Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-49781

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

PUBLISHED
Vendor
Brainstorm Force
Product
OttoKit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49780

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

PUBLISHED
Vendor
Dokan, Inc.
Product
Dokan
Provider severity
HIGH
Conflicts
0

CVE-2026-4978

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.

PUBLISHED
Vendor
UMAI Vision
Product
Traffic Analysis System
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49779

Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.

PUBLISHED
Vendor
Addify
Product
Tax Exempt for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49778

Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.

PUBLISHED
Vendor
WPFunnels
Product
WPFunnels Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-49777

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

PUBLISHED
Vendor
ShapedPlugin, LLC
Product
Product Slider Pro for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49776

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.

PUBLISHED
Vendor
JExtensions Store
Product
GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49775

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

PUBLISHED
Vendor
info@welcart
Product
Welcart e-Commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49774

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.

PUBLISHED
Vendor
Filipe Nasc
Product
RD Station
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49773

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

PUBLISHED
Vendor
FolioVision
Product
FV Flowplayer Video Player
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

PUBLISHED
Vendor
Liquid Web / StellarWP
Product
The Events Calendar
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.

PUBLISHED
Vendor
10Web
Product
Photo Gallery by 10Web
Provider severity
HIGH
Conflicts
0

CVE-2026-49770

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

PUBLISHED
Vendor
WP Travel Engine
Product
WP Travel Engine
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4977

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerable to Improper Access Control in all versions up to, and including, 1.2.58 This is due to insufficient field-level permission validation in the upload_file_remove() AJAX handler where the $htmlvar parameter is not validated against a whitelist of allowed fields or checked against the field's for_admin_use property. This makes it possible for authenticated attackers, with subscr

PUBLISHED
Vendor
stiofansisland
Product
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49769

Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

PUBLISHED
Vendor
Tomdever
Product
wpForo Forum
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49768

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

PUBLISHED
Vendor
Happyforms
Product
Happyforms
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49767

Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.

PUBLISHED
Vendor
Tomdever
Product
wpForo Forum
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49766

Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

PUBLISHED
Vendor
WP User Manager
Product
WP User Manager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49765

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.

PUBLISHED
Vendor
CRM Perks
Product
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49764

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

PUBLISHED
Vendor
Metagauss
Product
RegistrationMagic
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49763

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

PUBLISHED
Vendor
CRM Perks
Product
Integration for Contact Form 7 HubSpot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49762

Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to cause a denial of service through CPU and memory exhaustion. The version parser converts numeric version components (major, minor, patch and numeric pre-release/build identifiers) to integers without bounding their length. A single large all-digit component therefore forces a super-linear, non-yielding base-10 to arbitrary-precision integer conversi

PUBLISHED
Vendor
elixir-lang, elixir-lang
Product
elixir, elixir
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49760

Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes ar

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4976

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Totolink
Product
LR350
Provider severity
HIGH
Conflicts
2

CVE-2026-49759

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ER

PUBLISHED
Vendor
Red Hat, Erlang, Erlang, Red Hat, Red Hat
Product
Red Hat OpenStack Platform 17.1, OTP, OTP, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2
Provider severity
HIGH
Conflicts
3

CVE-2026-49757

Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address (an upsert on the email field, or a user-defined sign-in filter) rather than by the OpenID Connect iss/sub claim combination. Per OpenID Connect Core §5.7, only iss/sub uniquely and stably identifies an end-user; other claims, including email, MUST NOT be use

PUBLISHED
Vendor
team-alembic, team-alembic
Product
ash_authentication, ash_authentication
Provider severity
CRITICAL
Conflicts
1

CVE-2026-49756

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by interpolating the caller-supplied name, filename, and content_type values directly into the content-disposition and content-type lines with no escaping or CRLF stripping. A value containing ", \r, or \n closes the surrounding quoted value and starts

PUBLISHED
Vendor
wojtekmach, wojtekmach
Product
req, req
Provider severity
LOW
Conflicts
1

CVE-2026-49755

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb response bodies. Req's default response pipeline includes Req.Steps.decode_body/1 and Req.Steps.decompress_body/1 in lib/req/steps.ex. decode_body/1 dispatches on the server-supplied content-type (or URL extension) and calls :zip.extract(body, [:memory]) for application/zip, :erl_tar.extract({:binary, bo

PUBLISHED
Vendor
wojtekmach, wojtekmach
Product
req, req
Provider severity
HIGH
Conflicts
1

CVE-2026-49754

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). When Mint's HTTP/2 receive path observes a HEADERS frame without the END_HEADERS flag, the unparsed header-block fragment is parked in conn.headers_being_processed, and every subsequent CONTINUATION frame on that stream is appended to the accumulator. Nothing in the receive path caps the accumulator: ther

PUBLISHED
Vendor
elixir-mint, elixir-mint
Product
mint, mint
Provider severity
HIGH
Conflicts
1

CVE-2026-49753

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 Content-Length parser, Mint.HTTP1.Parse.content_length_header/1 in lib/mint/http1/parse.ex, parses the header value with Integer.parse/1, which accepts an optional + or - sign prefix. The length >= 0 guard rejects negatives, but inputs such as +0 or +123 are returned as

PUBLISHED
Vendor
elixir-mint, elixir-mint
Product
mint, mint
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4975

A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
AC15
Provider severity
HIGH
Conflicts
2

CVE-2026-49745

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
HIGH
Conflicts
0

CVE-2026-49744

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
HIGH
Conflicts
0

CVE-2026-49743

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-fr

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
HIGH
Conflicts
0

CVE-2026-49742

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
HIGH
Conflicts
1

CVE-2026-49741

Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and permission checks. This allowed injecting arbitrary form configurations, re-enabling attack vectors originally addressed in TYPO3-CORE-SA-2018-003, including SQL injection and privilege escalation. This issue affects TYPO3 CMS versions 14.0.0-14.3.2.

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
HIGH
Conflicts
1

CVE-2026-49740

TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store or sys_registry database table) could inject a crafted serialized payload to trigger PHP Object Injection, potentially exploiting a gadget chain to achieve Remote Code Execution or other high-impact effects. Exploiting this vulnerability requires direct local w

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4974

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Tenda
Product
AC7
Provider severity
HIGH
Conflicts
2

CVE-2026-49738

The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be incorrectly accepted as valid when the project root was /var/www/html. Administrator users with access to the File Abstraction Layer were able to create new file storage definitions pointing to directories outside the project root, bypassing this path check. This issue affects TYPO3 CM

PUBLISHED
Vendor
TYPO3
Product
TYPO3 CMS
Provider severity
LOW
Conflicts
0

CVE-2026-4973

A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument quiz_question results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Quiz System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-4972

A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.php. Such manipulation of the argument Description leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Reviewer System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-4971

A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
SourceCodester
Product
Note Taking App
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4970

A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
code-projects
Product
Social Networking Site
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4969

A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

PUBLISHED
Vendor
code-projects
Product
Social Networking Site
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-4968

A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
SourceCodester
Product
Diary App
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4967

In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed.

PUBLISHED
Vendor
Unisoc (Shanghai) Technologies Co., Ltd.
Product
SC7731E/SC9832E/SC9863A/T310/T610/T618/T7200/T7225/T7250/T7255/T7280/T7300/T8100/T9100/T8200/T8300
Provider severity
HIGH
Conflicts
0

CVE-2026-4966

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Free Hotel Reservation System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4965

A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performing a manipulation results in improper neutralization of directives in dynamically evaluated code. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
letta-ai
Product
letta
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-4964

A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_helper.py of the component File URL Handler. Such manipulation of the argument ImageContent leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
letta-ai
Product
letta
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4963

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of the component Incomplete Fix CVE-2025-9959. This manipulation causes code injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
huggingface
Product
smolagents
Provider severity
MEDIUM
Conflicts
2