Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-45598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows 11 version 23H2, Windows 11 version 26H1, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2019, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2022, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45597

Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 23H2, Windows 11 Version 24H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45596

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2012, Windows 10 Version 22H2, Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2019, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2025, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-45595

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 11 version 23H2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows Server 2012 R2, Windows 10 Version 22H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45594

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2022, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2016, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 23H2, Windows Server 2019, Windows 11 Version 24H2, Windows 10 Version 21H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45593

Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows 11 version 23H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows Server 2019, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-45592

Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2022, Windows 10 Version 1809, Windows Server 2016, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 11 version 23H2, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-45591

A flaw was found in ASP.NET Core SignalR and Blazor Server. A remote attacker could send a specially crafted MessagePack payload containing deeply nested arrays that trigger excessive recursion and cause a stack overflow. This issue may result in application termination and a denial of service condition

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Microsoft, Microsoft, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Microsoft, Microsoft, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Hardened Images, ASP.NET Core 9.0, .NET 10.0, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, .NET 8.0, ASP.NET Core 8.0, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9, Microsoft Visual Studio 2026 version 18.6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, ASP.NET Core 10.0, Red Hat Hardened Images, Red Hat Hardened Images, .NET 9.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
3

CVE-2026-45588

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 11 version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-45586

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2025, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-45585

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider im

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45584

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Malware Protection Engine
Provider severity
HIGH
Conflicts
0

CVE-2026-45583

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server Subscription Edition RTM
Provider severity
HIGH
Conflicts
1

CVE-2026-45582

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters — such as customer or tenant identifiers, short secrets embedded in query strings, and signed request parameters — could therefore appear in stored

PUBLISHED
Vendor
czlonkowski
Product
n8n-mcp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45581

fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode serv

PUBLISHED
Vendor
hyperledger
Product
fabric-chaincode-java
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45580

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, without htmlspecialchars(). A canStream user can persist a key containing " plus an event handler via plugin/Live/saveLive.php, and any visitor (logged in or anonymous) opening the stream's live page executes attacker JavaScript in the platform origin.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4558

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Linksys
Product
MR9600
Provider severity
HIGH
Conflicts
2

CVE-2026-45578

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshellarg(). A ' in any of the three interpolated values ($users_id, $m3u8, $obj->liveTransmitionHistory_id) closes the quoted token and lets the attacker append arbitrary commands.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-45577

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.

PUBLISHED
Vendor
markmhendrickson
Product
neotoma
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45576

zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local filesystem destination root. This issue is fixed in version 2.0.3.

PUBLISHED
Vendor
openziti
Product
zrok
Provider severity
HIGH
Conflicts
0

CVE-2026-45575

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge response to the attacker's encryption key and POSTs it to the attacker's auth endpoint. This captures the

PUBLISHED
Vendor
oviva-ag, com.oviva.telematik
Product
epa4all-client, epa4all-client
Provider severity
HIGH
Conflicts
1

CVE-2026-45574

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential exchanges. This vulnerability is fixed in 1.2.2.

PUBLISHED
Vendor
oviva-ag, com.oviva.telematik
Product
epa4all-client, epa4all-client
Provider severity
HIGH
Conflicts
1

CVE-2026-45571

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.

PUBLISHED
Vendor
go-git
Product
go-git
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45570

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.

PUBLISHED
Vendor
go-git
Product
go-git
Provider severity
LOW
Conflicts
0

CVE-2026-4557

A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
code-projects
Product
Exam Form Submission
Provider severity
MEDIUM
Conflicts
2

CVE-2026-45569

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring containment — '..' in (a, b, c) evaluates to True only if any of a, b, c is equal to the literal string '..'. For any realistic path-traversal payload (../../etc/passwd, ..\\..\\etc\\pass

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
HIGH
Conflicts
1

CVE-2026-45568

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a server-side response from an attacker-chosen URL. This issue is fixed in version 2.0.3.

PUBLISHED
Vendor
openziti
Product
zrok
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45567

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches.

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
HIGH
Conflicts
1

CVE-2026-45566

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via window.location.replace(). The block does not consider the userinfo@host syntax. next=@evil.example/path produces https://victim.example@evil.example/path, which all modern browsers route to evil.exam

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45565

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else flow returns the metacharacter-stripped value without also enforcing the .. block. An attacker who appends a single ;, &, |, $, or backtick to a .. payload routes the value through

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
HIGH
Conflicts
1

CVE-2026-45564

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver is not run through EscapedString (Pydantic doesn't validate path segments declared as str) and the surrounding .. block is the broken tuple-membership patch from GHSA-vapt-004. An

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
HIGH
Conflicts
0

CVE-2026-45563

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in an unrelated group — can list any other user's full action audit trail (server IPs touched, configs deployed, services restarted). At time of publication, there are no publicly available patches.

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45561

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(f'http://{server_ip}:{agent_port}/...'). The path component is constrained only by Flask's default URL converter, which permits any value (including IPv4 literals like 169.254.169.254, RFC1918 ranges, and 127.0.0.1). At time of publication, there are

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45560

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string concatenation with no escaping. The frontend (app/static/js/script.js, log-viewer paths) uses .html(data) / .append(data) to inject the response body. Anyone able to write a line into a managed HAProxy/Nginx access log (i.e. anyone who can send an HT

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45559

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput, no LDAP escape — and inserted, a username like *)(mail=*)(cn=* injects additional clauses, allowing the admin to enumerate or harvest attributes outside the intended record. At time of publication, the

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45558

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped, and is rendered verbatim into the generated HAProxy configuration via the section.j2, global.j2, and defaults.j2 Ansible templates. Because Roxy-WI then pushes the generated config

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
CRITICAL
Conflicts
1

CVE-2026-45557

Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.

PUBLISHED
Vendor
Technitium
Product
DNS Server
Provider severity
MEDIUM
Conflicts
2

CVE-2026-45556

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The validation chain (_replace_config_path_to_correct → check_is_conf) only requires the path to contain a hard-coded service substring (nginx/haproxy/apache2/httpd/keepalived) and the

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
CRITICAL
Conflicts
1

CVE-2026-45555

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without any allowlist, signature check, or user confirmation; includeAnalyzers defaults to true, so no explicit opt-in is required. An attacker who can place a malicious .csproj referencing an attacker-controlled DLL in a location the victim opens w

PUBLISHED
Vendor
MarcelRoozekrans
Product
roslyn-codelens-mcp
Provider severity
HIGH
Conflicts
0

CVE-2026-45554

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse, which Uvicorn writes to the server log as a full traceback. Because the routes are reachable without authentication, a remote attacker can amplify log volume and consume disk and log-p

PUBLISHED
Vendor
zauberzeug
Product
nicegui
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45553

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes attacker-controlled content to ui.restructured_text(), an attacker can use standard Docutils directives (include, csv-table with :file:, raw with :file:) to read local files readable by the NiceGUI server process. Applications that only pass trusted static strings to ui.restructure

PUBLISHED
Vendor
zauberzeug
Product
nicegui
Provider severity
HIGH
Conflicts
0

CVE-2026-45552

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip, get_exporter_version, and get_task_status are not wrapped in page_for_admin and do not call roxywi_common.is_user_has_access_to_its_group(server_ip) or check_is_server_in_group(server_ip).

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
CRITICAL
Conflicts
1

CVE-2026-45551

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module injects the email_font_size setting directly into JavaScript without escaping. By combining these two issues, any low-privileged authenticated user can overwrite an administrator's email_font_size setti

PUBLISHED
Vendor
Intermesh
Product
groupoffice
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45550

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to it. The downstream SQL update functions update_smon, update_smonHttp, update_smonTcp, update_smonPing, update_smonDns (app/modules/db/smon.py:515-562) all execute WHERE smon_id = ? wi

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4555

A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-513
Provider severity
HIGH
Conflicts
2

CVE-2026-45549

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the server_ip form field. Any authenticated user, including role 4 (guest), can start, stop, or restart the roxy-wi-smon-agent systemd unit on any server they can name. Roxy-WI executes the systemd action ov

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
HIGH
Conflicts
1

CVE-2026-45548

Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist validation that is consistently applied to all other automation steps. This allows an authenticated user to trigger server-side requests to internal network addresses. This vulnerability is fixed in 3.34.8.

PUBLISHED
Vendor
Budibase
Product
budibase
Provider severity
HIGH
Conflicts
0

CVE-2026-45545

Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored injection. With carefully crafted input it is possible to break out of the length limitation. The attacker could use this to extract information from the database, or modify data. This issue

PUBLISHED
Vendor
nextcloud
Product
security-advisories
Provider severity
HIGH
Conflicts
0

CVE-2026-45544

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0.

PUBLISHED
Vendor
nextcloud
Product
security-advisories
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45543

Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to uploaded files for forms where that user previously had results access. This issue has been patched in version 5.2.7.

PUBLISHED
Vendor
nextcloud
Product
security-advisories
Provider severity
MEDIUM
Conflicts
0