Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-60094

Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.

PUBLISHED
Vendor
Vinchin
Product
Backup & Recovery 9.0
Provider severity
MEDIUM
Conflicts
1

CVE-2026-60092

AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin's getMeetInfo.json.php endpoint. When a participant joins a public meeting, the raw HTTP User-Agent header is stored (meet_join_log.user_agent) without sanitization (bypassing AVideo's setter-level xss_esc() layer) and later echoed without output encoding (no htmlspecialchars()) in the Participants management panel, which is accessible to the meetin

PUBLISHED
Vendor
AVideo
Product
AVideo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-60091

PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-60090

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
CRITICAL
Conflicts
1

CVE-2026-6009

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system

PUBLISHED
Vendor
Jaspersoft, Jaspersoft, Jaspersoft, Jaspersoft, Jaspersoft, Jaspersoft, Jaspersoft, Jaspersoft
Product
Jaspersoft Studio Professional, JasperReports Library Professional, JasperReports Web Studio, JasperReports Server, JasperReports Library Community Edition, JasperReports IO At-Scale, Jaspersoft Studio Community Edition, JasperReports IO Professional
Provider severity
HIGH
Conflicts
1

CVE-2026-60089

PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the developer subsequently calls agent.start() without explicitly passing an output parameter, PraisonAI writes the agent response to that path (creating parent directories as needed),

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-60088

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-60087

PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-60086

PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-60085

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
HIGH
Conflicts
1

CVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method.

PUBLISHED
Vendor
HMBRAND
Product
DBI
Provider severity
CRITICAL
Conflicts
0

CVE-2026-60081

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.

PUBLISHED
Vendor
HMBRAND
Product
DBI::ProfileData
Provider severity
HIGH
Conflicts
0

CVE-2026-60080

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Fory
Provider severity
HIGH
Conflicts
0

CVE-2026-6008

Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0.

PUBLISHED
Vendor
Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co.
Product
DijiDemi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-60075

Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the r

PUBLISHED
Vendor
SBECK
Product
Date::Manip
Provider severity
HIGH
Conflicts
0

CVE-2026-60074

Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numi

PUBLISHED
Vendor
SBECK
Product
Date::Manip
Provider severity
HIGH
Conflicts
0

CVE-2026-60073

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a system crash or disclosure of kernel memory.

PUBLISHED
Vendor
AutomationDirect
Product
Productivity Suite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6007

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
Construction Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-60065

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This vulnerability may allow remote unauthenticated attackers to have limited control to restart the NGINX worker process. There is no control plane exposure; this is a data plane issue

PUBLISHED
Vendor
F5
Product
NGINX Plus
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-60063

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability.

PUBLISHED
Vendor
AutomationDirect
Product
Productivity Suite
Provider severity
HIGH
Conflicts
1

CVE-2026-60062

The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A successful exploit may allow an attacker to cross a security boundary. Impact: A remotely authenticated low-privileged attacker could gain limited read and write access outside of the list of directories specified in the NGINX Age

PUBLISHED
Vendor
F5, F5
Product
NGINX Agent, NGINX Instance Manager
Provider severity
MEDIUM
Conflicts
2

CVE-2026-60060

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.

PUBLISHED
Vendor
TeraTerm Project
Product
TTSSH2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6006

A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Patient Record Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-6005

A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
code-projects
Product
Patient Record Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-6004

A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument cat_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple IT Discussion Forum
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-60034

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.

PUBLISHED
Vendor
themexpert.com
Product
JMedia extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-60033

Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.

PUBLISHED
Vendor
themexpert.com
Product
JMedia extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-60032

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.

PUBLISHED
Vendor
themexpert.com
Product
JMedia extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-60031

Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

PUBLISHED
Vendor
themexpert.com
Product
Quix Page Builder Pro extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-60030

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissions.

PUBLISHED
Vendor
themexpert.com
Product
Quix Page Builder Pro extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-6003

A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple IT Discussion Forum
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-60029

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

PUBLISHED
Vendor
themexpert.com
Product
Quix Page Builder Pro extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-60028

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder user could inject scripts, fires for any visitor or admin viewing the page. Unescaped output + unsanitised SVG.

PUBLISHED
Vendor
themexpert.com
Product
Quix Page Builder Pro extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-60027

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files. Requires a published page with a Form element.

PUBLISHED
Vendor
themexpert.com
Product
Quix Page Builder Pro extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-60026

Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requires caching on (default).

PUBLISHED
Vendor
themexpert.com
Product
Quix Page Builder Pro extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-60025

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

PUBLISHED
Vendor
joomdonation.com
Product
Events Booking extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-60024

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

PUBLISHED
Vendor
joomdonation.com
Product
Events Booking extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-6002

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

PUBLISHED
Vendor
DivvyDrive Information Technologies Inc.
Product
DivvyDrive
Provider severity
HIGH
Conflicts
0

CVE-2026-60011

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

PUBLISHED
Vendor
Sharp Corporation, Toshiba Tec Corporation
Product
Sharp MFPs, Toshiba Tec MFPs
Provider severity
MEDIUM
Conflicts
2

CVE-2026-6001

Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042.

PUBLISHED
Vendor
ABIS Technology Ltd. Co.
Product
BAPSİS
Provider severity
HIGH
Conflicts
0

CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or re

PUBLISHED
Vendor
F5, F5
Product
NGINX Plus, NGINX Open Source
Provider severity
HIGH
Conflicts
2

CVE-2026-60002

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
HIGH
Conflicts
0

CVE-2026-60001

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
MEDIUM
Conflicts
0

CVE-2026-60000

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
LOW
Conflicts
0

CVE-2026-6000

A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Online Library Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-59999

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59998

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59997

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59996

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59995

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

PUBLISHED
Vendor
OpenBSD
Product
OpenSSH
Provider severity
MEDIUM
Conflicts
0