Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-48580

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Office Online Server, Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Office 365 for Mac
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4858

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
HIGH
Conflicts
0

CVE-2026-48579

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Exchange Online
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48578

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2016, Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-48576

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2012, Windows Server 2012 R2, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-48575

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019, Windows 10 Version 1809, Windows 11 version 23H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-48574

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2022, Windows Server 2016, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 11 version 23H2, Windows Server 2019, Windows 11 Version 23H2, Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-48573

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019, Windows Server 2012 R2, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-48572

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 23H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-48571

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-48570

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 23H2, Windows Server 2019, Windows Server 2012, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-4857

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects.  Until a remediating security fix or patches containing this security fix are installed, the Debug Pages Read Only capability and any custom capabilities that contain the ViewAccessDebugPag

PUBLISHED
Vendor
SailPoint Technologies
Product
IdentityIQ
Provider severity
HIGH
Conflicts
0

CVE-2026-48569

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
HIGH
Conflicts
1

CVE-2026-48568

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 11 version 23H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2025, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2012, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-48567

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure HorizonDB
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48566

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48565

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Narrator Braille
Provider severity
HIGH
Conflicts
0

CVE-2026-48564

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2025, Windows Server 2016, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-48563

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2019, Windows 11 version 23H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-48562

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft Edge Copilot for IOS, Microsoft Edge Copilot for Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48560

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48559

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitiz

PUBLISHED
Vendor
epoupon
Product
lms
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48558

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may

PUBLISHEDCISA KEV
Vendor
SimpleHelp
Product
SimpleHelp
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48557

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .php stems in saved filenames. The blocklist also omits executable extensions including .php6, .shtml, and .htaccess. The double-extension bypass requires a legacy Apache AddHandler configuration to achi

PUBLISHED
Vendor
spatie
Product
laravel-medialibrary
Provider severity
HIGH
Conflicts
1

CVE-2026-48555

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.

PUBLISHED
Vendor
spatie
Product
laravel-medialibrary
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48547

KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() call in the release.yml workflow. Attackers can have a malicious pull request merged to trigger the GitHub Actions runner with contents write permissions and access to GITHUB_TOKEN.

PUBLISHED
Vendor
lingdojo
Product
kana-dojo
Provider severity
HIGH
Conflicts
1

CVE-2026-48546

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull request modifying messages.cjs to import arbitrary Node.js modules, bypassing sandbox restrictions and achieving remote code execution with full GitHub Actions runner privileges including access to AUT

PUBLISHED
Vendor
lingdojo
Product
kana-dojo
Provider severity
HIGH
Conflicts
1

CVE-2026-48545

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment.

PUBLISHED
Vendor
gradio-app
Product
gradio
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48544

Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended module directory by exploiting an incomplete path containment check using str.startswith() without a trailing path separator. Attackers can send crafted GET requests with path traversal segments targeting a prefix-matching sibling directory on disk, bypassing the directory containme

PUBLISHED
Vendor
Avaiga
Product
taipy
Provider severity
HIGH
Conflicts
1

CVE-2026-48539

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding and is executed in the browser of the user who created the scheduled report when they subsequently view the MailInsights page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48538

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML via the configured folders parameter to /Archiver/ImportSettingsWizard.ashx. The injected payload is stored by ImportSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Archive Assistant default import settings.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48537

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated attackers to inject arbitrary web script or HTML via the excluded extensions parameter to /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored by FileArchiveAssistantWizard.btnSave_Click() without output encoding and is executed in the browsers of users who subsequently view the File Archive Assistant settings page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48536

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The injected payload is stored by GeneralSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the General Settings page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48535

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx. The injected payload is stored by CallHomeSettingsWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the General Settings Additional Settings page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48534

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the IMAP Server configuration page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48532

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the File History Retention Policies page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48531

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Retention and Spam Policies page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48530

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is stored by CategorizationPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Classification Rules page.

PUBLISHED
Vendor
GFI Software
Product
GFI Archiver
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4853

The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insufficient input validation on the fileName parameter in the file upload handler. The plugin sanitizes the fileName parameter using sanitize_text_field(), which removes HTML tags but does not prevent path traversal sequences like '../'. The unsanitized filename is then directly concatenated in Upload::get

PUBLISHED
Vendor
backupguard
Product
JetBackup – Backup, Restore & Migrate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48529

GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from different users share this singleton and their lockdown-related GraphQL queries are executed using the first user's credentials. The singleton is never updated to reflect later users' tokens. This vulnerability

PUBLISHED
Vendor
github
Product
github-mcp-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48527

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name. @haxtheweb/haxcms-nodejs 26.0.1 and haxcms-php 26.0.2 patch the issue.

PUBLISHED
Vendor
haxtheweb, haxtheweb
Product
haxcms-php, haxcms-nodejs
Provider severity
HIGH
Conflicts
1

CVE-2026-48526

A flaw was found in PyJWT, a Python library for JSON Web Token (JWT) implementation. When decoding JWTs, the library fails to validate the use of JSON Web Keys (JWK) in the HMAC algorithm while also supporting asymmetric algorithms. This allows a remote attacker to use the issuer's public key as the secret key for the HMAC algorithm, leading to the ability to forge JWTs. This vulnerability can result in authentication bypass or unauthorized access.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, jpadilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat AI Inference Server, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.19 for RHEL 9, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.7, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat OpenShift AI 2.25, Red Hat Hardened Images, Red Hat AI Inference Server, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Hardened Images, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.7, Red Hat Enterprise Linux AI (RHEL AI) 3, pyjwt, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Migration Toolkit for Applications 8.2, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2.6, OpenShift Lightspeed, Red Hat Trusted Artifact Signer, Red Hat Trusted Artifact Signer 1.3, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2.7, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.18, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.7, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2.6, Red Hat Quay 3.1, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat AI Inference Server 3.3, Red Hat Satellite 6.18, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Quay 3.12, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.15, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Quay 3.16, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.9, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.5, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10.0 Extended Update Support
Provider severity
HIGH
Conflicts
2

CVE-2026-48525

PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled “work amplifier”: a

PUBLISHED
Vendor
jpadilla
Product
pyjwt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48524

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be

PUBLISHED
Vendor
jpadilla
Product
pyjwt
Provider severity
LOW
Conflicts
1

CVE-2026-48523

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv

PUBLISHED
Vendor
jpadilla
Product
pyjwt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48522

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame

PUBLISHED
Vendor
jpadilla
Product
pyjwt
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48520

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM. The files path can be any path supported by the storage - it can be either a loc

PUBLISHED
Vendor
langflow-ai
Product
langflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4852

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
webzunft
Product
Image Source Control Lite – Show Image Credits and Captions
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48519

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Pyt

PUBLISHED
Vendor
langflow-ai
Product
langflow
Provider severity
CRITICAL
Conflicts
0