Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-57633

Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

PUBLISHED
Vendor
WCBoost
Product
WCBoost &#8211; Products Compare
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57632

Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

PUBLISHED
Vendor
Omnisend
Product
Email Marketing for WooCommerce by Omnisend
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57631

Administrator SQL Injection in Popup box <= 6.0.1 versions.

PUBLISHED
Vendor
Ays Pro
Product
Popup box
Provider severity
HIGH
Conflicts
0

CVE-2026-57630

Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.

PUBLISHED
Vendor
Creative Themes
Product
Blocksy Companion Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57629

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

PUBLISHED
Vendor
StatCounter
Product
StatCounter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57628

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

PUBLISHED
Vendor
WP All Import
Product
WP All Import
Provider severity
HIGH
Conflicts
0

CVE-2026-57627

Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

PUBLISHED
Vendor
Themeum
Product
Kirki
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57626

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.

PUBLISHED
Vendor
MailPoet
Product
MailPoet
Provider severity
HIGH
Conflicts
0

CVE-2026-57625

Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.

PUBLISHED
Vendor
ASE
Product
Admin and Site Enhancements (ASE) Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57624

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

PUBLISHED
Vendor
Creative Themes
Product
Blocksy Companion Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57623

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

PUBLISHED
Vendor
BoldGrid
Product
W3 Total Cache
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57622

Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

PUBLISHED
Vendor
Arraytics
Product
WPCafe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57621

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

PUBLISHED
Vendor
Arraytics
Product
Booktics
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.8.

PUBLISHED
Vendor
Tim Strifler
Product
Exclusive Addons Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5762

Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.

PUBLISHED
Vendor
Wikimedia Foundation
Product
MediaWiki - ReportIncident Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57619

Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.

PUBLISHED
Vendor
Elementor
Product
Elementor Website Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57618

Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

PUBLISHED
Vendor
Themeisle
Product
Neve PRO
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57617

Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

PUBLISHED
Vendor
SeedProd LLC.
Product
SeedProd Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57600

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

PUBLISHED
Vendor
Hikvision, Hikvision, Hikvision, Hikvision
Product
DS-2TD Series, DS-2DE Series, DS-2DP Series, DS-2CD Series
Provider severity
HIGH
Conflicts
1

CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
CRITICAL
Conflicts
1

CVE-2026-57599

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

PUBLISHED
Vendor
Hikvision
Product
DS-2CD Series
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57589

sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

PUBLISHED
Vendor
OpenBSD
Product
OpenBSD
Provider severity
HIGH
Conflicts
0

CVE-2026-57588

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

PUBLISHED
Vendor
tenable
Product
Nessus
Provider severity
LOW
Conflicts
1

CVE-2026-57587

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

PUBLISHED
Vendor
tenable
Product
Nessus
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-57585

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

PUBLISHED
Vendor
msgpack
Product
msgpack-python
Provider severity
HIGH
Conflicts
0

CVE-2026-57584

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same construct is produced by the /:params placeholder and the CLI router. Phalcon\Mvc\Router::handle() matches this pattern against the attacker-controlled request URI on every request, so a crafted path such as one containing repeated slashes followed by decoded new

PUBLISHED
Vendor
phalcon
Product
cphalcon
Provider severity
HIGH
Conflicts
0

CVE-2026-5758

JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.

PUBLISHED
Vendor
Mafintosh
Product
Protocol-buffers-schema parser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57575

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Forgery (SSRF) vulnerability in URL preview functionality in UrlPreviewService. Due to missing network restrictions before establishing outbound connections, a remote attacker can cause the Misskey server to initiate HTTP requests to loopback, private, or link-local services. Because IP address validation takes place after the request has been sent and the process is subsequently

PUBLISHED
Vendor
misskey-dev
Product
misskey
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57574

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows the reuse of a single-use code within its valid time step. If both credentials and a TOTP code are obtained concurrently, an attacker may reuse the code to perform unauthorized actions, potentially leading to account takeover. This issue is fixed in version 2026.

PUBLISHED
Vendor
misskey-dev
Product
misskey
Provider severity
HIGH
Conflicts
0

CVE-2026-57573

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a remote unauthenticated client to call POST /crawl/stream or POST /crawl with crawler_config.stream=true with a URL pointing at an internal, private, or link-local address; the server fet

PUBLISHED
Vendor
unclecode
Product
crawl4ai
Provider severity
HIGH
Conflicts
0

CVE-2026-57572

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request yields arbitrary com

PUBLISHED
Vendor
unclecode
Product
crawl4ai
Provider severity
CRITICAL
Conflicts
1

CVE-2026-57571

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path use

PUBLISHED
Vendor
unclecode
Product
crawl4ai
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5757

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.

PUBLISHED
Vendor
Ollama AI
Product
Ollama
Provider severity
HIGH
Conflicts
1

CVE-2026-5756

Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.

PUBLISHED
Vendor
Data Recognition Corporation
Product
Central Office Services - Content Hosting Component
Provider severity
HIGH
Conflicts
1

CVE-2026-5755

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file upload or posting permissions to cause a denial of service (server OOM) via uploading a crafted TIFF file or posting a URL that serves one.. Mattermost Advisory ID: MMSA-2026-00648

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5754

Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.

PUBLISHED
Vendor
Radware
Product
Alteon vADC
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57536

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

PUBLISHED
Vendor
pretix
Product
pretix-mollie
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57535

Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information about the rendering server and possibly creating an SSRF vector in the local network.

PUBLISHED
Vendor
pretix
Product
pretix
Provider severity
LOW
Conflicts
0

CVE-2026-57534

Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.

PUBLISHED
Vendor
pretix
Product
pretix-pages
Provider severity
LOW
Conflicts
0

CVE-2026-57533

Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes.

PUBLISHED
Vendor
pretix
Product
pretix
Provider severity
LOW
Conflicts
0

CVE-2026-57532

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements of the PDF rendering and editing libraries used, this is one of the few pages in our backend that do not have a strong Content-Security-Policy that would render this capability useless for most scenarios.

PUBLISHED
Vendor
pretix
Product
pretix
Provider severity
HIGH
Conflicts
0

CVE-2026-57531

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's origin by causing a victim to paste attacker-controlled content. The parseDOM.getAttrs handler stores raw innerHTML of pasted span elements with data-type="emoji" without sanitization, and the toMarkdown runner subsequently assigns this unsanitized value directly to a live DOM element's inner

PUBLISHED
Vendor
Milkdown
Product
milkdown
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57530

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The parseMarkdown runner stores raw URL values from the remark AST as href mark attributes without URL scheme validation, and the ineffective DOMPurify.sanitize call in edit-view.ts treats

PUBLISHED
Vendor
Milkdown
Product
milkdown
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5753

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email a

PUBLISHED
Vendor
servmask
Product
All-in-One WP Migration Unlimited Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57527

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing

PUBLISHED
Vendor
zaproxy
Product
zap-extensions
Provider severity
HIGH
Conflicts
1

CVE-2026-57522

Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration whose template references a user-controlled token (such as #ActingUserName# or #UserName#, populated from a member's display name), an authenticated member can set their display name to JSON metacharacters and inject arbitra

PUBLISHED
Vendor
bitwarden
Product
server
Provider severity
LOW
Conflicts
1

CVE-2026-57521

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization checks. Attackers can exploit the missing ManageOrganizationBillingRequirement on the preview invoice endpoints to retrieve Stripe-computed tax totals, subscription status, and billing details derived from any target org

PUBLISHED
Vendor
bitwarden
Product
server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-57520

Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.

PUBLISHED
Vendor
bitwarden
Product
server
Provider severity
HIGH
Conflicts
1

CVE-2026-5752

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.

PUBLISHED
Vendor
Cohere
Product
cohere-terrarium
Provider severity
CRITICAL
Conflicts
1

CVE-2026-57518

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in UserApiController::saveAction(). Attackers can assign themselves a custom role with the 'system: manage packages' permission and then upload and install a malicious PHP package through the admin package installer to achieve remote code execution.

PUBLISHED
Vendor
pagekit
Product
pagekit
Provider severity
HIGH
Conflicts
1