Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-54822

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

PUBLISHED
Vendor
SALESmanago
Product
SALESmanago & Leadoo
Provider severity
HIGH
Conflicts
0

CVE-2026-54821

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

PUBLISHED
Vendor
Bootstrapped Ventures
Product
Visual Link Preview
Provider severity
HIGH
Conflicts
0

CVE-2026-54820

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

PUBLISHED
Vendor
Crocoblock. Jetimpex Inc.
Product
JetBooking
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5482

Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution.  This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0

PUBLISHED
Vendor
Tecrail
Product
Responsive FileManager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54819

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

PUBLISHED
Vendor
Webilia Inc.
Product
Listdom
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

PUBLISHED
Vendor
VeronaLabs
Product
Slimstat Analytics
Provider severity
HIGH
Conflicts
0

CVE-2026-54817

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4.

PUBLISHED
Vendor
FluxBuilder
Product
MStore API
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54816

Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.

PUBLISHED
Vendor
Monetizemore
Product
Advanced Ads
Provider severity
HIGH
Conflicts
0

CVE-2026-54815

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.

PUBLISHED
Vendor
Cargo RD
Product
Cargo Shipping Location for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

PUBLISHED
Vendor
StylemixThemes
Product
Motors
Provider severity
HIGH
Conflicts
0

CVE-2026-54813

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force SureDash allows Blind SQL Injection. This issue affects SureDash: from n/a through 1.8.0.

PUBLISHED
Vendor
Brainstorm Force
Product
SureDash
Provider severity
HIGH
Conflicts
0

CVE-2026-54812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109.

PUBLISHED
Vendor
StylemixThemes
Product
Motors
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54811

Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.

PUBLISHED
Vendor
Tips and Tricks HQ
Product
WP eMember
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54810

Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1.

PUBLISHED
Vendor
Nexi Payments
Product
Nexi XPay
Provider severity
HIGH
Conflicts
0

CVE-2026-54809

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.

PUBLISHED
Vendor
VillaTheme
Product
GIFT4U
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54808

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.

PUBLISHED
Vendor
WP Travel
Product
WP Travel Gutenberg Blocks
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54807

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

PUBLISHED
Vendor
ThemeGrill
Product
Registration Form for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54806

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

PUBLISHED
Vendor
Melapress
Product
WP Activity Log
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54805

Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.

PUBLISHED
Vendor
sbouey
Product
Falang multilanguage
Provider severity
HIGH
Conflicts
0

CVE-2026-54804

Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

PUBLISHED
Vendor
melhorenvio
Product
Melhor Envio
Provider severity
HIGH
Conflicts
0

CVE-2026-54803

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.

PUBLISHED
Vendor
Cozy Vision Technologies Pvt. Ltd.
Product
SMS Alert Order Notifications
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54802

Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.

PUBLISHED
Vendor
Cozy Vision Technologies Pvt. Ltd.
Product
SMS Alert Order Notifications
Provider severity
HIGH
Conflicts
0

CVE-2026-54801

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.

PUBLISHED
Vendor
Siemens, Siemens
Product
CPCI85 Central Processing/Communication, SICORE Base system
Provider severity
HIGH
Conflicts
2

CVE-2026-54800

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.

PUBLISHED
Vendor
Siemens, Siemens
Product
CPCI85 Central Processing/Communication, SICORE Base system
Provider severity
MEDIUM
Conflicts
2

CVE-2026-54799

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.

PUBLISHED
Vendor
Siemens, Siemens
Product
SICORE Base system, CPCI85 Central Processing/Communication
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-54798

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.

PUBLISHED
Vendor
Siemens, Siemens
Product
CPCI85 Central Processing/Communication, SICORE Base system
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-5479

In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and related EVP cipher finalization functions) fails to verify the authentication tag before returning plaintext to the caller. When an application uses the EVP API to perform ChaCha20-Poly1305 decryption, the implementation computes or accepts the tag but does not compare it against the expected value.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-54787

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.

PUBLISHED
Vendor
sigstore
Product
sigstore-go
Provider severity
LOW
Conflicts
0

CVE-2026-54786

Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those before 44.0.3; and versions 45.0.0 and 45.0.1 contain a native implementation of WASIp1 which suffers from a leak in the fd_renumber function where the file descriptor being renumbered to is not properly closed. Wasmtime's implementation erroneously only updated the table of descriptors for WASIp1 and didn't update the underlying table of descriptors

PUBLISHED
Vendor
bytecodealliance
Product
wasmtime
Provider severity
LOW
Conflicts
1

CVE-2026-54785

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read. This issue is fixe

PUBLISHED
Vendor
eLyiN
Product
gemini-bridge
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54784

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
HIGH
Conflicts
1

CVE-2026-54783

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with one captured signed SOAP envelope to replay arbitrary service operations as the victim principal. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
HIGH
Conflicts
1

CVE-2026-54782

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54781

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or custom confirmation method assertions to authenticate a subject without proving authority over the assertion. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
HIGH
Conflicts
1

CVE-2026-54780

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:SignedInfo SignatureMethod against the configured SecurityAlgorithmSuite but does not validate each ds:Reference DigestMethod, allowing a sender to use a rejected digest algorithm such as SHA-1 while the message is still accepted. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
LOW
Conflicts
1

CVE-2026-5478

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalization or directory boundary enforcement. This makes it possible for unauthenticated attackers to read arb

PUBLISHED
Vendor
wpeverest
Product
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-54779

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a captured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54778

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to another or crash the host process under contention. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54777

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListener startup between shared memory GUID publication and service named pipe creation. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54776

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade before dispatching messages, bypassing framing-layer identity checks in UnixPosixIdentitySecurityUpgradeProvider. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54775

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpoint denial of service for attackers with produce permission. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54774

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 SecurityToken key identifier and bypass assertion signature verification. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
HIGH
Conflicts
1

CVE-2026-54773

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header before wsse:Security and cause WSSecurityOneDotZeroReceiveSecurityHeader to verify an attacker-supplied signature instead of the security header signature. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54772

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tcp, net.pipe, or net.uds framing handshake and pin one server thread-pool worker at full CPU per connection. This issue is fixed in versions 1.8.1 and 1.9.1.

PUBLISHED
Vendor
CoreWCF
Product
CoreWCF
Provider severity
HIGH
Conflicts
1

CVE-2026-54771

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`. Version 0.65.3 fixes the issue.

PUBLISHED
Vendor
langroid
Product
langroid
Provider severity
HIGH
Conflicts
0

CVE-2026-5477

An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The function wc_CmacUpdate used the guard `if (cmac->totalSz != 0)` to skip XOR-chaining on the first block (where digest is all-zeros and the XOR is a no-op). However, totalSz is word32 and wraps to zero after 2^28 block flushes (4 GiB), causing the guard to erroneously discard the live CBC-MAC chain state. Any two messages sharing a common suffix beyond the 4 GiB mark then produce iden

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-54769

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python's `eval()` function. However, this relies on an incomplete understa

PUBLISHED
Vendor
langroid
Product
langroid
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54768

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.

PUBLISHED
Vendor
wp-graphql
Product
wp-graphql
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54765

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the

PUBLISHED
Vendor
traefik
Product
traefik
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54764

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 4

PUBLISHED
Vendor
traefik
Product
traefik
Provider severity
MEDIUM
Conflicts
0