Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-56650

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2012, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-5665

A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Online FIR System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-56649

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2016, Windows Server 2025, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012, Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56648

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2016
Provider severity
HIGH
Conflicts
2

CVE-2026-56647

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2019, Windows 11 Version 25H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-56646

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56645

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
HIGH
Conflicts
0

CVE-2026-56644

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2022, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-56643

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-56642

Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Service Fabric
Provider severity
HIGH
Conflicts
0

CVE-2026-5663

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue.

PUBLISHED
Vendor
OFFIS
Product
DCMTK
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-56624

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or verify-required options that could be embedded in the certificate, nor did it validate these options. As a result it was possible that a user could authenticate with such a certificate that included a

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Provider severity
HIGH
Conflicts
0

CVE-2026-56623

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories outside of the configured server-side root directory. The path validation applied for CVE-2026-48827 in Apache MINA SSHD 2.18.0 and 3.0.0-M4 was partly ineffective for Servers running on Windows. A

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Provider severity
HIGH
Conflicts
0

CVE-2026-5661

A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
n/a
Product
Free5GC
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56609

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56608

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
LOW
Conflicts
0

CVE-2026-5660

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
itsourcecode
Product
Construction Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-5659

A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The manipulation results in deserialization. The attack can be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
pytries
Product
datrie
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56587

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

PUBLISHED
Vendor
HCLSoftware
Product
IntelliOps Event Management
Provider severity
LOW
Conflicts
0

CVE-2026-56586

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

PUBLISHED
Vendor
HCLSoftware
Product
IntelliOps Event Management
Provider severity
LOW
Conflicts
0

CVE-2026-56585

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.

PUBLISHED
Vendor
HCLSoftware
Product
IntelliOps Event Management
Provider severity
LOW
Conflicts
0

CVE-2026-56584

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.

PUBLISHED
Vendor
HCLSoftware
Product
IntelliOps Event Management
Provider severity
LOW
Conflicts
0

CVE-2026-56583

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56582

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56581

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56580

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56579

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56578

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56577

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

PUBLISHED
Vendor
HCLSoftware
Product
MyCloud
Provider severity
LOW
Conflicts
0

CVE-2026-56571

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
LOW
Conflicts
0

CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
LOW
Conflicts
0

CVE-2026-5657

iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56569

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56568

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
LOW
Conflicts
0

CVE-2026-56567

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

PUBLISHED
Vendor
HCL Software
Product
HCL iControl
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5656

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

PUBLISHED
Vendor
Red Hat, Red Hat, Wireshark Foundation, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10.0 Extended Update Support, Wireshark, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
3

CVE-2026-5655

SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5654

AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56538

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

PUBLISHED
Vendor
HCLSoftware
Product
Connections
Provider severity
LOW
Conflicts
0

CVE-2026-56537

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

PUBLISHED
Vendor
HCLSoftware
Product
Connections
Provider severity
LOW
Conflicts
0

CVE-2026-5653

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5652

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.

PUBLISHED
Vendor
Arcadia Technology, LLC
Product
Crafty Controller
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5650

A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Online Application System for Admission
Provider severity
MEDIUM
Conflicts
2

CVE-2026-5649

A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Application System for Admission
Provider severity
MEDIUM
Conflicts
2

CVE-2026-5648

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Laundry System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-5647

A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/admin_feature.php of the component Add Product Page. The manipulation of the argument product_name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Shoe Store
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-56460

HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.

PUBLISHED
Vendor
HCLSoftware
Product
HCL DevOps Deploy / HCL Launch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5646

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Easy Blog Site
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-56459

HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log files that could be read by a local user.

PUBLISHED
Vendor
HCLSoftware
Product
HCL DevOps Deploy / HCL Launch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56458

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

PUBLISHED
Vendor
HCLSoftware
Product
HCL DevOps Deploy
Provider severity
MEDIUM
Conflicts
0