Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-57925

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

PUBLISHED
Vendor
JetBrains
Product
YouTrack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

PUBLISHED
Vendor
JetBrains
Product
YouTrack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57923

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

PUBLISHED
Vendor
JetBrains
Product
YouTrack
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57922

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

PUBLISHED
Vendor
JetBrains
Product
YouTrack
Provider severity
LOW
Conflicts
0

CVE-2026-57921

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

PUBLISHED
Vendor
JetBrains
Product
YouTrack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57920

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

PUBLISHED
Vendor
Peplink
Product
InControl
Provider severity
HIGH
Conflicts
0

CVE-2026-5792

Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026.

PUBLISHED
Vendor
Hedef Media Promotion Interactive Media Marketing Inc.
Product
Related Marketing Cloud (RMC)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57919

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of arbitrary commands with SYSTEM privileges via an untrusted search path. This allows privilege escalation by placing a malicious shadow.exe in a controlled working directory.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2026-57918

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.

PUBLISHED
Vendor
sahlberg
Product
libnfs
Provider severity
HIGH
Conflicts
0

CVE-2026-57917

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.

PUBLISHED
Vendor
Asseco
Product
proCertum SmartSign
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57916

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.

PUBLISHED
Vendor
Asseco
Product
proCertum SmartSign
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

PUBLISHED
Vendor
Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform Expansion Pack, Apache Kerby, streams for Apache Kafka 2, Red Hat Data Grid 8, Red Hat AMQ Clients, Red Hat JBoss Enterprise Application Platform Expansion Pack, streams for Apache Kafka 3, Red Hat Fuse 7, Red Hat Data Grid 8
Provider severity
HIGH
Conflicts
2

CVE-2026-57914

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Kerby
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57913

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

PUBLISHED
Vendor
Johnson & Johnson
Product
Audit Tracking Management System
Provider severity
HIGH
Conflicts
0

CVE-2026-57912

Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.

PUBLISHED
Vendor
Johnson & Johnson
Product
Campus Recruiting
Provider severity
HIGH
Conflicts
0

CVE-2026-5791

Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

PUBLISHED
Vendor
DivvyDrive Information Technologies Inc.
Product
DivvyDrive
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5790

Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or administrators access the affected sections, the code executes in their browsers, enabling the theft of session cookies and account hijacking.

PUBLISHED
Vendor
Stel Order
Product
Stel Order
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57898

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated a

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse BaSyx - Java Server SDK
Provider severity
CRITICAL
Conflicts
1

CVE-2026-57896

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could lead to limited information disclosure or disruption of the affected product.

PUBLISHED
Vendor
AutomationDirect
Product
Productivity Suite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57895

Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folder, which results in arbitrary code execution with SYSTEM privilege

PUBLISHED
Vendor
Fuji Electric Co.,Ltd.
Product
Pupsman
Provider severity
HIGH
Conflicts
1

CVE-2026-5789

Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration.

PUBLISHED
Vendor
CivetWeb
Product
CivetWeb
Provider severity
HIGH
Conflicts
0

CVE-2026-57881

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this vulnerability by sending crafted login data with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57880

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this vulnerability by sending a crafted RTSP request containing overly long authentication data, resulting in memory corruption, denial of service, or potentially arbitrary code execution.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5788

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

PUBLISHED
Vendor
Ivanti
Product
Endpoint Manager Mobile
Provider severity
HIGH
Conflicts
0

CVE-2026-57879

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this vulnerability by sending a crafted RTSP request, resulting in memory corruption, denial of service, or potentially arbitrary code execution.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57878

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by sending a crafted HTTP request with overly long input, resulting in memory corruption, denial of service, or potentially arbitrary code execution.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57877

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
HIGH
Conflicts
0

CVE-2026-57876

An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing HTTP request body data. A remote attacker may exploit this vulnerability by sending a crafted request with excessive input, causing memory corruption and resulting in a denial of service.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
HIGH
Conflicts
0

CVE-2026-57875

An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A remote attacker may exploit this vulnerability by sending a specially crafted HTTP request, causing the affected process to crash and resulting in a denial of service.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
HIGH
Conflicts
0

CVE-2026-57874

An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a crafted upload request with overly long input, causing memory corruption and resulting in a denial of service.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
HIGH
Conflicts
0

CVE-2026-57873

An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this vulnerability by sending a malformed multipart request, causing the affected CGI process to crash and resulting in a denial of service.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
HIGH
Conflicts
0

CVE-2026-57872

An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this vulnerability by sending a crafted request to read arbitrary files accessible to the affected process, resulting in information disclosure.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPCLPC2011/2211
Provider severity
HIGH
Conflicts
0

CVE-2026-57871

Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.

PUBLISHED
Vendor
MicroRealEstate
Product
MicroRealEstate
Provider severity
HIGH
Conflicts
0

CVE-2026-57870

Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.

PUBLISHED
Vendor
MicroRealEstate
Product
MicroRealEstate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5787

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

PUBLISHED
Vendor
Ivanti
Product
Endpoint Manager Mobile
Provider severity
HIGH
Conflicts
0

CVE-2026-57869

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.

PUBLISHED
Vendor
MicroRealEstate
Product
MicroRealEstate
Provider severity
HIGH
Conflicts
1

CVE-2026-57868

MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.

PUBLISHED
Vendor
MicroRealEstate
Product
MicroRealEstate
Provider severity
HIGH
Conflicts
0

CVE-2026-57867

MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.

PUBLISHED
Vendor
MicroRealEstate
Product
MicroRealEstate
Provider severity
HIGH
Conflicts
0

CVE-2026-57862

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation feature, causing cURL to resolve and connect to internal network resources such as cloud instance metadata services, localhost services, and RFC1918 addresses while the isPrivateURL() filter in app/C

PUBLISHED
Vendor
Kanboard
Product
Kanboard
Provider severity
HIGH
Conflicts
1

CVE-2026-57860

ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json whose mcpServers entries specify arbitrary command and args values (for example, command: bash with args: ['-c', 'touch /tmp/pwned']). When a user runs the forge CLI inside a cloned untrusted repository, the specified commands are spawned with the invoking

PUBLISHED
Vendor
tailcallhq
Product
forgecode
Provider severity
HIGH
Conflicts
1

CVE-2026-5786

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

PUBLISHED
Vendor
Ivanti
Product
Endpoint Manager Mobile
Provider severity
HIGH
Conflicts
0

CVE-2026-57859

e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The e_array::unserialize() function in e107_handlers/core_functions.php performs only a prefix check for the string 'array' before passing the stored value to eval(), causing automatic PHP execution whenever the affected user's preferences are m

PUBLISHED
Vendor
e107inc
Product
e107
Provider severity
HIGH
Conflicts
1

CVE-2026-57857

The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in flowpayment-fl.php (lines 57-58) without input sanitization (for example sanitize_text_field()) or output escaping (for example esc_html()) before being rendered in the checkout notice HTML. An unauthenticated attacker can craft a URL c

PUBLISHED
Vendor
Flow
Product
Flow Payment
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57856

Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', $bucket), which permits '..' and '../' sequences. The sanitized value is interpolated into a Flysystem path as uploads://buckets/{bucket}. Flysystem's WhitespacePathNormalizer resolves 'buckets/..' to the empty string (the uploads storage root) without raising PathT

PUBLISHED
Vendor
Cockpit HQ
Product
Cockpit CMS
Provider severity
HIGH
Conflicts
1

CVE-2026-57855

Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including buckets intended for admin use only.

PUBLISHED
Vendor
Cockpit HQ
Product
Cockpit CMS
Provider severity
HIGH
Conflicts
1

CVE-2026-57852

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook endpoint to execute all configured scheduled jobs or target a specific job, causing unintended execution of operator-defined commands under the web server process user.

PUBLISHED
Vendor
Trilby Media
Product
Grav CMS scheduler-webhook plugin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57851

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable

PUBLISHED
Vendor
Micro-Star International (MSI)
Product
KernCoreLib64.sys
Provider severity
HIGH
Conflicts
1

CVE-2026-57850

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given.

PUBLISHED
Vendor
RustDesk
Product
RustDesk
Provider severity
HIGH
Conflicts
1

CVE-2026-5785

Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.

PUBLISHED
Vendor
Zohocorp, Zohocorp
Product
ManageEngine Password Manager Pro, ManageEngine PAM360
Provider severity
HIGH
Conflicts
1

CVE-2026-57848

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent.extra.STREAM extra. The activity does not validate or filter the incoming URI before using it as the outgoing attachment, so a caller can pass a file:// URI pointing at the application's own internal storage (for example /data/data/chat.revolt/databases/revolt

PUBLISHED
Vendor
stoatchat
Product
Stoat for Android
Provider severity
MEDIUM
Conflicts
1