Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-55949

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019, Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-55948

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft Excel 2016, Office Online Server
Provider severity
HIGH
Conflicts
1

CVE-2026-55947

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Office Online Server, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-55945

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55944

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Dynamics NAV 2018
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5594

A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes code injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
premAI-io
Product
premsql
Provider severity
MEDIUM
Conflicts
2

CVE-2026-5590

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without validation, leading to a crash.

PUBLISHED
Vendor
zephyrproject-rtos
Product
Zephyr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55899

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office 365 for Mac, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
2

CVE-2026-55898

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Excel 2016, Microsoft Office LTSC 2024, Office Online Server, Microsoft Office 365 for Mac
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and ex

PUBLISHED
Vendor
vim
Product
vim
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily

PUBLISHED
Vendor
vim
Product
vim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55890

Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown excerpt-action pipeline, allowing an editor to save Markdown image style parameters that are written into the rendered img style attribute without sanitization. This issue is fixed in version 2.0.0-rc.9.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5589

An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bounds write. When CONFIG_BT_MESH_OD_PRIV_PROXY_SRV is enabled, the function parses solicitation PDUs from raw BLE advertising payloads. The AD parsing loop reads an attacker-controlled length byte (reported_len) and computes reported_len - 3 without checking that reported_len >= 3. When reported_len is less than 3, the subtraction is performed in signe

PUBLISHED
Vendor
zephyrproject-rtos
Product
Zephyr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55886

Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Prototype Pollution through Jodit.modules.Helpers.set(chain, value, obj), which walks the dot-separated chain, creating and following each path segment without filtering prototype-mutating keys. A chain that begins with (or contains) __proto__, constructor, or prototype lets the final assignment reach and mutate Object.prototype. Applications that pass

PUBLISHED
Vendor
xdan
Product
jodit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55885

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site configuration, through the backup download endpoint protected only by the session-static admin-nonce URL parameter. This issue is reported as fixed in version 1.7.53.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue

PUBLISHED
Vendor
tilt-dev
Product
tilt
Provider severity
CRITICAL
Conflicts
0

CVE-2026-55883

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoint and the upgrader accepts clients that omit an Origin header. When the HUD is network-exposed, an attacker who can reach the listener can open the HUD WebSocket and receive the full view stream, including session state, Tiltfile contents, resource statuses, an

PUBLISHED
Vendor
tilt-dev
Product
tilt
Provider severity
HIGH
Conflicts
0

CVE-2026-55882

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug with no access control. When the HUD or apiserver listener is network-exposed, an unauthenticated caller can read process memory through /debug/pprof/heap and /debug/pprof/goroutine, including session and apiserver tokens, and degrade performance through /debug/pprof/profile or /debug/pprof/trace. This issue is fixed in version

PUBLISHED
Vendor
tilt-dev
Product
tilt
Provider severity
HIGH
Conflicts
0

CVE-2026-55881

OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checked only that the project belonged to the requester's tenant and did not verify that the session belonged to that project, allowing any authenticated low-privilege user to read another tenant's first 15 seconds of session-replay recording data. This is

PUBLISHED
Vendor
openreplay
Product
openreplay
Provider severity
HIGH
Conflicts
0

CVE-2026-55880

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while dashboards.update_widget and dashboards.remove_widget filtered only on dashboard id and widget id, allowing any authenticated member to delete another user's private session notes and remove or rewrite widgets on another user's p

PUBLISHED
Vendor
openreplay
Product
openreplay
Provider severity
HIGH
Conflicts
0

CVE-2026-5588

A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix. The PKIX draft `CompositeVerifier` implementation improperly accepts an empty signature sequence as a valid cryptographic signature. This issue allows a remote attacker to bypass signature verification mechanisms, potentially compromising the authenticity and integrity of data.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Legion of the Bouncy Castle Inc., Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Legion of the Bouncy Castle Inc., Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Legion of the Bouncy Castle Inc., Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Fuse 7, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1, OpenShift Developer Tools and Services, OpenShift Developer Tools and Services, Cryostat 4, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Single Sign-On 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat AMQ Broker 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, streams for Apache Kafka 3, Red Hat build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat AMQ Broker 7.13.5, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, BC-JAVA, Red Hat OpenShift Dev Spaces 3.28, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Fuse 7, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat build of Quarkus 3.27.3.SP1, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat build of Quarkus 3.20.6.SP1, streams for Apache Kafka 2, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, streams for Apache Kafka 2, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform 7, Red Hat Data Grid 8, streams for Apache Kafka 3, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, BCPKIX-FIPS, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat AMQ Broker 7.12.7, Red Hat Satellite 6, Red Hat Data Grid 8, BCPIX-LTS, Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-55879

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashboard through TextEllipsis and the event-details modal, allowing an unauthenticated attacker to store script that executes in the dashboard origin, reads the session JWT from localStorage, and takes ov

PUBLISHED
Vendor
openreplay
Product
openreplay
Provider severity
CRITICAL
Conflicts
0

CVE-2026-55878

Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths like ../../../etc, a crafted or compromised kit can write attacker-controlled content to arbitrary locations or read local files outside the recipe directory. This issue is fixed in versions 2.36.1 and 3.2.0.

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
HIGH
Conflicts
0

CVE-2026-55877

Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested script elements, on* event handlers, or dangerous URL schemes to execute cross-site scripting. This issue is fixed in versions 2.36.1 and 3.2.0.

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55874

SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in the X-Amz-Copy-Source header used by CopyObject and UploadPartCopy, allowing an authenticated identity scoped to one bucket to read objects from other buckets through server-side copy. This issue is fixed in version 4.34.

PUBLISHED
Vendor
seaweedfs
Product
seaweedfs
Provider severity
HIGH
Conflicts
0

CVE-2026-55873

SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.

PUBLISHED
Vendor
seaweedfs
Product
seaweedfs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5587

A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py of the component Refiner Agent. The manipulation leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was

PUBLISHED
Vendor
wbbeyourself
Product
MAC-SQL
Provider severity
MEDIUM
Conflicts
2

CVE-2026-55865

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time because liquid.TokenStream.eof did not give the EOF token matching kind and value fields, allowing malicious template authors to craft templates for a denial of service attack. This issue is fixed in version 2.2.1.

PUBLISHED
Vendor
jg-rp
Product
liquid
Provider severity
HIGH
Conflicts
0

CVE-2026-5586

A vulnerability was determined in zhongyu09 openchatbi up to 0.2.1. The impacted element is an unknown function of the component Multi-stage Text2SQL Workflow. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
zhongyu09
Product
openchatbi
Provider severity
MEDIUM
Conflicts
2

CVE-2026-55852

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently checked before extraction. This issue is fixed in versions 16.23.0 and 15.112.0.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
HIGH
Conflicts
0

CVE-2026-55851

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the

PUBLISHED
Vendor
netty
Product
netty
Provider severity
HIGH
Conflicts
0

CVE-2026-5585

A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of the component Task Detail Endpoint. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Tencent
Product
AI-Infra-Guard
Provider severity
MEDIUM
Conflicts
2

CVE-2026-55849

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. This issue is fixed in version 5.0.0.

PUBLISHED
Vendor
CycloneDX
Product
cyclonedx-node-npm
Provider severity
HIGH
Conflicts
0

CVE-2026-55844

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a not secure network. This vulnerability is fixed in 2025.5.0.

PUBLISHED
Vendor
home-assistant
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-55843

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another administrator, or a user with users.edit updating a regular account, to remove the target’s administrative or granular permissions. This issue is fixe

PUBLISHED
Vendor
grokability
Product
snipe-it
Provider severity
HIGH
Conflicts
0

CVE-2026-5584

A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Fosowl
Product
agenticSeek
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-55838

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls validate_admin_request to enforce admin-action IAM checks; the MetricsHandler skips this call entirely. A restricted IAM user whose policy grants only access to their own bucket can read server-wide operational metrics including d

PUBLISHED
Vendor
rustfs
Product
rustfs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55833

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue i

PUBLISHED
Vendor
netty
Product
netty
Provider severity
HIGH
Conflicts
0

CVE-2026-55831

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map in

PUBLISHED
Vendor
netty
Product
netty
Provider severity
HIGH
Conflicts
1

CVE-2026-55830

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter and bypass the embedding application's access policy. This issue is fixed in version 8.3.

PUBLISHED
Vendor
zopefoundation
Product
RestrictedPython
Provider severity
HIGH
Conflicts
0

CVE-2026-5583

A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Online Shopping Portal Project
Provider severity
MEDIUM
Conflicts
2

CVE-2026-55827

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitmap->data only for the smaller DstWidth and DstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content. This issue is fixed in version 3.27.1.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
HIGH
Conflicts
1

CVE-2026-55825

Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file from another job directory inside var/job-attachments. The controller authorizes only the jobUuid route parameter. The later attachment lookup joins that authorized job UUID with the attacker-controlled identifier, then passes the combined path to the virtual files

PUBLISHED
Vendor
contao
Product
contao
Provider severity
LOW
Conflicts
0

CVE-2026-55824

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to external domains by creating a scoped client: full options for root page origins, cleaned options for everything else. The cleaner removes Cookie and Authorization headers, but it removes the non-Symfony option names basic_auth and bearer_auth instead of Symfony Htt

PUBLISHED
Vendor
contao
Product
contao
Provider severity
LOW
Conflicts
0

CVE-2026-5582

The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. This makes it possible for unauthenticated attackers to toggle the status of sync rules (enable/disable) via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
fusewp
Product
FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55810

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

PUBLISHED
Vendor
Drupal
Product
Plotly.js Graphing
Provider severity
HIGH
Conflicts
0

CVE-2026-55809

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.

PUBLISHED
Vendor
Drupal
Product
Flag attendance field
Provider severity
HIGH
Conflicts
0

CVE-2026-55808

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

PUBLISHED
Vendor
Drupal
Product
Drupal core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55807

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

PUBLISHED
Vendor
Drupal
Product
Drupal core
Provider severity
LOW
Conflicts
0

CVE-2026-55806

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.

PUBLISHED
Vendor
Drupal
Product
Drupal core
Provider severity
MEDIUM
Conflicts
0