Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-54149

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not consistently validate MCP transport type, allowing an authenticated user to import a .tool file containing stdio transport with malicious commands and trigger the configuration through an AI Chat node so MultiServerMCPClient executes arbitrary system comma

PUBLISHED
Vendor
1Panel-dev
Product
MaxKB
Provider severity
HIGH
Conflicts
0

CVE-2026-5414

A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Newgen
Product
OmniDocs
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54133

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into generated PHP source without sufficient escaping. A crafted expression can cause the generated cache file

PUBLISHED
Vendor
jmespath
Product
jmespath.php
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54132

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2016, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 1607
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54131

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-54130

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5413

A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails leads to information disclosure. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosu

PUBLISHED
Vendor
Newgen
Product
OmniDocs
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-54129

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-54128

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2019, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2012, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2012 R2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-54127

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 11 version 26H1, Windows Server 2022, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-54126

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54125

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows Server 2019, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-54124

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Terminal for Windows 10, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Terminal for Windows 11, Windows Server 2025, Windows Server 2022
Provider severity
HIGH
Conflicts
2

CVE-2026-54122

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2012, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-54120

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Surface Management Services
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5412

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This issue is resolved in Juju versions 2.9.57 and 3.6.21.

PUBLISHED
Vendor
Canonical
Product
Juju
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54119

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1809, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-54118

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2017 (GDR), Microsoft SQL Server 2025 (CU 6), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 25), Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack
Provider severity
HIGH
Conflicts
1

CVE-2026-54117

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft SQL Server 2025 (CU 6), Microsoft SQL Server 2025 for x64-based Systems (GDR)
Provider severity
HIGH
Conflicts
1

CVE-2026-54116

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2025 (CU 6)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54115

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2016, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 10 Version 1607, Windows Server 2019, Windows Server 2012, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-54114

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2022, Windows 11 version 26H1, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-54112

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
2

CVE-2026-54111

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
2

CVE-2026-5411

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the licensing module, combined with unrestricted file extraction in sync_cloud_protection(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files including PHP

PUBLISHED
Vendor
webfactory
Product
Advanced Google reCAPTCHA
Provider severity
HIGH
Conflicts
0

CVE-2026-54109

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2022, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-54108

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54107

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2012, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2016, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-54106

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access controls and log in.

PUBLISHED
Vendor
Civilian Board of Contract Appeals, Government Accountability Office
Product
Electronic Docketing System (EDS), Electronic Protest Docketing System (EPDS)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-54105

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated attacker can submit a request containing an arbitrary 'user_id' parameter and receive a JSON response containing account-specific information, including the associated email address.

PUBLISHED
Vendor
Government Accountability Office, Civilian Board of Contract Appeals
Product
Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-54104

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges.

PUBLISHED
Vendor
Government Accountability Office, Civilian Board of Contract Appeals
Product
Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Provider severity
HIGH
Conflicts
2

CVE-2026-54103

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.

PUBLISHED
Vendor
Government Accountability Office, Civilian Board of Contract Appeals
Product
Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Provider severity
CRITICAL
Conflicts
2

CVE-2026-54100

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers 10.22, Red Hat OpenShift for Windows Containers 10.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
1

CVE-2026-54099

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges a

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift for Windows Containers 10.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers 10.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
1

CVE-2026-54097

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, a low-privileged authenticated user of filebrowser (with create + delete permissions in their own isolated scope) can silently destroy share-link records belonging to any other user — including the administrator — by performing a legitimate DELETE on a file in their own directory whose logical path happens to be a byte-prefix of another user's

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
HIGH
Conflicts
0

CVE-2026-54096

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and stores a public share record without checking whether the target file currently exists. Later, when a file is created at that same path, the previously created public share immediately becomes valid and exposes the new file through `GET /api/public/dl/<hash>`. T

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
HIGH
Conflicts
0

CVE-2026-54094

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTTP file handlers from following symbolic links before they open, serve, write, share, or list a file. As a result, a scoped user — and in some cases an unauthenticated public-share recipient — can cross the intended scope boundary by following a symlink whose path is lexically inside their scope but whose target is outsi

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
HIGH
Conflicts
1

CVE-2026-54093

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, filebrowser builds the download-as-zip / download-as-tar archive entry names with filepath.ToSlash, which on a Linux host is a no-op for backslashes (\ is only a path separator on Windows). A file whose name contains Windows-style traversal is accepted by the resource handlers, stored on the Linux filesystem with a literal backslash name, and t

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54092

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily lags any container created, and has even made my docker daemon start to send errors with status code 500 even after the container was destroyed. This vulnerability is fixed in 2.63

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54091

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase the share owner's filesystem root to the shared directory and then evaluate descendant paths against the owner's global and per-user rules using the rebased relative path instead of the original path relative to the owner's scope. As a result, an attacker who knows a public directory share URL can acc

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
HIGH
Conflicts
0

CVE-2026-54090

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.33.8, when a shell interpreter is configured (e.g. /bin/sh -c), the command allowlist can be bypassed through shell metacharacters. The allowlist validates only the first token of user input, but the entire raw string is handed to the shell — semicolons, pipes, backticks, and $() all work to chain arbitrary commands after a permitted one. This vulner

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
HIGH
Conflicts
1

CVE-2026-5409

Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54089

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server directly can impersonate any user - including admin - by sending a single forged HTTP header. No credentials are required. Additionally, specifying a non-existent username causes the server to automaticall

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54088

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied credentials (username and password) are interpolated into this command string using os.Expand without sanitization. An unauthenticated remote attacker can inject shell metacharacters in the username or

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54082

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in PDFAValidator.validate(...) and GFPDAcroForm.getdynamicRender(), where default DocumentBuilderFactory parsing of rich-text annotation or form-field values and XFA configurations in untrusted PDFs can allow local file disclosure and outbound network requests. This issue is fixed in versions 1.30.2 and 1.31.71.

PUBLISHED
Vendor
veraPDF
Product
veraPDF-validation
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54081

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1FontProgram.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 1 font /FontDescriptor /FontFile program can execute unbounded PostScript array allocation, a zero-increment for loop, or self-recursive toExecute user dictionary lookups and exhaust v

PUBLISHED
Vendor
veraPDF
Product
veraPDF-parser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54080

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 0 font /Encoding or /ToUnicode CMap stream can execute unbounded PostScript array allocation or a zero-increment for loop and exhaust validator memory or CPU. This issue is fixed in versions

PUBLISHED
Vendor
veraPDF
Product
veraPDF-parser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5408

BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54079

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/java/org/verapdf/gf/model/impl/pd/GFPDAcroForm.java in the getdynamicRender() method, where a crafted PDF containing a malicious XFA stream can cause external entity expansion during PDF/UA-1 validation and allow local file disclosure or outbound server-side reque

PUBLISHED
Vendor
veraPDF
Product
veraPDF-validation
Provider severity
HIGH
Conflicts
0