Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-58656

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain a leaked JWT token from access logs, proxy logs, browser history, or Referrer headers can create persistent backdoor super-admin accounts and exfiltrate sensitive configuration and user data.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-58655

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or page.header.flex.object.title) to Twig's template_from_string(), causing them to be evaluated as Twig code rather than treated as text. This path bypasses Grav's Security::cleanDangerousTwig() sanitization. A

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-58654

The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType) beginning with 'image/' and does not inspect the actual file content or restrict the resulting extension, allowing an authenticated user to store arbitrary content — including PHP code, SVG with embedded JavaScript, and polyglot payloads — under user/accounts

PUBLISHED
Vendor
Grav
Product
Grav
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58653

PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.

PUBLISHED
Vendor
PraisonAI
Product
PraisonAI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58652

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads the raw UCI 'script' and 'script_args' values and executes the configured path when the captive-portal

PUBLISHED
Vendor
openwrt, openwrt
Product
luci-app-travelmate, travelmate
Provider severity
HIGH
Conflicts
2

CVE-2026-5865

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-58647

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Power BI Report Server
Provider severity
HIGH
Conflicts
0

CVE-2026-58644

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
CRITICAL
Conflicts
1

CVE-2026-58643

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58640

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows 10 Version 21H2, Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2019, Windows 11 version 23H2, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5864

Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58638

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2019, Windows Server 2012, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58637

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2022, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-58636

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft PC Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-58635

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2019, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-58634

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-58633

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-58632

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-58631

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
HIGH
Conflicts
0

CVE-2026-58630

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure App Service for Linux
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5863

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-58629

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows Server 2019, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 11 version 23H2, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-58628

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-58627

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-58626

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2022, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 22H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-58624

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. This GitPgmCommandFactory allowed a user authenticated via SSH to run any JGit command available, including commands tha

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5862

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-58619

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2016, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows Server 2025, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-58618

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot for iOS
Provider severity
HIGH
Conflicts
0

CVE-2026-58614

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58613

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-58610

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-5861

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-58609

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2016, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-58608

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2012
Provider severity
HIGH
Conflicts
2

CVE-2026-58602

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-58601

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 21H2, Windows 11 version 23H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2025, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-5860

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-58598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-58597

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58596

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
HIGH
Conflicts
0

CVE-2026-58595

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Bing Search for iOS
Provider severity
HIGH
Conflicts
0

CVE-2026-58594

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2025, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-58593

NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. In the object mock, attributedTo is used directly as a uid, and actors.assert silently ignores numeric identifiers (filtering them out without re-deriving the uid), so a federated remote actor can set attributedTo to a bare numeric va

PUBLISHED
Vendor
NodeBB
Product
NodeBB
Provider severity
HIGH
Conflicts
2

CVE-2026-58592

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the FunctionType is destroyed, leaving the callback with a dangling reference (the normal instantiate path use

PUBLISHED
Vendor
LadybirdBrowser
Product
Ladybird
Provider severity
HIGH
Conflicts
2

CVE-2026-58591

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.

PUBLISHED
Vendor
Drupal
Product
Colorbox
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58590

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

PUBLISHED
Vendor
Drupal
Product
FlowDrop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5859

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-58589

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

PUBLISHED
Vendor
Drupal
Product
FlowDrop
Provider severity
MEDIUM
Conflicts
0