Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-44421

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large out-of-bounds heap write and may lead to client crashes or code execution. This bug is reachable from a

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, FreeRDP
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, FreeRDP
Provider severity
HIGH
Conflicts
2

CVE-2026-44420

A heap-buffer overflow vulnerability exists in the FreeRDP server's clipboard channel. A remote attacker can exploit this by sending a specially crafted message to the server, which can crash the service (Denial of Service) or potentially allow the attacker to execute arbitrary code.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, FreeRDP, Red Hat
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, FreeRDP, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
2

CVE-2026-4442

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44418

EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query parameters that use non-standard validation types. This is caused by an incomplete fix for CVE-2026-35184.

PUBLISHED
Vendor
phili67
Product
ecclesiacrm
Provider severity
HIGH
Conflicts
0

CVE-2026-44417

A flaw was found in Apache CXF. Untrusted users, if allowed to configure Java Message Service (JMS) for Apache CXF, can exploit this vulnerability to achieve remote code execution (RCE). This issue arises from an incomplete fix for a prior security flaw, indicating an alternative path that could lead to code execution.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat
Product
Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Fuse 7, Red Hat Single Sign-On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 7, Apache CXF, Red Hat JBoss Enterprise Application Platform 8
Provider severity
HIGH
Conflicts
2

CVE-2026-44413

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

PUBLISHED
Vendor
JetBrains
Product
TeamCity
Provider severity
HIGH
Conflicts
0

CVE-2026-44412

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected applications contain a stack based overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

PUBLISHED
Vendor
Siemens
Product
Solid Edge SE2026
Provider severity
HIGH
Conflicts
1

CVE-2026-44411

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR files. An attacker could leverage this vulnerability to execute code in the context of the current process.

PUBLISHED
Vendor
Siemens
Product
Solid Edge SE2026
Provider severity
HIGH
Conflicts
1

CVE-2026-44410

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry out malicious attacks.

PUBLISHED
Vendor
ZTE
Product
ZXUniPOS NDS-LTE
Provider severity
LOW
Conflicts
0

CVE-2026-4441

Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
0

CVE-2026-44409

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, causing the risk of information disclosure.

PUBLISHED
Vendor
ZTE
Product
MU5250
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44408

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  modify configuration through the interface.

PUBLISHED
Vendor
ZTE
Product
MU5250
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44407

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

PUBLISHED
Vendor
ZTE
Product
ZXCLOUD iRAI
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44406

ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM privileges, successful hijacking enables local arbitrary code execution, privilege escalation, and memory corruption.

PUBLISHED
Vendor
ZTE
Product
ZXCLOUD iRAI
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44405

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

PUBLISHED
Vendor
Paramiko
Product
Paramiko
Provider severity
LOW
Conflicts
0

CVE-2026-44403

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session values into Lua source code without proper escaping of closing delimiters, causing the injected code to be executed when the poisoned session is loaded via loadfile().

PUBLISHED
Vendor
Wing FTP Server
Product
Wing FTP Server
Provider severity
HIGH
Conflicts
1

CVE-2026-44400

MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.

PUBLISHED
Vendor
MailEnable
Product
MailEnable Enterprise Premium
Provider severity
HIGH
Conflicts
1

CVE-2026-4440

Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Critical)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-44394

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a u

PUBLISHED
Vendor
OpenStack
Product
Keystone
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44393

A flaw was found in OpenStack oslo.messaging. The RabbitMQ driver does not properly verify the hostname of the message broker when establishing a TLS (Transport Layer Security) connection. An attacker capable of intercepting control-plane network traffic can exploit this vulnerability to impersonate the RabbitMQ broker. This allows the attacker to perform a man-in-the-middle attack, potentially leading to the disclosure or manipulation of sensitive RPC (Remote Procedure Call) and notification tr

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, n/a
Product
Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4, n/a
Provider severity
HIGH
Conflicts
2

CVE-2026-44392

Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be executed.

PUBLISHED
Vendor
Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd.
Product
Movable Type Premium (Advanced Edition), Movable Type Premium, Movable Type Premium (Advanced Edition), Movable Type Advanced, Movable Type Premium (Advanced Edition), Movable Type Advanced, Movable Type Advanced, Movable Type Advanced, Movable Type, Movable Type, Movable Type Premium, Movable Type, Movable Type, Movable Type Premium
Provider severity
MEDIUM
Conflicts
2

CVE-2026-44390

A flaw was found in Unbound. A remote attacker can exploit this vulnerability by sending specially crafted DNS responses containing very large Resource Record Sets (RRsets) that require name compression. This can cause Unbound to spend a significant amount of time processing these responses, leading to degraded performance and potentially a denial of service (DoS) for legitimate users.

PUBLISHED
Vendor
NLnet Labs, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Unbound, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6, Red Hat Hardened Images, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-4439

Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-44387

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WAB-M2133, WAB-S1167-PS, WAB-S1775, WAB-M1775-PS, WAB-I1750-PS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-44383

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

PUBLISHED
Vendor
Hydro-Québec
Product
Le Circuit Electrique charging station backend
Provider severity
HIGH
Conflicts
1

CVE-2026-44381

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters and incorporated them into database query ordering clauses without sufficient validation of the requested field name. An attacker with access to the affected endpoints could craft a malicious ordering

PUBLISHED
Vendor
MISP
Product
MISP
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44380

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within the same organization. Because non-site administrators were not explicitly prevented from accessing or resetting site administrator auth keys, an attacker with organization administrator privileges coul

PUBLISHED
Vendor
MISP
Product
MISP
Provider severity
HIGH
Conflicts
0

CVE-2026-4438

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, The GNU C Library, Siemens
Product
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, glibc, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Provider severity
MEDIUM
Conflicts
2

CVE-2026-44379

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID values, potentially causing integrity issues or unexpected behaviour in code paths that assume Collection UUIDs are valid identifiers. This vulnerability is fixed in 2.5.37.

PUBLISHED
Vendor
MISP
Product
MISP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44378

Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibits indefinite length encodings. This vulnerability is fixed in 3.12.0.

PUBLISHED
Vendor
randombit
Product
botan
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44377

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates and Documents). The application unsafely evaluates user-supplied input directly through the Smarty template engine. By leveraging this, an authenticated attacker with administrative privileges can bypass current restrictions and call native PHP functions within the templates, such as readgzfile() to read

PUBLISHED
Vendor
cubecart
Product
v6
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44376

CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic flaw in classes/catalogue.class.php, user input is reflected without sanitization only when a search returns exactly one product. This flaw bypasses current filters, allowing an attacker to execute malicious JavaScript in the victim's browser, leading to session hijacking, site defacement, or phishing. This vulnerability is fixed in

PUBLISHED
Vendor
cubecart
Product
v6
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44375

Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack contains an uncontrolled stack allocation vulnerability in DateTime decoding. A malicious MessagePack payload can declare an oversized timestamp extension length, causing the reader to allocate an attacker-controlled number of bytes on the stack. This can trigger a StackOverflowException, which is not catchable by user code and terminates the process. This vulnerability is fixe

PUBLISHED
Vendor
AArnott
Product
Nerdbank.MessagePack
Provider severity
HIGH
Conflicts
0

CVE-2026-44374

Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @

PUBLISHED
Vendor
@backstage, @backstage, @backstage
Product
plugin-catalog-unprocessed-entities-common, plugin-catalog-backend-module-unprocessed, plugin-catalog-unprocessed-entities
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44373

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.

PUBLISHED
Vendor
nitrojs, nitrojs
Product
nitropack, nitro
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44372

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using wildcards rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. This vulnerability is fixed in 3.0.260429-beta.

PUBLISHED
Vendor
nitrojs, nitrojs
Product
nitropack, nitro
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44371

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

PUBLISHED
Vendor
OSC
Product
ondemand
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4437

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

PUBLISHED
Vendor
The GNU C Library, Siemens, Siemens, Siemens, Siemens, Siemens
Product
glibc, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Provider severity
HIGH
Conflicts
1

CVE-2026-44369

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacker who is able to create or edit an annotation guide on a task is able to add malicious JavaScript code, which will then run in the browser of anyone who opens this annotation guide. This code will be able to make arbitrary requests to CVAT with the victim user's privileges. This vulnerability is fixed in 2.64.0.

PUBLISHED
Vendor
cvat-ai
Product
cvat
Provider severity
HIGH
Conflicts
0

CVE-2026-44368

PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recover the values of shares, ultimately leading to secret reconstruction. This vulnerability is fixed in 0.2.1.

PUBLISHED
Vendor
svvqt
Product
pyquorum
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44367

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4.

PUBLISHED
Vendor
Aiven-Open
Product
klaw
Provider severity
LOW
Conflicts
1

CVE-2026-44366

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Vvveb CMS comment submission flow. The author field is submitted by an unauthenticated user on any public post page, stored without sanitization, and later rendered unsanitized in two distinct sinks: This vulnerability is fixed in 1.0.8.1.

PUBLISHED
Vendor
givanz
Product
Vvveb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44364

MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home blueprint being exempted from CSRF protection. This could allow modification of session query data in the context of the authenticated user. The issue was fixed by enabling CSRF pr

PUBLISHED
Vendor
MISP
Product
misp-modules
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44363

MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Additionally, the qrcode module disabled TLS certificate verification when retrieving remote images, exposing

PUBLISHED
Vendor
MISP
Product
misp-modules
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44362

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading process. In `core/crypto/signed_hdr.c`, the function `shdr_load_pub_key()` par

PUBLISHED
Vendor
OP-TEE
Product
optee_os
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4436

A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant injection logic such that too much or too little odorant is injected into a gas line.

PUBLISHED
Vendor
GPL Odorizers, GPL Odorizers, GPL Odorizers, GPL Odorizers
Product
GPL Odorizers GPL750 (XL7), GPL750 (XL4), GPL Odorizers GPL750 (XL7 Prime), GPL750 (XL4 Prime)
Provider severity
HIGH
Conflicts
1

CVE-2026-44359

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-co

PUBLISHED
Vendor
meshtastic
Product
firmware
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44358

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js module resolution. A fork pull request processed by a pull_request_target workflow could therefore cause fork-supplied code to execute inside the action container in place of the acti

PUBLISHED
Vendor
espressif
Product
shared-github-dangerjs
Provider severity
HIGH
Conflicts
1

CVE-2026-44353

Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote .m3u8 HLS playlist or .mpd DASH manifest can list file:///path/to/file as a segment, and streamlink will read that local file and write its contents to the output stream. This vulnerability is fixed in 8.4.0.

PUBLISHED
Vendor
streamlink
Product
streamlink
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44352

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs from any user. This vulnerability is fixed in 1.2.3.

PUBLISHED
Vendor
reconurge
Product
flowsint
Provider severity
MEDIUM
Conflicts
0