Trending Vulnerabilities
The most severe recently published CVEs — CVSS 7.0 and above, ranked by score and recency.
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the fi
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue af
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authenticat
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Tal
A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability fo
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Pro
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the functio
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbi
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session
In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segment
In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adju
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a ne
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of th
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function st
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_ur
In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircui
In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrup
In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/octeontx - fix DMA cleanup using wr
In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong lo
In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main t
In the Linux kernel, the following vulnerability has been resolved: geneve: gate GRO hint in geneve_gro_complete() on g
In the Linux kernel, the following vulnerability has been resolved: geneve: validate inner network offset in geneve_gro
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that a
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vul
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backl
Stay Ahead of Threats
CyberStrike continuously monitors for trending vulnerabilities and scans your infrastructure automatically.
Get Started