Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-5965

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

PUBLISHED
Vendor
NewSoft
Product
NewSoftOA
Provider severity
CRITICAL
Conflicts
1

CVE-2026-59649

In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-FJA, BC-JAVA, BC-LTS-JAVA
Provider severity
HIGH
Conflicts
1

CVE-2026-59648

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-JAVA, BC-FJA, BC-LTS-JAVA
Provider severity
MEDIUM
Conflicts
1

CVE-2026-59647

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-LTS-JAVA, BC-FJA, BC-JAVA
Provider severity
MEDIUM
Conflicts
1

CVE-2026-59646

In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-FJA, BC-JAVA, BC-LTS-JAVA
Provider severity
HIGH
Conflicts
1

CVE-2026-59645

In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-FJA, BC-LTS-JAVA, BC-JAVA
Provider severity
HIGH
Conflicts
1

CVE-2026-59644

In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
Provider severity
HIGH
Conflicts
0

CVE-2026-59643

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-FJA, BC-JAVA
Provider severity
HIGH
Conflicts
1

CVE-2026-59642

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-LTS-JAVA, BC-FJA, BC-JAVA
Provider severity
HIGH
Conflicts
1

CVE-2026-59641

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-JAVA, BC-LTS-JAVA, BC-FJA, BC-FJA
Provider severity
HIGH
Conflicts
1

CVE-2026-59640

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-JAVA, BC-LTS-JAVA, BC-FJA
Provider severity
HIGH
Conflicts
1

CVE-2026-5964

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

PUBLISHED
Vendor
Digiwin
Product
EasyFlow .NET
Provider severity
CRITICAL
Conflicts
1

CVE-2026-59639

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-JAVA, BC-FJA, BC-LTS-JAVA
Provider severity
HIGH
Conflicts
1

CVE-2026-59638

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-JAVA, BC-LTS-JAVA, BC-FJA
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5963

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

PUBLISHED
Vendor
Digiwin
Product
EasyFlow .NET
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5962

A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Tenda
Product
CH22
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-5961

A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects unknown code of the file /topic-details.php. The manipulation of the argument post_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple IT Discussion Forum
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-5960

A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
code-projects
Product
Patient Record Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-5959

A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 1.8.2 can resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted

PUBLISHED
Vendor
GL.iNet, GL.iNet, GL.iNet, GL.iNet
Product
GL-RM10RC, GL-RM10, GL-RM1, GL-RM1PE
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-5958

When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: 1. resolves symlink to its target and stores the resolved path for determining when output is written, 2. opens the original symlink path (not the resolved one) to read the file. Between these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed

PUBLISHED
Vendor
GNU
Product
Sed
Provider severity
LOW
Conflicts
0

CVE-2026-5957

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is called on the allowed base directory (wp-content/uploads/emailkit/templates/) which may not exist, causing it to return false. In PHP 8.x, strpos($real_path, false) implicitly converts false to an empty string, and strpos() with an empty needle always returns

PUBLISHED
Vendor
roxnor
Product
EmailKit – Email Customizer for WooCommerce & WP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59560

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

PUBLISHED
Vendor
Roxnor
Product
FundEngine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59559

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

PUBLISHED
Vendor
themewant
Product
RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59558

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

PUBLISHED
Vendor
wpdevelop
Product
Booking Calendar
Provider severity
HIGH
Conflicts
0

CVE-2026-59557

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

PUBLISHED
Vendor
Franky
Product
Events Made Easy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-59556

Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.

PUBLISHED
Vendor
acowebs
Product
Dynamic Pricing With Discount Rules for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-59555

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

PUBLISHED
Vendor
Roland Barker
Product
Participants Database
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59554

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

PUBLISHED
Vendor
Ziina
Product
Ziina
Provider severity
HIGH
Conflicts
0

CVE-2026-59553

Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.

PUBLISHED
Vendor
RexTheme
Product
Product Feed Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-59552

Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.

PUBLISHED
Vendor
Shahadat Hossain
Product
3D Flipbook PDF Viewer &amp; Embedder
Provider severity
HIGH
Conflicts
0

CVE-2026-59551

Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

PUBLISHED
Vendor
rtCamp
Product
rtMedia for WordPress, BuddyPress and bbPress
Provider severity
HIGH
Conflicts
0

CVE-2026-59550

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

PUBLISHED
Vendor
Strategy11 Team
Product
AWP Classifieds
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.

PUBLISHED
Vendor
Inrove Software and Internet Services
Product
BiEticaret
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59549

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

PUBLISHED
Vendor
rtCamp
Product
rtMedia for WordPress, BuddyPress and bbPress
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59548

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.

PUBLISHED
Vendor
Byteflows
Product
Byteflows Travel &amp; Hotel Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-59547

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

PUBLISHED
Vendor
Easy Payment
Product
Payment Gateway for PayPal on WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-59546

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

PUBLISHED
Vendor
John Darrel
Product
Hide My WP Ghost
Provider severity
HIGH
Conflicts
0

CVE-2026-59545

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

PUBLISHED
Vendor
miniOrange
Product
miniOrange Discord Integration
Provider severity
HIGH
Conflicts
0

CVE-2026-59544

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

PUBLISHED
Vendor
Thrive Themes Coupon
Product
Thrive Quiz Builder
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59543

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

PUBLISHED
Vendor
WPLake
Product
Advanced Views
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59542

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

PUBLISHED
Vendor
WP Chill
Product
Kali Forms
Provider severity
HIGH
Conflicts
0

CVE-2026-59541

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

PUBLISHED
Vendor
Hakan Ozevin
Product
WP BASE Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-59540

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

PUBLISHED
Vendor
Cozy Vision Technologies Pvt. Ltd.
Product
SMS Alert Order Notifications
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59539

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

PUBLISHED
Vendor
Cozmoslabs
Product
Paid Member Subscriptions
Provider severity
HIGH
Conflicts
0

CVE-2026-59538

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

PUBLISHED
Vendor
Ruben Garcia
Product
GamiPress
Provider severity
CRITICAL
Conflicts
0

CVE-2026-59537

Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.

PUBLISHED
Vendor
Sender
Product
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-59536

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

PUBLISHED
Vendor
CoCart Headless
Product
CoCart – Headless ecommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-59535

Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

PUBLISHED
Vendor
Thrive Themes Coupon
Product
Thrive Product Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-59534

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

PUBLISHED
Vendor
Aurovrata Venet
Product
Post My CF7 Form
Provider severity
HIGH
Conflicts
0

CVE-2026-59533

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

PUBLISHED
Vendor
Christoph Vielgrader
Product
Relevanssi Light
Provider severity
CRITICAL
Conflicts
0