Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-49193

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49190

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4919

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

PUBLISHED
Vendor
IBM
Product
Guardium Data Protection
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49189

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49187

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49186

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49185

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49184

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2012, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-49183

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 1809, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-49181

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-49180

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2019, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2012 R2, Windows 10 Version 22H2, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4918

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

PUBLISHED
Vendor
IBM
Product
Guardium Data Protection
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49178

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2022, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012, Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-49177

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2019, Windows 10 Version 1607, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-49175

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-49174

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 21H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49173

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows 11 version 26H1
Provider severity
HIGH
Conflicts
0

CVE-2026-49172

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows 10 Version 1607, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2022, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 11 version 26H1
Provider severity
CRITICAL
Conflicts
1

CVE-2026-49171

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2022, Windows 11 version 26H1, Windows Server 2019, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-49170

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2019, Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-4917

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

PUBLISHED
Vendor
IBM
Product
Guardium Data Protection
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49169

Use after free in DNS Server allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-49168

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2019, Windows Server 2025, Windows Server 2016, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49167

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49166

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-49165

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows 11 version 26H1, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2016, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-49164

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2025, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-49162

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-49161

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft PC Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-49160

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows Server 2016, Windows Server 2025, Windows 10 Version 1607, Windows Server 2022, Windows 11 version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-4916

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
LOW
Conflicts
0

CVE-2026-49159

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Graph
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49158

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Thrift
Provider severity
HIGH
Conflicts
0

CVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache ActiveMQ
Provider severity
HIGH
Conflicts
0

CVE-2026-4915

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (server process termination) via a crafted webhook callback response containing a null attachment entry.. Mattermost Advisory ID: MMSA-2026-00641

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49147

App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper that sanitises the filenames printed by -f, -g, the colored match heading, and per-match lines, but the --show-types, -l/-L, and -c paths still emit the raw filename. A file whose

PUBLISHED
Vendor
PETDANCE
Product
App::Ack
Provider severity
HIGH
Conflicts
0

CVE-2026-49146

App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The -B and -C context options accepted any positive integer, and ack sized the before-context buffer to that value, so a project .ackrc setting --before-context=100000000 made ack allocate a buffer of 100 million elements. A project .ackrc committed to an untrusted repo

PUBLISHED
Vendor
PETDANCE
Product
App::Ack
Provider severity
HIGH
Conflicts
0

CVE-2026-49145

App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does not include --files-from, so a project .ackrc can set it to a path whose listed files ack then reads and searches. Version 3.10.0 added --follow to the blocklist; --files-from remains accepted. A project .ackrc committe

PUBLISHED
Vendor
PETDANCE
Product
App::Ack
Provider severity
HIGH
Conflicts
1

CVE-2026-49144

BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and access sensitive files.

PUBLISHED
Vendor
browserstack
Product
browserstack-runner
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-49143

BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitting crafted JSON request bodies to the handler, which passes user-supplied data to vm.runInNewContext() combined with eval(). Attackers can escape the Node.js vm sandbox by leveraging a host-context Function reference through util.format to access the host process via this.constructor.constructor, ach

PUBLISHED
Vendor
browserstack
Product
browserstack-runner
Provider severity
HIGH
Conflicts
1

CVE-2026-49141

WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a kno

PUBLISHED
Vendor
ArnasDon
Product
wacrm
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-49140

Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events with omitted or invalid declared sizes to trigger simultaneous large media downloads that fully materialize response bodies before post-download rejection, consuming process resour

PUBLISHED
Vendor
HKUDS
Product
nanobot
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4914

Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.

PUBLISHED
Vendor
Ivanti, Ivanti
Product
Neurons for ITSM (Cloud), Neurons for ITSM (On-Premise)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49139

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation reference by sending a crafted inbound activity to the Teams webhook, causing subsequent bot replies to transmit token-bearing Authorization header requests to an attacker-controlled h

PUBLISHED
Vendor
HKUDS
Product
nanobot
Provider severity
HIGH
Conflicts
0

CVE-2026-49138

Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP redirect following behavior in the httpx library to bypass initial URL validation and cause the runtime to send outbound requests to internal hosts before final resolved URL validation is

PUBLISHED
Vendor
HKUDS
Product
nanobot
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49136

Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to read arbitrary image-format files outside the intended uploads directory by exploiting an incomplete path prefix check using os.path.startswith() without a trailing separator. Attackers can supply crafted markdown image references in user-controlled page descriptions that resolve to sibling director

PUBLISHED
Vendor
Anionex
Product
banana-slides
Provider severity
HIGH
Conflicts
1