Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-55016

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55014

Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Remote Help
Provider severity
HIGH
Conflicts
0

CVE-2026-55012

Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Malware Protection Engine
Provider severity
HIGH
Conflicts
1

CVE-2026-55011

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Malware Protection Engine
Provider severity
HIGH
Conflicts
0

CVE-2026-55010

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Minecraft Bedrock Dedicated Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5501

wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for any subject name with any public key and arbitrary signature bytes, and the function returns `WOLFSSL_

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-55009

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14
Provider severity
HIGH
Conflicts
1

CVE-2026-55008

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server Subscription Edition RTM
Provider severity
CRITICAL
Conflicts
1

CVE-2026-55006

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 14
Provider severity
HIGH
Conflicts
1

CVE-2026-55005

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 14
Provider severity
HIGH
Conflicts
1

CVE-2026-55004

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows Server 2025, Windows 10 Version 1607, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-55003

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2012 R2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55002

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2025 (CU 6), Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2017 (GDR), Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 25), Microsoft SQL Server 2025 for x64-based Systems (GDR)
Provider severity
HIGH
Conflicts
1

CVE-2026-55001

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-55000

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5500

wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received and has no lower bounds check. A man-in-the-middle can therefore truncate the mac field from 16 bytes to 1 byte, reducing the tag check from 2⁻¹²⁸ to 2⁻⁸.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-54999

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012, Windows 10 Version 1809, Windows Server 2022, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Exchange Online
Provider severity
HIGH
Conflicts
0

CVE-2026-54997

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2012, Windows Server 2016, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2022
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54996

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-54995

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-54993

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-54992

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 10 Version 1607, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-54991

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-54990

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54989

Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2012 R2, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-54988

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Excel 2016, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024, Microsoft Office 2019, Microsoft 365 Apps for Enterprise
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54987

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022, Windows Server 2012 R2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1607, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-54986

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-54983

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2012, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-54982

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-5497

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method splits the base64 data string on commas to extract individual JPEG frames without enforcing a frame count limit. An attacker can exploit this by crafting a single API request containing thousands of comma-separated base64-encoded JPEG frames in a data URL, causin

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, vllm-project, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), vllm-project/vllm, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server, Red Hat AI Inference Server
Provider severity
HIGH
Conflicts
3

CVE-2026-5496

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDSPRJ files. The issue results from the lack of proper validation of user-supplied data,

PUBLISHED
Vendor
Labcenter Electronics
Product
Proteus
Provider severity
HIGH
Conflicts
0

CVE-2026-5495

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDSPRJ files. The issue results from the lack of proper validation of user-suppli

PUBLISHED
Vendor
Labcenter Electronics
Product
Proteus
Provider severity
HIGH
Conflicts
0

CVE-2026-5494

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDSPRJ files. The issue results from the lack of proper validation of user-suppli

PUBLISHED
Vendor
Labcenter Electronics
Product
Proteus
Provider severity
HIGH
Conflicts
0

CVE-2026-5493

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDSPRJ files. The issue results from the lack of proper validation of user-supplied

PUBLISHED
Vendor
Labcenter Electronics
Product
Proteus
Provider severity
HIGH
Conflicts
0

CVE-2026-5492

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to di

PUBLISHED
Vendor
DriveLock
Product
DriveLock
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54919

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an IP-literal host with server certificate verification enabled, SSLClient and Client in HTTPS mode skip certificate chain validation and WebSocketClient on the Mbed TLS backend skips

PUBLISHED
Vendor
yhirose
Product
cpp-httplib
Provider severity
HIGH
Conflicts
0

CVE-2026-54917

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath

PUBLISHED
Vendor
seaweedfs
Product
seaweedfs
Provider severity
HIGH
Conflicts
0

CVE-2026-54911

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues. This vulnerability is fixed in 5.13.0.

PUBLISHED
Vendor
ultrajson
Product
ultrajson
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54910

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape

PUBLISHED
Vendor
gtsteffaniak
Product
filebrowser
Provider severity
HIGH
Conflicts
1

CVE-2026-5491

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 6067 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability t

PUBLISHED
Vendor
DriveLock
Product
DriveLock
Provider severity
HIGH
Conflicts
0

CVE-2026-54909

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. This issue is fixed in version 3.1.3.

PUBLISHED
Vendor
pion
Product
stun
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54908

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.

PUBLISHED
Vendor
pion
Product
dtls
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54906

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a

PUBLISHED
Vendor
ruby-concurrency
Product
concurrent-ruby
Provider severity
LOW
Conflicts
1

CVE-2026-54905

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low 15 bits are used for the read hold count, and bit 15 is used as WRITE_LOCK_HELD. After 32,768 reentrant read acquisitions, the local read count crosses into the write-lock bit. try_write_lock then treats the thread as al

PUBLISHED
Vendor
ruby-concurrency
Product
concurrent-ruby
Provider severity
LOW
Conflicts
0

CVE-2026-54904

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compare_and_set(old_value, new_value) succeeds; Numeric compare_and_set, which checks old == old_value before attempting the underlying atomic swap.; and Ruby NaN semantics, where Float::NAN == Float::NAN is always false. As a

PUBLISHED
Vendor
ruby-concurrency
Product
concurrent-ruby
Provider severity
HIGH
Conflicts
0

CVE-2026-54903

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.

PUBLISHED
Vendor
ohler55
Product
oj
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54902

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerable to Use-After-Free when in SAJ mode. The Oj::Parser does not protect cached object keys (≥ 35 bytes) from garbage collection, and a Ruby callback that triggers GC inside hash_end can cause the key string to be reclaimed while the C parser still holds a pointer to it. The subsequent access to the freed string VALUE results in a segfault, confirmed by an RIP pointing to address

PUBLISHED
Vendor
ohler55
Product
oj
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54901

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mark array_class and hash_class references during garbage collection, leading to Use-After-Free. If GC runs after the class is assigned but before a parse, the class object is reclaimed, leaving the parser holding a dangling VALUE. The subsequent parse call dereferences the freed object, producing a segfault. This issue has been fixed in version 3.17.2

PUBLISHED
Vendor
ohler55
Product
oj
Provider severity
MEDIUM
Conflicts
0