Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-58588

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.

PUBLISHED
Vendor
Drupal
Product
Drupal Canvas
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58587

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.

PUBLISHED
Vendor
Drupal
Product
Drupal Canvas
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58586

Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.

PUBLISHED
Vendor
ZAPAD
Product
Image::WebP
Provider severity
CRITICAL
Conflicts
0

CVE-2026-58583

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Windows 11 25H2 HLK (Hardware Lab Kit). The fixed driver may be available through Windows Update or from Lenovo directly.

PUBLISHED
Vendor
FluxInk
Product
Color Management Driver
Provider severity
HIGH
Conflicts
1

CVE-2026-58580

LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the userId scope that sibling methods apply, and findMessagePlugin reads back by id alone. Reachable via the corresponding tRPC message procedures, an authenticated user who knows another user's message identifier can overwrite th

PUBLISHED
Vendor
lobehub
Product
lobehub
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5858

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-58579

RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then renders that name into the "Rerun from current step" confirmation modal via dangerouslySetInnerHTML, and the i18next configuration sets escapeValue:false, so the value is inserted into the DOM without HTML encoding. An au

PUBLISHED
Vendor
infiniflow
Product
ragflow
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58578

LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop by supplying a catastrophic-backtracking pattern in a GitHub repository URL path during skill import. Attackers can craft a malicious basePath value containing unescaped regex metacharacters such as catastrophic-backtracking patterns, which are injected into a dynamically constructed regular expression in the findSkillM

PUBLISHED
Vendor
lobehub
Product
lobehub
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-58559

DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei, Huawei
Product
Harmony OS, EMUI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58558

Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
Harmony OS, EMUI
Provider severity
HIGH
Conflicts
1

CVE-2026-58557

Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58556

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei, Huawei
Product
Harmony OS, EMUI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58555

Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58554

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
EMUI, HarmonyOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58553

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58552

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58551

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58550

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58549

Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58547

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2019, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58546

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2025, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58545

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58544

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-58543

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2025
Provider severity
MEDIUM
Conflicts
2

CVE-2026-58542

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-58541

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2019, Windows Server 2022, Windows 10 Version 1809, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-58540

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2016, Windows 10 Version 1809, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-5854

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument merge results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Totolink
Product
A7100RU
Provider severity
CRITICAL
Conflicts
2

CVE-2026-58539

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2012, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58538

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2019, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-58537

Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-58536

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2022, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-58535

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2016 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58534

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 1809, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-58533

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58532

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 10 Version 1607, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-58531

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2019, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2016, Windows Server 2025, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-58530

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2022, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-5853

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument addrPrefixLen leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
Totolink
Product
A7100RU
Provider severity
CRITICAL
Conflicts
2

CVE-2026-58529

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-58528

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 22H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-58527

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 Version 25H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-58526

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
2

CVE-2026-58525

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
HIGH
Conflicts
0

CVE-2026-58524

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58523

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58522

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58521

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - Cargo Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-58520

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.

PUBLISHED
Vendor
The Wikimedia Foundation
Product
Mediawiki - UrlShortener Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5852

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument igmpVer causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Totolink
Product
A7100RU
Provider severity
CRITICAL
Conflicts
2