Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-56195

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56194

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019, Windows Server 2025, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607
Provider severity
HIGH
Conflicts
2

CVE-2026-56193

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-56192

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft SharePoint Server Subscription Edition, Microsoft Office 2019, Microsoft SharePoint Server 2019, Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office LTSC for Mac 2021, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56191

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Exchange Online
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56190

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 1607, Windows 11 version 26H1, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012, Windows 11 Version 24H2, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation)
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5619

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lead to os command injection. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Braffolk
Product
mcp-summarization-functions
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56189

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2012 R2, Windows Server 2025, Windows 10 Version 1607, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025, Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation)
Provider severity
CRITICAL
Conflicts
1

CVE-2026-56187

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-56186

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2019, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2022, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56183

Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-56182

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2025, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2022, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-56181

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-5618

A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
kalcaddle
Product
kodbox
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56178

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Defender for Endpoint for Mac
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56176

Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2016, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2012, Windows 10 Version 21H2, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-56175

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2022, Windows 10 Version 1607, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-56173

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2019, Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 23H2, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-56171

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Windows Admin Center, Remote Desktop Web Client
Provider severity
HIGH
Conflicts
1

CVE-2026-56170

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
.NET 8.0, .NET 9.0, .NET 10.0
Provider severity
HIGH
Conflicts
1

CVE-2026-5617

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that the cookie value was legitimately set during an admin-initiated user switch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalat

PUBLISHED
Vendor
royalnavneet
Product
Login as User – Switch User & WooCommerce Login as Customer
Provider severity
HIGH
Conflicts
0

CVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
HIGH
Conflicts
0

CVE-2026-56168

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2022, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure AI Search
Provider severity
HIGH
Conflicts
0

CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Account
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56164

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56163

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Kubernetes Service
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Red Hat OpenShift (ARO)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5616

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a pa

PUBLISHED
Vendor
n/a
Product
JeecgBoot
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-56159

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2016, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 1809
Provider severity
CRITICAL
Conflicts
1

CVE-2026-56157

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56156

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-56155

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2012, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-56152

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.

PUBLISHED
Vendor
Elastic
Product
Elastic Defend
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56151

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

PUBLISHED
Vendor
Elastic
Product
Fleet Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5615

A weakness has been identified in givanz Vvvebjs up to 2.0.5. The affected element is an unknown function of the file upload.php of the component File Upload Endpoint. This manipulation of the argument uploadAllowExtensions causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Patch name: 8cac22cff99b8bc701c408aa8e887fa702755336. Applying a patch is the recommended action to fix this issue. The

PUBLISHED
Vendor
givanz
Product
Vvvebjs
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56149

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56148

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56147

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. Because the access control check and the resource retrieval use different resolution mechani

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
HIGH
Conflicts
0

CVE-2026-56146

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchlist data that should require elevated privileges. Under specific deployment conditions, this could also allow such a user to access data beyond their authorized scope.

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56145

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash.

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56144

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause those indices' configured ingest pipelines to execute and return their output, potentially disclosing data processed or enriched by those pipelines. Additionally, the same feature can be used to retrieve index mapping meta

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56142

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

PUBLISHED
Vendor
JetBrains
Product
Hub
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible

PUBLISHED
Vendor
JetBrains
Product
Hub
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56140

Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it originally configured only an outbound filter (setOutFilterPattern, which blocks Camel*, breadcrumbId and org.apache.camel.* headers from being written out) and did not configure an inbound filter rule. For the related camel-aws2-sqs component this

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel AWS2 SNS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5614

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Belkin
Product
F9K1015
Provider severity
HIGH
Conflicts
2