Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-48840

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

PUBLISHED
Vendor
Exim
Product
Exim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48839

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

PUBLISHED
Vendor
VeronaLabs
Product
WP Statistics
Provider severity
HIGH
Conflicts
0

CVE-2026-48838

Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.

PUBLISHED
Vendor
WPExperts
Product
Post SMTP
Provider severity
HIGH
Conflicts
0

CVE-2026-48837

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.

PUBLISHED
Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-48836

Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

PUBLISHED
Vendor
MantraBrain
Product
Easy Invoice
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48835

Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.

PUBLISHED
Vendor
Awesomemotive
Product
Contact Form by WPForms
Provider severity
HIGH
Conflicts
0

CVE-2026-48832

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

PUBLISHED
Vendor
SPIP
Product
SPIP
Provider severity
LOW
Conflicts
0

CVE-2026-4883

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's ser

PUBLISHED
Vendor
Piotnet
Product
Piotnet Forms
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48829

In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.

PUBLISHED
Vendor
GNU
Product
GNU SASL
Provider severity
HIGH
Conflicts
0

CVE-2026-48828

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48827

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected. Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue. The iss

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache MINA SSHD
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48824

Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to prevent DoS via unlimited SMTP DATA and /api/v1/send body sizes") wrapped only `POST /api/v1/send` with `http.MaxBytesReader`. The four other Mailpit JSON-body API endpoints `PUT /api/v1/messages` (SetReadStatus), `DELETE /api/v1/messages` (DeleteMessages), `PUT /api/v1/tags` (SetMessageTags), and `POST /api/v1/message/{id}/

PUBLISHED
Vendor
axllent
Product
mailpit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48823

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript into the tags field when creating a bookmark (Shaare). The malicious payload is stored and later executed when users interact with the "Filter by tag" search feature on the homepage. User-supplied input in the tags field is not properly sanitized or output-escaped before

PUBLISHED
Vendor
shaarli
Product
Shaarli
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48822

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the Bookmark Description field. An authenticated user can inject a malicious javascript: URI inside a Markdown link. The vulnerability originates in the filterProtocols method within BookmarkMarkdownFormatter.php.This method attempts to sanitize Markdown links by filtering dangerous protocols (such as javascript:) before

PUBLISHED
Vendor
shaarli
Product
Shaarli
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48821

Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted into the DOM using innerHTML without proper sanitization. The issue originates from the interaction between the backend thumbnail update endpoint and the frontend JavaScript responsible for rendering u

PUBLISHED
Vendor
shaarli
Product
Shaarli
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48820

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1

PUBLISHED
Vendor
cakephp
Product
cakephp
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4882

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a "Profile Picture" field is added to the form.

PUBLISHED
Vendor
WPEverest
Product
User Registration Advanced Fields
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48819

Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/params.ts ships a runtime template copied into generated SDKs as params.gen.ts, and buildClientParams writes unknown slot-prefixed keys such as $body_, $headers_, $path_, and $query_ directly to the corresponding slot, allowing $query___proto__ alongside a legitimate q field to set params.query through params["query"]["__proto__"] = value, call Object.setPrototypeOf(params.query,

PUBLISHED
Vendor
hey-api
Product
openapi-ts
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48818

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Kludex, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Migration Toolkit for Applications 8, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), starlette, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server 3.3, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server 3.3, Red Hat Satellite 6, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Exploit Intelligence, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6
Provider severity
HIGH
Conflicts
2

CVE-2026-48817

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo

PUBLISHED
Vendor
Kludex
Product
starlette
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48816

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.

PUBLISHED
Vendor
sigstore
Product
sigstore-js
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48815

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1.

PUBLISHED
Vendor
sigstore
Product
sigstore-js
Provider severity
HIGH
Conflicts
0

CVE-2026-48814

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw described in the title remained: the SSE MCP server still defaulted to an empty secret, _isAuthorized

PUBLISHED
Vendor
Jovancoding
Product
Network-AI
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48812

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was created by an older version of FreeScout without possessing a valid token or session. Version 1.8.221 con

PUBLISHED
Vendor
freescout-help-desk
Product
freescout
Provider severity
HIGH
Conflicts
0

CVE-2026-48811

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's access to the mailbox containing the conversation has been revoked. The ThreadPolicy::delete authorization policy does not verify mailbox membership, so a former team member retains destructive write access to notes they created. This vulnerability is fixed in 1.

PUBLISHED
Vendor
freescout-help-desk
Product
freescout
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48810

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox membership check was found in the sibling ThreadPolicy::edit method. A user with the PERM_EDIT_CONVERSATIONS permission who created a message or internal note in Mailbox A can rewrite that thread's body after an administrator removes them from Mailbox A, because the policy checks only authorship and a

PUBLISHED
Vendor
freescout-help-desk
Product
freescout
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4881

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.

PUBLISHED
Vendor
Octopus Deploy
Product
Octopus Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48808

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0.

PUBLISHED
Vendor
twigphp
Product
Twig
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48807

Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.

PUBLISHED
Vendor
twigphp
Product
Twig
Provider severity
HIGH
Conflicts
1

CVE-2026-48806

Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0.

PUBLISHED
Vendor
twigphp
Product
Twig
Provider severity
HIGH
Conflicts
1

CVE-2026-48805

Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0.

PUBLISHED
Vendor
twigphp
Product
Twig
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48801

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service tr

PUBLISHED
Vendor
markdown-it
Product
linkify-it
Provider severity
HIGH
Conflicts
0

CVE-2026-48800

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xml is read by NppXml::value(aNode) (Parameters.cpp:3658) in the feedUserCmds() function and stored in UserCommand._cmd without any validation. When the user clicks the corresponding entry in the Run menu, NppCommands.cpp:4264 creates a Command object with string2wstring(ucmd.getCmd()) and calls run(), which invokes ShellExecute (RunDlg.cpp:221) with

PUBLISHED
Vendor
notepad-plus-plus
Product
notepad-plus-plus
Provider severity
HIGH
Conflicts
0

CVE-2026-4880

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Base64-encoded user ID in the token parameter to identify users, leaking valid authentication tokens through the 'barcodeScannerConfigs' action, and lacking meta-key restrictions on the 'setUserMeta' act

PUBLISHED
Vendor
ukrsolution
Product
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48799

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.

PUBLISHED
Vendor
gitroomhq
Product
postiz-app
Provider severity
HIGH
Conflicts
1

CVE-2026-48797

Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push. The CLI accepts two operator-facing flags intended as security controls: --auth user:pass — documented as "require HTTP Basic authentication on every request to the UI." and--share — do

PUBLISHED
Vendor
mcp-tool-shop-org, mcp-tool-shop-org
Product
@mcptoolshop/backpropagate, backpropagate
Provider severity
CRITICAL
Conflicts
2

CVE-2026-48795

AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to create plain intermediate objects and pollute Object.prototype. This issue is fixed in versions 10.1.5 and 11.0.3.

PUBLISHED
Vendor
adonisjs
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-48794

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonicalization of domains in very specific edge cases, an access control rule may be skipped when it should match a request. The specific conditions that could lead to a security issue for vulnerability are: 1. The specific target resource of the attack must be using the forwarded au

PUBLISHED
Vendor
authelia
Product
authelia
Provider severity
LOW
Conflicts
1

CVE-2026-48793

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. SubtitleEncoder.ConvertTextSubtitleToSrtInternal (SubtitleEncoder.cs, line 382) interpolates the subtitle file path into FFmpeg command-line arguments without calling EncodingUtils.NormalizePath(). On Linux, filenames can contain double-quote characters, which break the argument quoting and allow injection of arbitrary FFmpeg arg

PUBLISHED
Vendor
jellyfin
Product
jellyfin
Provider severity
HIGH
Conflicts
0

CVE-2026-48792

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ignores EACCES errors when opening /dev/input/event* nodes, causing pusb_has_virtual_input_device() to return 0 (no virtual devices found) even when every open() call failed due to insufficient permissions. The caller in src/local.c cannot distinguish a clean absence of virtual devices from a permission-denied scan, and acts on the false negative by continuing authentication wi

PUBLISHED
Vendor
mcdope
Product
pam_usb
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48789

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared path containment helper rejects POSIX-style "../" traversal but does not reject Windows-style parent paths returned by path.relative(), such as "..". This vulnerability is fixed in 1.13.0.

PUBLISHED
Vendor
Mintplex-Labs
Product
anything-llm
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48788

Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Versions 1.6.0 through 1.15.0 contain a Cross-Site Scripting (XSS) vulnerability exploitable through content-type spoofing. The Remark42 image proxy fetches an arbitrary remote URL and re-serves the response from Remark42's own origin. During the download phase, the proxy determines whether the resource is an image by inspecting only the Content-Type header advertised by the remote se

PUBLISHED
Vendor
umputun
Product
remark42
Provider severity
HIGH
Conflicts
1

CVE-2026-48787

gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulnerability by injecting attacker-controlled Go source code through POST /autoCode/addFunc, and then invoking POST /autoCode/mcpStart to trigger a rebuild and restart of the standalone MCP service. This allows arbitrary operating system commands to be executed on the server with the privileges of the app

PUBLISHED
Vendor
flipped-aurora
Product
gin-vue-admin
Provider severity
HIGH
Conflicts
0

CVE-2026-48784

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13.

PUBLISHED
Vendor
symfony, symfony
Product
symfony, routing
Provider severity
MEDIUM
Conflicts
2

CVE-2026-48783

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint, /public/modify-subscription, could not change the persisted subscription tier, but it did execute enforcement-related side effects on the caller's own organization, including adjusting team-membe

PUBLISHED
Vendor
gitroomhq
Product
postiz-app
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48782

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous fix, CVE-2026-46678, did not decode, exposing cloud IAM short-term credentials. The previous remediation decoded only IPv4-mapped IPv6, 6to4, and the NAT64 well-known prefix, so the metadata guarantee did not hold for the

PUBLISHED
Vendor
pydantic, pydantic
Product
pydantic-ai, pydantic-ai-slim
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48781

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, including users regi

PUBLISHED
Vendor
gitroomhq
Product
postiz-app
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48780

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.

PUBLISHED
Vendor
forem
Product
forem
Provider severity
HIGH
Conflicts
0

CVE-2026-4878

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4.14, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Insights proxy 1.5, Red Hat Enterprise Linux 8, Red Hat Discovery 2, Red Hat OpenShift Container Platform 4.15, Red Hat Hardened Images, Red Hat OpenShift distributed tracing 3.9.0, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat OpenShift Container Platform 4.13, Red Hat AI Inference Server 3.3, Red Hat OpenShift Container Platform 4.14, Red Hat Discovery 2, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 7, Red Hat AI Inference Server 3.2, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Discovery 2, Red Hat OpenShift distributed tracing 3.9.2, Red Hat OpenShift distributed tracing 3.9.2, Red Hat Update Infrastructure 5, Cost Management Metrics Operator 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.18, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 9, Red Hat Discovery 2, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift distributed tracing 3.9.0, Red Hat Enterprise Linux 9, Red Hat Discovery 2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10, Cost Management Metrics Operator 4, Red Hat Insights proxy 1.5, Red Hat Enterprise Linux 10, Red Hat Discovery 2, Red Hat OpenShift distributed tracing 3.9.0, Red Hat Enterprise Linux 6, Cost Management Metrics Operator 4, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 7, Red Hat Hardened Images, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.16, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat AI Inference Server 3.3, Red Hat Update Infrastructure 5, Red Hat OpenShift Container Platform 4.15, Red Hat AI Inference Server 3.2, Red Hat OpenShift Container Platform 4.18, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 6, Red Hat OpenShift distributed tracing 3.9.2, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48779

A flaw was found in ws, an open source WebSocket client and server. A remote attacker can exploit this memory exhaustion vulnerability by sending a high volume of exceptionally small fragments and data chunks. This action forces the affected component to allocate and hold structural wrappers that consume excessive memory. Consequently, this leads to process termination and a denial of service (DoS) for the remote peer.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, websockets, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat Hardened Images, Red Hat JBoss Enterprise Application Platform Expansion Pack, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.19, OpenShift Pipelines, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift AI (RHOAI), Gatekeeper 3, Red Hat OpenShift Service Mesh 3.3, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat OpenShift Service Mesh 2.6, Red Hat Developer Hub 1.9, Cryostat 4, Red Hat Build of Podman Desktop, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.3, Cryostat 4, Red Hat Openshift Data Foundation 4.19, Red Hat Quay 3, Red Hat OpenShift Service Mesh 3.0, OpenShift Lightspeed, Red Hat OpenShift Service Mesh 3.2, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.18, Red Hat Enterprise Linux 10, Red Hat Hardened Images, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Red Hat JBoss Enterprise Application Platform 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Service Mesh 3.1, Red Hat Enterprise Linux AI (RHEL AI) 3, Node HealthCheck Operator, OpenShift Lightspeed, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat Connectivity Link 1, Cluster Observability Operator 1.5.0, OpenShift Service Mesh 3, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Red Hat Enterprise Linux 9, Red Hat Migration Toolkit 1.8, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Openshift Data Foundation 4.19, Red Hat Enterprise Linux 8, Red Hat Openshift Data Foundation 4.2, Red Hat Hardened Images, Red Hat Openshift Data Foundation 4.19, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Openshift Data Foundation 4.19, Red Hat Build of Podman Desktop - Tech Preview, Red Hat OpenShift Virtualization 4, OpenShift Lightspeed, Red Hat OpenShift Dev Spaces 3.29, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Openshift Data Foundation 4.2, Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Hardened Images, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, OpenShift Pipelines, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4, Red Hat Ansible Automation Platform 2, Red Hat Hardened Images, Red Hat Openshift Data Foundation 4.18, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Openshift Data Foundation 4.18, Self-service automation portal 2, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Service Mesh 2.6, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.19, Node HealthCheck Operator, Red Hat OpenShift Service Mesh 3.2, Red Hat Enterprise Linux 10, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Ansible Automation Platform 2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat build of Apache Camel - HawtIO 4, Red Hat Openshift Data Foundation 4.2, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Openshift Data Foundation 4.2, Red Hat Developer Hub 1.10, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.2, OpenShift Pipelines, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat Data Grid 8, Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.2, OpenShift Pipelines, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, ws, Cryostat 4 on RHEL 9, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Node HealthCheck Operator, Red Hat Ansible Automation Platform 2, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Service Mesh 3.0, Red Hat Openshift Data Foundation 4.2, Red Hat Build of Keycloak, Red Hat OpenShift Service Mesh 3.1, Cluster Observability Operator 1.5.0, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Fuse 7, Self-service automation portal 2, Red Hat Openshift Data Foundation 4.18, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Red Hat Discovery 2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Cluster Observability Operator 1.5.0, OpenShift Service Mesh 3, Cluster Observability Operator 1.5.0, Cryostat 4, Red Hat AMQ Broker 7, Red Hat OpenShift Dev Spaces 3.29, Red Hat Openshift Data Foundation 4.19, Red Hat Satellite 6, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images
Provider severity
HIGH
Conflicts
2