:15 AM CSTCVE-2022-45090
8.8/10 · Worth your timeNVDvuln
Summary
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
CVECVE-2022-45090
SeverityHIGH
TypeUPDATED
PublishedSun, Feb 12 · 04:15 AM CST
ModifiedMon, May 18 · 04:16 PM CDT
Thu, Aug 24 · 11:15 PM CDTCVE-2023-32079
8.8/10 · Worth your timeNVDvuln
Summary
Netmaker makes networks with WireGuard. A Mass assignment vulnerability was found in versions prior to 0.17.1 and 0.18.6 that allows a non-admin user to escalate privileges to those of an admin user. The issue is patched in 0.17.1 and fixed in 0.18.6. If Users are using 0.17.1, they should run `docker pull gravitl/netm
CVECVE-2023-32079
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 24 · 11:15 PM CDT
ModifiedMon, May 18 · 04:44 PM CDT
Fri, May 08 · 10:16 PM CDTCVE-2026-41486
8.8/10 · Worth your timeNVDvuln
Summary
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_shaped_tensor) globally in PyArrow. When PyArrow reads a Parquet file containing one of these extension types, it calls __a
CVECVE-2026-41486
SeverityHIGH
TypeUPDATED
PublishedFri, May 08 · 10:16 PM CDT
ModifiedMon, May 18 · 06:30 PM CDT
Thu, Jan 27 · 01:15 PM CSTCVE-2021-44793
8.6/10 · Worth your timeNVDvuln
Summary
Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive inform
CVECVE-2021-44793
SeverityHIGH
TypeUPDATED
PublishedThu, Jan 27 · 01:15 PM CST
ModifiedMon, May 18 · 01:16 PM CDT
Thu, Mar 26 · 09:17 PM CDTCVE-2026-0966
8.2/10 · Worth your timeNVDvuln
Summary
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_P
CVECVE-2026-0966
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 26 · 09:17 PM CDT
ModifiedTue, May 19 · 10:16 AM CDT