Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-46605

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Apache Software Foundation
Product
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All
Provider severity
MEDIUM
Conflicts
1

CVE-2026-46604

The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/tiff
Provider severity
HIGH
Conflicts
0

CVE-2026-46602

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/tiff
Provider severity
HIGH
Conflicts
0

CVE-2026-46601

The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.

PUBLISHED
Vendor
golang.org/x/image, golang.org/x/image
Product
golang.org/x/image/webp, golang.org/x/image/webp
Provider severity
HIGH
Conflicts
1

CVE-2026-46600

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

PUBLISHED
Vendor
golang.org/x/net
Product
golang.org/x/net/dns/dnsmessage
Provider severity
HIGH
Conflicts
1

CVE-2026-4660

A flaw was found in the go-getter library. A remote attacker could exploit this vulnerability by providing a maliciously crafted URL during certain git operations. This could allow the attacker to perform arbitrary file reads on the file system, potentially leading to the disclosure of sensitive information.

PUBLISHED
Vendor
Red Hat, HashiCorp, Red Hat, Red Hat, Red Hat
Product
Red Hat Trusted Artifact Signer 1.3, Tooling, Red Hat Trusted Artifact Signer, Red Hat Trusted Artifact Signer, Red Hat OpenShift Container Platform 4
Provider severity
HIGH
Conflicts
3

CVE-2026-46599

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

PUBLISHED
Vendor
golang.org/x/image
Product
golang.org/x/image/tiff
Provider severity
HIGH
Conflicts
1

CVE-2026-46598

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

PUBLISHED
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh/agent
Provider severity
MEDIUM
Conflicts
1

CVE-2026-46597

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

PUBLISHED
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh
Provider severity
HIGH
Conflicts
0

CVE-2026-46595

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This is a follow-on to incomplete coverage from the CVE-2024-45337 fix.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, golang.org/x/crypto, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Builds 1.7.1, DevWorkspace Operator 0.42, Red Hat Enterprise Linux AI 3.4, Red Hat Advanced Cluster Management for Kubernetes 2, Zero Trust Workload Identity Manager, Red Hat Openshift Data Foundation 4.22, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat OpenShift Builds 1.8.1, OpenShift API for Data Protection 1.6, Red Hat OpenStack Platform 16.2, Red Hat OpenShift on AWS, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 8, Red Hat Openshift Data Foundation 4.22, Red Hat OpenStack Platform 18.0, Red Hat OpenShift Container Platform 4, Red Hat Trusted Artifact Signer 1.4, Red Hat Openshift Data Foundation 4.22, Confidential Compute Attestation, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 9, Red Hat OpenStack Platform 16.2, Red Hat OpenShift AI (RHOAI), RHEM 1.1 for RHEL 10, Red Hat Openshift Data Foundation 4.22, Security Profiles Operator, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, RHEM 1.0 for RHEL 9, Red Hat OpenShift Dev Spaces 3.29, Red Hat Openshift Data Foundation 4.22, OpenShift Serverless, Red Hat OpenShift Builds 1.8.1, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI 3.4, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, golang.org/x/crypto/ssh, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux AI (RHEL AI) 3, Multicluster Engine for Kubernetes, Red Hat Quay 3.15, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, cert-manager Operator for Red Hat OpenShift, Red Hat Hardened Images, Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Enterprise Linux AI 3.4, Red Hat OpenShift AI (RHOAI), External Secrets Operator for Red Hat OpenShift, Red Hat Enterprise Linux AI 3.4, Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.8, Red Hat OpenStack Platform 17.1, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.22, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux AI 3.4, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.8, Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.8, Red Hat Enterprise Linux 9, RHEM 1.1 for RHEL 9, Red Hat Ceph Storage 9, Red Hat Enterprise Linux 10, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat Openshift Data Foundation 4.22, Red Hat Enterprise Linux 8, Multicluster Engine for Kubernetes, Zero Trust Workload Identity Manager - Tech Preview, Red Hat OpenShift GitOps, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, multicluster engine for Kubernetes 2.8, Red Hat Enterprise Linux AI 3.4, Red Hat Edge Manager 1.0, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Security 4.9, OpenShift Serverless, Red Hat OpenShift GitOps, Red Hat Quay 3, Red Hat Enterprise Linux 9, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.22, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift for Windows Containers, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, OpenShift Pipelines, Red Hat Enterprise Linux AI 3.4, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Multicluster Engine for Kubernetes, Red Hat OpenShift AI 3.3
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-46594

A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1.

PUBLISHED
Vendor
PHP Jabbers
Product
PHP Poll Script
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46593

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.

PUBLISHED
Vendor
PHP Jabbers
Product
PHP Poll Script
Provider severity
HIGH
Conflicts
0

CVE-2026-46592

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values (CxfConstants.OPERATION_NAME / OPERATION_NAMESPACE) were the plain strings operationName / operationNamespace. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrate

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
1

CVE-2026-46591

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property values by binding them as query parameters ($paramN), but the property names (the JSON keys of that map) were still concatenated into the query string verbatim in Neo4jProducer.retriev

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-46590

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the configured secret backend by deserializing a Base64-wrapped value with a raw java.io.ObjectInputStream.readObject() and no ObjectInputFilter or class allow-list; the cast to KeyMetadat

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-4659

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable debug output in widget settings. The URLtoRelative() function only performs a simple string replacement to remove the site's base URL without sanitizing path traversal sequences (../

PUBLISHED
Vendor
unitecms
Product
Unlimited Elements For Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-46588

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-46587

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.14.8, 4.18.3, 4.21.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-46586

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache OFBiz
Provider severity
HIGH
Conflicts
1

CVE-2026-46585

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain string QUERY (and RETURN_LUCENE_DOCS for HEADER_RETURN_LUCENE_DOCS). Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass fr

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel Lucene
Provider severity
HIGH
Conflicts
1

CVE-2026-46584

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Component. The camel-mail producer (MailProducer.getSender) scanned the outgoing Exchange for message headers in the mail.smtp. / mail.smtps. namespace and, when any were present, built a per-message JavaMail sender with those values applied as JavaMail session properties, overriding the endpoint configuration. This namespace is Camel-internal - only MailProducer interprets i

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel Mail
Provider severity
LOW
Conflicts
1

CVE-2026-46582

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific re

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
LOW
Conflicts
0

CVE-2026-46580

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse Theia
Provider severity
HIGH
Conflicts
1

CVE-2026-4658

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and including, 6.0.4. This is due to insufficient output escaping in the render_callback() function where these attributes are placed into class and data-id HTML attributes using raw sprintf() and implode() without esc_attr() e

PUBLISHED
Vendor
wpdevteam
Product
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46579

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.18
Provider severity
HIGH
Conflicts
1

CVE-2026-46562

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the ChangeMissionDatabase privilege could override an algorithm through the MdbOverrideApi.updateAlgorithm endpoint and supply JavaScript that reaches arbitrary Java classes (for example Java.type("java.lang.Runtime").getRun

PUBLISHED
Vendor
yamcs
Product
yamcs
Provider severity
CRITICAL
Conflicts
1

CVE-2026-46561

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An authenticated attacker can supply a URL pointing to an attacker-controlled server that responds with a 302 redirect to an internal/private IP address, bypassing the is_global_host() check on the initial URL. This vulnerability is fixed in 0.5.0b3.dev100.

PUBLISHED
Vendor
pyload
Product
pyload
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46559

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
1

CVE-2026-46558

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.

PUBLISHED
Vendor
makeplane
Product
plane
Provider severity
HIGH
Conflicts
1

CVE-2026-46557

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument. This issue has been patched in version 7.1.2-23.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46556

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services. This is a blind SSRF with confirmed internal port scanning and internal API triggering capabilities. Version 2.2.1 patches the issue.

PUBLISHED
Vendor
flaskbb
Product
flaskbb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46555

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute `media_path` parameter without confining it to a safe directory. Combined, these issues allow any local process running as the same user as the bridge to send WhatsApp messages from

PUBLISHED
Vendor
verygoodplugins
Product
whatsapp-mcp
Provider severity
HIGH
Conflicts
1

CVE-2026-46554

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authenticate requests until their cache entry expired, because the auth cache was not invalidated by token value at deletion time. The API token deletion path removed the database row but did not evict the token-value keyed entry from the auth cache. The auth middleware therefore continued to accept the deleted token until the cache entry aged out, leaving a deletion-to-revocation windo

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
LOW
Conflicts
0

CVE-2026-46553

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC_ATTACHMENT_FIELD_SIZE against either the remote file's advertised Content-Length or the decoded length of a data: URI, allowing an authenticated user to bypass the configured per-file size limit. This vulnerability is fixed in 2026.04.1.

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
LOW
Conflicts
0

CVE-2026-46552

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (xc-shared-base-id), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem the invite via the normal signup flow and retain authenticated access even after the owner revoked the shared link. Shared-base sessions

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46551

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attachment API did not enforce NC_ATTACHMENT_FIELD_SIZE against the remote content-length or against the response stream. An authenticated user (Editor+) could direct the server to download arbitrarily large files, exhausting disk space and causing denial of service. In packages/nocodb/src/services/attachments.service.ts, the HEAD probe read content-length but never compared it to NC

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46550

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing both the secure flag and the sameSite attribute. Over plain HTTP the cookie could be intercepted on the network; without sameSite, browsers attached it to cross-site POSTs, enabling CSRF against the token-refresh endpoint. This vulnerability is fixed in 2026.04.1.

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4655

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. The function fetches SVG content using wp_safe_remote_get() and then directly echoes it to the page without any sanitization, only applying a preg_replace() to add attributes to the SVG tag which

PUBLISHED
Vendor
bdthemes
Product
Element Pack – Widgets, Templates & Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46549

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but the ACL middleware never consulted either. An OAuth token issued with a restricted scope (e.g. MCP-only) therefore inherited the full permissions of the underlying user across all routes; the granted_resources.base_id restriction was bypassed on org-level endpoints that don't populate req.context.base_id. This vulnerabil

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
LOW
Conflicts
0

CVE-2026-46548

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because httpAgent / httpsAgent were passed as part of the request body rather than the axios config. An authenticated user with hook-creation permission could direct outbound POST requests to arbitrary internal hosts. This vulnerability is fixed in 2026.04.1.

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46547

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in the Page Leaving Warning page. The ncRedirectUrl and ncBackUrl query parameters are used in window.location.href and <a> tag bindings without validation, allowing javascript: URI injection. This vulnerability is fixed in 2026.04.1.

PUBLISHED
Vendor
nocodb
Product
nocodb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46546

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0.

PUBLISHED
Vendor
frappe
Product
lms
Provider severity
LOW
Conflicts
0

CVE-2026-46545

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-service vulnerability in MerkleRadixTrie::put_chunk allows any state-sync peer to crash any node performing state synchronization (freshly joining nodes and recovering nodes). This issue has been patched in version 1.5.0.

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
HIGH
Conflicts
0

CVE-2026-46544

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an existing in-memory session object if that session_id already exists. If a prior session has completed and remains in memory with populated results, a different authenticated client can send a new TASK message using the same session_id. The server re-enters the existing session object and

PUBLISHED
Vendor
microsoft
Product
UFO
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46543

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls get_epoch_chunks which iterates backwards through macro blocks using Policy::macro_block_before. When it reaches the genesis block number, macro_block_before panics with "No macro blocks before genesis block". This issue has been patc

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46542

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. Ed25519PublicKey::delinearize() in keys/src/multisig/mod.rs called .unwrap() on curve point decompression, which panics when a public key is constructed from 32 bytes that do not represent a valid point on the Ed25519 curve. Ed25519PublicKey construction only validates by

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46541

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle_dht_get(), the DhtResults accumulator is only initialized when the first DHT record passes verification. If the first record fails (from a malicious DHT node), DhtResults is never created, and all subsequent valid records are discarded with "DHT inconsistent state" errors. This issue has been patched in version 1.4.0.

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
HIGH
Conflicts
0

CVE-2026-46540

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork chain whose tip is a macro block (checkpoint or election), it only updates self.head but fails to update self.macro_head, self.election_head, self.current_validators, or store the election header in the chain_store. This is in direct contrast with the full Blockchain::rebranch() at blockchain/src/blockchain/push.rs:

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4654

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific ticket being requested. This makes it possible for authenticated attackers, with subscriber-level access and above, to access sensitive information from all support tickets in the system

PUBLISHED
Vendor
awesomesupport
Product
Awesome Support – WordPress HelpDesk & Support Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-46539

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the function to return true without performing any cryptographic verification when get_interlink_hops yields an empty hop list. This occurs when the target block is at the election block position immediately preceding the election head's epoch. An attacker providing transaction inclusion proofs can forg

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
MEDIUM
Conflicts
0