Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-45465

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45464

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45463

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Office 2016, Microsoft Office LTSC 2021, Microsoft Office for Android, Microsoft Office 2019, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
2

CVE-2026-45462

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45461

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft Office for Android, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-45460

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office 2019, Microsoft Office for Android, Microsoft Office LTSC for Mac 2024
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4546

A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitability is said to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Flos Freeware
Product
Notepad2
Provider severity
HIGH
Conflicts
2

CVE-2026-45459

Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2024
Provider severity
LOW
Conflicts
1

CVE-2026-45458

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Word 2016, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server Subscription Edition, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2024, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-45457

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac
Provider severity
HIGH
Conflicts
1

CVE-2026-45456

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office 365 for Mac, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft Office LTSC 2024, Microsoft Word 2016, Microsoft SharePoint Enterprise Server 2016, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2021, Microsoft Office 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-45455

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC 2021, Microsoft Office 365 for Mac, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Office Online Server, Microsoft Office LTSC for Mac 2021, Microsoft Excel 2016, Microsoft Office 2019
Provider severity
LOW
Conflicts
1

CVE-2026-45454

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45453

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4545

A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manipulation results in uncontrolled search path. The attack is only possible with local access. The attack is considered to have high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Flos Freeware
Product
Notepad2
Provider severity
HIGH
Conflicts
2

CVE-2026-45448

CWE-601 URL redirection to untrusted site ('open redirect')

PUBLISHED
Vendor
ntop
Product
ntopng
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45447

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling app

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, OpenSSL, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 10, Red Hat Discovery 2, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10, Multicluster Engine for Kubernetes, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 10, OpenSSL, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7, Red Hat Insights proxy 1.5, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Update Infrastructure 5, multicluster engine for Kubernetes 2.8, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Discovery 2, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Cost Management 4, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
3

CVE-2026-45446

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers. AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not e

PUBLISHED
Vendor
OpenSSL
Product
OpenSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45445

Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality. If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not

PUBLISHED
Vendor
OpenSSL
Product
OpenSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-45444

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

PUBLISHED
Vendor
WP Swings
Product
Gift Cards For WooCommerce Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45443

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.

PUBLISHED
Vendor
ADD-ONS.ORG
Product
PDF for Elementor Forms + Drag And Drop Template Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45442

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3.

PUBLISHED
Vendor
Brainstorm Force
Product
Presto Player
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45441

Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.

PUBLISHED
Vendor
Magepeople inc.
Product
WpEvently
Provider severity
HIGH
Conflicts
0

CVE-2026-4544

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler. Executing a manipulation of the argument homepage/hostname/login_page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-WN578W2
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-45439

Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

PUBLISHED
Vendor
Realtyna
Product
Realtyna Organic IDX plugin
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45438

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

PUBLISHED
Vendor
WebToffee
Product
Smart Coupons for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-45437

Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.

PUBLISHED
Vendor
Bhavin Thummar
Product
Product Filter Widget for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-45436

Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.

PUBLISHED
Vendor
Rain-Task Ltd.
Product
WPBakery Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45435

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.

PUBLISHED
Vendor
Melapress
Product
WP Activity Log
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45434

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache OFBiz
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45433

This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle (MITM) attacks on the targeted device.

PUBLISHED
Vendor
GX INDIA, GX INDIA
Product
GX Earth 1010, GX Earth 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-45432

This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obtain sensitive authentication information, which could lead to unauthorized access to the targeted device.

PUBLISHED
Vendor
GX INDIA, GX INDIA
Product
GX Earth 1010, GX Earth 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-45431

This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands on the targeted device. Successful exploitation of this vulnerability could allow the attacker to perform remote code execution with root privileges on the targeted device.

PUBLISHED
Vendor
GX INDIA, GX INDIA
Product
GX Earth 1010, GX Earth 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-45430

The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.

PUBLISHED
Vendor
Backdrop CMS contributed projects
Product
backdrop-contrib/salesforce
Provider severity
HIGH
Conflicts
0

CVE-2026-4543

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is an unknown function of the file /cgi-bin/firewall.cgi of the component POST Request Handler. Performing a manipulation of the argument dmz_flag/del_flag results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-WN578W2
Provider severity
MEDIUM
Conflicts
2

CVE-2026-45426

Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested path segment when verifying the JWT's `sub` claim. `str.lstrip()` strips any of a *set* of characters from the left (not a prefix), so a JWT issued for a Dag named e.g. `dag_a` would authorize log access to any other Dag whose name began wi

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
LOW
Conflicts
0

CVE-2026-4542

A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
SSCMS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-45419

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled staticResource names and Base64 content, allowing path traversal and arbitrary file writes because only / was used when extracting the file name. This issue is fixed in version 2.10.23.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
HIGH
Conflicts
0

CVE-2026-45418

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #132.

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
HIGH
Conflicts
0

CVE-2026-45417

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with executeQuery in io.dataease.datasource.provider.CalciteProvider#checkStatus, allowing SQL injection against DB2, SQL Server, PostgreSQL, and other affected datasources. This issue is fixed in version 2.10.23.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
HIGH
Conflicts
0

CVE-2026-45416

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (S

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Keycloak, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces, OpenShift Serverless, Streams for Apache Kafka 2.9.4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift Dev Spaces, OpenShift Serverless, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat OpenShift AI (RHOAI), Red Hat build of Quarkus 3.27.4.SP1, OpenShift Serverless, Red Hat Build of Keycloak, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Red Hat build of Apache Camel - HawtIO 4, Red Hat AMQ Broker 7, OpenShift Serverless, OpenShift Serverless, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat build of Debezium 3, Red Hat OpenShift Dev Spaces, OpenShift Serverless, Red Hat Single Sign-On 7, Red Hat AMQ Clients, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, netty, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform 8, Cryostat 4 on RHEL 9, Red Hat Build of Keycloak, Red Hat build of Quarkus 3.33.2.SP1, OpenShift Serverless, Red Hat Fuse 7, Red Hat OpenShift AI (RHOAI), streams for Apache Kafka 3, Red Hat Build of Keycloak, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces, Red Hat Data Grid 8.6.2, Red Hat JBoss Enterprise Application Platform 7, Red Hat OpenShift Dev Spaces, Red Hat build of Apicurio Registry 3, Red Hat Satellite 6, Red Hat Build of Keycloak, Red Hat Offline Knowledge Portal 1.2.5, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
2

CVE-2026-45413

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute force (hashcat). This vulnerability is fixed in 2.9.1.

PUBLISHED
Vendor
1Panel-dev
Product
MaxKB
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45412

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2.9.1.

PUBLISHED
Vendor
1Panel-dev
Product
MaxKB
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45411

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the next value. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerabi

PUBLISHED
Vendor
Red Hat, Red Hat, patriksimek
Product
Self-service automation portal 2, Red Hat Developer Hub, vm2
Provider severity
CRITICAL
Conflicts
2

CVE-2026-45410

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed in the database, the backend performed a bcrypt password comparison before returning a 401 Unauthorized, adding ~370 ms of latency. When the email did not exist, the backend returned immediately (~10 ms). This ~14× timing difference could be detected without any difference in HTT

PUBLISHED
Vendor
mauriceboe
Product
TREK
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4541

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this

PUBLISHED
Vendor
janmojzis
Product
tinyssh
Provider severity
LOW
Conflicts
2

CVE-2026-45409

Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi

PUBLISHED
Vendor
kjd
Product
idna
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45408

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<EOF instead of <<'EOF') in fn-git-create-hook() at plugins/git/internal-functions:378. On git push, bash interprets the semicolon as a command separator, executing arbitrary commands as the dokku user

PUBLISHED
Vendor
dokku
Product
dokku
Provider severity
CRITICAL
Conflicts
0

CVE-2026-45407

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leaving git credentials readable by any local user who can traverse the dokku home directory. This vulnerability is fixed in 0.38.2.

PUBLISHED
Vendor
dokku
Product
dokku
Provider severity
MEDIUM
Conflicts
0

CVE-2026-45406

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containing a single quote breaks the quoting and allows command substitution to execute arbitrary commands on the host as the dokku user during the app's next deploy. This vulnerability is fixed in 0.38.2.

PUBLISHED
Vendor
dokku
Product
dokku
Provider severity
CRITICAL
Conflicts
0