Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-48892

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API outp

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48891

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read permission on some Dags could enumerate the identifiers of other Dags they were not authorized to read by inspecting the dependency graph for trigger / sensor references. Affects deployments

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48889

Subscriber Privilege Escalation in Amelia <= 2.3 versions.

PUBLISHED
Vendor
TMS
Product
Amelia
Provider severity
HIGH
Conflicts
0

CVE-2026-48887

Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

PUBLISHED
Vendor
Ahmad
Product
JS Help Desk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48886

Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

PUBLISHED
Vendor
Ahmad
Product
JS Help Desk
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48885

Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.

PUBLISHED
Vendor
Groundhogg
Product
HollerBox
Provider severity
HIGH
Conflicts
0

CVE-2026-48883

Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.

PUBLISHED
Vendor
WPClever
Product
WPC Product Bundles for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-48882

Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

PUBLISHED
Vendor
codepeople
Product
WP Time Slots Booking Form
Provider severity
HIGH
Conflicts
0

CVE-2026-48881

Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

PUBLISHED
Vendor
themetechmount
Product
TrueBooker
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48880

Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.

PUBLISHED
Vendor
Ahmad
Product
WP Job Portal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4888

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses from the server.

PUBLISHED
Vendor
wpeverest
Product
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48879

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

PUBLISHED
Vendor
Sergey
Product
AIWU
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48878

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.

PUBLISHED
Vendor
Bootstrapped Ventures
Product
Visual Link Preview
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48877

Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0.

PUBLISHED
Vendor
Tom
Product
GenerateBlocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48876

Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.

PUBLISHED
Vendor
Web Guy
Product
Stop Spammers
Provider severity
HIGH
Conflicts
0

CVE-2026-48875

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

PUBLISHED
Vendor
Jetimpex Inc.
Product
JetSmartFilters
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48874

Subscriber SQL Injection in GamiPress <= 7.8.7 versions.

PUBLISHED
Vendor
Ruben Garcia
Product
GamiPress
Provider severity
HIGH
Conflicts
0

CVE-2026-48873

Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.

PUBLISHED
Vendor
Montonio
Product
Montonio for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-48872

Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.

PUBLISHED
Vendor
WPDeveloper
Product
EmbedPress
Provider severity
HIGH
Conflicts
0

CVE-2026-48871

Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.

PUBLISHED
Vendor
Takashi Kitajima
Product
MW WP Form
Provider severity
HIGH
Conflicts
0

CVE-2026-48870

Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.

PUBLISHED
Vendor
King Addons
Product
King Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4887

A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48869

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

PUBLISHED
Vendor
Kriesi
Product
Enfold
Provider severity
HIGH
Conflicts
0

CVE-2026-48868

Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.

PUBLISHED
Vendor
mra13 / Team Tips and Tricks HQ
Product
Simple Shopping Cart
Provider severity
HIGH
Conflicts
0

CVE-2026-48867

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.

PUBLISHED
Vendor
ExpressTech
Product
Quiz And Survey Master
Provider severity
HIGH
Conflicts
0

CVE-2026-48866

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

PUBLISHED
Vendor
Rocketgenius Inc.
Product
Gravity Forms
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48865

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6.

PUBLISHED
Vendor
ThimPress
Product
LearnPress
Provider severity
HIGH
Conflicts
0

CVE-2026-48864

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Satellite 6, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Discovery 2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Hardened Images, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat OpenShift Container Platform 4, Red Hat Discovery 2, Red Hat Enterprise Linux 9, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Update Infrastructure 5
Provider severity
HIGH
Conflicts
1

CVE-2026-48863

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, OpenSUSE, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, libsolv, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Satellite 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Satellite 6, Red Hat Enterprise Linux 7, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
1

CVE-2026-48862

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. In lib/mint/http2.ex, Mint.HTTP2.decode_push_promise_headers_and_add_response/5 inserts a :reserved_remote entry into conn.streams for every promised stream ID. The neighbouring Mint.HTTP2.assert_valid_promised_stream_id/2 only verifies that the promised ID is even and not already present; client_settings.m

PUBLISHED
Vendor
elixir-mint, elixir-mint
Product
mint, mint
Provider severity
HIGH
Conflicts
1

CVE-2026-48861

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices the caller-supplied method and target arguments directly into the HTTP/1 request line without any character validation: [method, ?\s, target, " HTTP/1.1\r\n"]. An application that forwards attacker-controlled input as the HTTP method or target to Mint.HTTP.request/5 is the

PUBLISHED
Vendor
elixir-mint, elixir-mint
Product
mint, mint
Provider severity
LOW
Conflicts
1

CVE-2026-48860

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, calls inet:sockname/1 instead of inet:peername/1 to obtain the peer's IP address. Because inet:sockname/1 returns the local socket address, both the local IP and the supposed peer IP resolve to the same value, causing the su

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
HIGH
Conflicts
2

CVE-2026-48859

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 computation with 600,000 iterations (~300ms) for valid usernames, but returns immediately (~0ms) for invalid usernames via the ssh_options:get_password_option/2 path. This t

PUBLISHED
Vendor
Erlang, Erlang, Erlang
Product
OTP, OTP, OTP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48858

Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server's 227 response and passes it directly to gen_tcp:connect/4 without validating it against the control connection peer address. The adjacent EPSV handlers correctly call peername(CSock) to d

PUBLISHED
Vendor
Erlang, Erlang, Erlang
Product
OTP, OTP, OTP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48856

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxy_authorization) are copied verbatim. The

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
HIGH
Conflicts
1

CVE-2026-48855

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
LOW
Conflicts
1

CVE-2026-48854

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.GRPC.Server.Adapters.Cowboy.Handler':read_full_body/3 (lib/grpc/server/adapters/cowboy/handler.ex) accumulates every received chunk into a single growing binary with no size cap. Additionally, when the client omits the grpc-timeout header, the per-chunk read timeo

PUBLISHED
Vendor
elixir-grpc, elixir-grpc
Product
grpc, grpc
Provider severity
HIGH
Conflicts
1

CVE-2026-48853

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it, achieve remote code execution on the server. 'Elixir.GRPC.Codec.Erlpack':decode/2 (lib/grpc/codec/erlpack.ex) calls :erlang.binary_to_term/1 on the raw gRPC message body without the :safe option, no size bound, and no type gua

PUBLISHED
Vendor
elixir-grpc, elixir-grpc
Product
grpc, grpc
Provider severity
CRITICAL
Conflicts
2

CVE-2026-48852

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

PUBLISHED
Vendor
PuTTY
Product
PuTTY
Provider severity
LOW
Conflicts
0

CVE-2026-48851

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

PUBLISHED
Vendor
PuTTY
Product
PuTTY
Provider severity
LOW
Conflicts
0

CVE-2026-48850

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

PUBLISHED
Vendor
PuTTY
Product
PuTTY
Provider severity
LOW
Conflicts
0

CVE-2026-4885

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected

PUBLISHED
Vendor
Piotnet
Product
Piotnet Addons For Elementor Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48849

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48848

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
HIGH
Conflicts
0

CVE-2026-48847

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
LOW
Conflicts
0

CVE-2026-48846

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48845

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48844

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
HIGH
Conflicts
0

CVE-2026-48843

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
HIGH
Conflicts
0

CVE-2026-48842

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
HIGH
Conflicts
0