Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-56457

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.

PUBLISHED
Vendor
HCLSoftware
Product
HCL DevOps Deploy / HCL Launch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56456

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56455

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system to crash or become unresponsive. To mitigate this flaw, comprehensive input length checks must be implemented and enforced on both the client and server sides.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56454

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56453

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56452

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could send filenames containing paths, resulting in files to be written in attacker-controlled places. The issue affects only * applications that use no longer supported Apache MINA SSHD versions < 2.0.0 and use the SCP

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Provider severity
HIGH
Conflicts
1

CVE-2026-56451

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

PUBLISHED
Vendor
Siemens
Product
Opcenter X
Provider severity
CRITICAL
Conflicts
1

CVE-2026-56450

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a valid code and bypass the intended second authentication factor, resulting in unauthorized account access. The patch introduces per-user failed-OTP tracking, blocks verification aft

PUBLISHED
Vendor
ail project
Product
ail framework
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5645

A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component Parameter Handler. Executing a manipulation of the argument mpesa can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
projectworlds
Product
Car Rental System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-56448

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot storage directories. This may allow the attacker to download and read arbitrary files that are accessible to the AIL process. The issue occurs because user-controlled path components w

PUBLISHED
Vendor
ail project
Product
ail framework
Provider severity
HIGH
Conflicts
0

CVE-2026-56447

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka options such as plugin.library.paths to load an external library, resulting in arbitrary code execution with the privileges of the MISP process. An attacker could leverage a MISP-writable location, such as an uploaded file or a

PUBLISHED
Vendor
misp
Product
misp
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56446

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP file in a web-accessible directory and inject PHP code through logged data. Accessing the resulting file could lead to remote code execution with the privileges of the web server process. The fix restricts log destinations

PUBLISHED
Vendor
misp
Product
misp
Provider severity
HIGH
Conflicts
0

CVE-2026-56445

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

PUBLISHED
Vendor
pydicom
Product
pynetdicom Library
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-56444

In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented i

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5644

A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice.php. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version

PUBLISHED
Vendor
Cyber-III
Product
Student-Management-System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-56437

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.

PUBLISHED
Vendor
Fuji Electric Co.,Ltd.
Product
Pupsman
Provider severity
HIGH
Conflicts
1

CVE-2026-56434

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX

PUBLISHED
Vendor
F5, F5
Product
NGINX Open Source, NGINX Plus
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-5643

A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This impacts an unknown function of the file /admin/Add%20notice/notice.php of the component Admin Add Endpoint. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery.

PUBLISHED
Vendor
Cyber-III
Product
Student-Management-System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-56428

The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.

PUBLISHED
Vendor
Bosch
Product
BSH ELP (Electronic Platform) Modules
Provider severity
HIGH
Conflicts
0

CVE-2026-56425

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier (session_id()) as the OAuth state parameter. Because session identifiers are long-lived authentication credentials, exposing them in OAuth redirect URLs could leak valid session tokens through browser history, HTTP Referer heade

PUBLISHED
Vendor
misp
Product
misp
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cause the application to authorize one object but mutate another, or could modify objects that were merely visible rather than editable by the user’s organization. The affected paths included: * Ev

PUBLISHED
Vendor
misp
Product
misp
Provider severity
HIGH
Conflicts
1

CVE-2026-56423

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for each selected object. For Event Reports, EventReportsController::deleteSelection relied on the global perm_add capability rather than a per-report ownership/authorization check. As a result, a contributor-level user could submit report IDs or UUIDs for

PUBLISHED
Vendor
misp
Product
misp
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56422

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object identifiers) without consistently stripping, pinning, or revalidating them against the server-authorized object. In affected paths, an authenticated user with access to one authorized object could submit crafted REST or form payloa

PUBLISHED
Vendor
misp
Product
misp
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5642

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva/update.php of the component HTTP POST Request Handler. This manipulation of the argument Name causes improper authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version det

PUBLISHED
Vendor
Cyber-III
Product
Student-Management-System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-56416

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actually present in the RDATA. The wire-format parser accepts multi-dname RRs whose RDATA ends after the first name, so an attacker who runs a DNSSEC-signed

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56415

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.

PUBLISHED
Vendor
Stonefly, Stonefly
Product
Storage Concentrator Virtual Machine, Storage Concentrator
Provider severity
CRITICAL
Conflicts
2

CVE-2026-56414

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.

PUBLISHED
Vendor
H.VIEW
Product
HV-500S6 IP Camera
Provider severity
HIGH
Conflicts
1

CVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.

PUBLISHED
Vendor
StoneFly, StoneFly
Product
Storage Concentrator Virtual Machine, Storage Concentrator
Provider severity
CRITICAL
Conflicts
2

CVE-2026-56412

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56411

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56410

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5641

A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The manipulation of the argument filename results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

PUBLISHED
Vendor
PHPGurukul
Product
Online Shopping Portal Project
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56409

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56408

libexpat before 2.8.2 has an integer overflow in copyString.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56407

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56406

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56405

libexpat before 2.8.2 has an integer overflow in getAttributeId.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56404

libexpat before 2.8.2 has an integer overflow in addBinding.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56403

libexpat before 2.8.2 has an integer overflow in storeAtts.

PUBLISHED
Vendor
libexpat project
Product
libexpat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56402

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.

PUBLISHED
Vendor
nanocoai
Product
nanoclaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-56400

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

PUBLISHED
Vendor
open-webui
Product
open-webui
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-5640

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Online Shopping Portal Project
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56399

Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.

PUBLISHED
Vendor
open-webui
Product
open-webui
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56398

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to

PUBLISHED
Vendor
open-webui
Product
open-webui
Provider severity
HIGH
Conflicts
1

CVE-2026-56397

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

PUBLISHED
Vendor
SiYuan
Product
SiYuan
Provider severity
CRITICAL
Conflicts
1

CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.

PUBLISHED
Vendor
phpMyFAQ
Product
phpMyFAQ
Provider severity
HIGH
Conflicts
1

CVE-2026-56395

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

PUBLISHED
Vendor
SiYuan
Product
SiYuan
Provider severity
CRITICAL
Conflicts
1

CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.

PUBLISHED
Vendor
craftcms
Product
cms
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-56393

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious payloads into section names, volume names, user group names, global set names, generated field names, checkbox/radio optio

PUBLISHED
Vendor
craftcms
Product
cms
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56392

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior lea

PUBLISHED
Vendor
GNU
Product
coreutils
Provider severity
LOW
Conflicts
0