Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-4424

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Update Infrastructure 5, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Update Infrastructure 5, Red Hat AI Inference Server 3.2, Red Hat Insights proxy 1.5, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, RHEL-8 based Middleware Containers, Red Hat OpenShift Container Platform 4.15, Red Hat AI Inference Server 3.2, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, RHEL-8 based Middleware Containers, Red Hat AI Inference Server 3.2, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat AI Inference Server 3.3, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Discovery 2, Red Hat AI Inference Server 3.3, Red Hat Update Infrastructure 5, Red Hat OpenShift Container Platform 4.13, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat OpenShift Container Platform 4.16, RHEL-8 based Middleware Containers, Red Hat Discovery 2, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, RHEL-8 based Middleware Containers, Red Hat AI Inference Server 3.2, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 9, Red Hat Discovery 2, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.14, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Update Infrastructure 5, RHEL-8 based Middleware Containers, Red Hat OpenShift Container Platform 4.12, Red Hat Hardened Images, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat Insights proxy 1.5, Red Hat Update Infrastructure 5, RHEL-8 based Middleware Containers, Red Hat AI Inference Server 3.3, Red Hat Update Infrastructure 5, Red Hat OpenShift Container Platform 4.16, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat AI Inference Server 3.3, Red Hat Discovery 2, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat AI Inference Server 3.3, RHEL-8 based Middleware Containers, Red Hat OpenShift Container Platform 4.13, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat OpenShift Container Platform 4.17, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat OpenShift Container Platform 4.18, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat OpenShift Container Platform 4.17, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4.15, RHEL-8 based Middleware Containers, Red Hat AI Inference Server 3.2, Red Hat OpenShift Container Platform 4.14, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.12, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10, RHEL-8 based Middleware Containers, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Hardened Images, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support
Provider severity
HIGH
Conflicts
1

CVE-2026-44239

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability i

PUBLISHED
Vendor
FreePBX
Product
security-reporting
Provider severity
HIGH
Conflicts
0

CVE-2026-44238

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administrator privileges are not needed. This vulnerability is fixed in 16.0.50 and 17.0.11.

PUBLISHED
Vendor
FreePBX
Product
security-reporting
Provider severity
HIGH
Conflicts
0

CVE-2026-44237

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditionally returns true, allowing any party with knowledge of a valid client_id to obtain OAuth2 access tokens without providing the correct client_secret. This vulnerability is fixed in 17.0.8.

PUBLISHED
Vendor
FreePBX
Product
security-reporting
Provider severity
HIGH
Conflicts
0

CVE-2026-44232

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, every IPv6 category bypasses is_url_safe. This vulnerability is fixed in 1.0.3.

PUBLISHED
Vendor
HackingRepo
Product
dssrf-js
Provider severity
HIGH
Conflicts
0

CVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentia

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44230

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44229

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44228

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44227

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. There are no effective workarounds. Avoid following untrusted RT URLs. This issue has been fixed in version 6.0.3.

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44226

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template names, an unauthenticated user can reliably trigger a server exception (for example by requesting a non-existent template) and receive internal stack traces in the HTTP response. This vulnerability is fixed in

PUBLISHED
Vendor
pyload
Product
pyload
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44225

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the host filesystem. A validateFsPath() function is supposed to sandbox this access, but its blocklist is incomplete. Any web app packaged with Pulpy can read and write arbitrary files in the user's home directory — including ~/.ssh/id_rsa, ~/.aws/credentials, and ~/Library/Keychains/. This vulnerability

PUBLISHED
Vendor
enesgkky
Product
Pulpy
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44224

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model without any ownership check or restriction on which groups can be assigned. A user with manage:users — a permission typically delegated to wiki moderators for account management — can set groups:[1] on their ow

PUBLISHED
Vendor
requarks
Product
wiki
Provider severity
HIGH
Conflicts
0

CVE-2026-44223

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a RuntimeError that crashes the EngineCore process. The crash is triggered when any request in the batch uses sampling penalty parameters (repetition_penalty, frequency_penalty, or presence_penalty). A single request with a penalty parameter (e.g., "repe

PUBLISHED
Vendor
vllm-project
Product
vllm
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44222

vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special tokens are interpreted as control. Image and video placeholder sequences supplied without matching data cause vLLM to index into empty grids during input-position computation, raising an unhandled IndexError and terminating the worker or degrading availability. Multi

PUBLISHED
Vendor
vllm-project
Product
vllm
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44221

ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database cre

PUBLISHED
Vendor
ArcadeData
Product
arcadedb
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44220

ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function in src/ciguard/discovery.py walks a directory tree following symlinks, with cycle protection via tracking visited resolved paths. An attacker who can plant a symlink in a directory the user (or AI agent) scans can cause discovery to walk into the symlink target and return paths to pipeline-shaped files outside the requested root. This vulnerability is fixed in 0.8.2.

PUBLISHED
Vendor
Jo-Jo98
Product
ciguard
Provider severity
LOW
Conflicts
0

CVE-2026-44219

ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyzer/sca/osv.py and src/ciguard/analyzer/sca/endoflife.py) call payload = json.loads(resp.read().decode('utf-8')) without a maximum-bytes cap. A hostile or compromised endoflife.date / OSV.dev (or a successful TLS MITM) could return a multi-GB response, exhausting the ciguard process's memory. This vulnerability is fixed in 0.8.2.

PUBLISHED
Vendor
Jo-Jo98
Product
ciguard
Provider severity
LOW
Conflicts
0

CVE-2026-44218

ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard container image inherits the default root user because the Dockerfile lacks a USER directive. This vulnerability is fixed in 0.8.2.

PUBLISHED
Vendor
Jo-Jo98
Product
ciguard
Provider severity
LOW
Conflicts
0

CVE-2026-44217

sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, implementations that allow user-provided values to be passed to event, retry or id fields are susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream. This vulnerability is fixed in 4.0.1.

PUBLISHED
Vendor
rexxars
Product
sse-channel
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44216

A flaw was found in Wasmtime, a runtime for WebAssembly. A remote attacker could exploit an arithmetic overflow vulnerability by instantiating a WebAssembly module or component that attempts to allocate an extremely large table using the WebAssembly memory64 proposal. This flaw causes Wasmtime to panic, resulting in a Denial of Service (DoS) for the affected system.

PUBLISHED
Vendor
Red Hat, Red Hat, bytecodealliance
Product
Red Hat Enterprise Linux 10, Red Hat Hardened Images, wasmtime
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-44215

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS filesystem image. The attacker controls the byte offset of the write within a ~254-byte window past the heap allocation boundary. This vulnerability is fixed in 6.0.1698.0.

PUBLISHED
Vendor
M2Team
Product
NanaZip
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44214

eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators (\n, \r, or \r\n) and thereby forge additional SSE fields or entire messages on the stream. This vulnerability is fixed in 1.0.2.

PUBLISHED
Vendor
rexxars
Product
eventsource-encoder
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44213

The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the INSTANA_ENDPOINT_PROXY environment variable. If a network attacker can Man-in-the-Middle (MitM) the proxy connection, all OpenTelemetry telemetry data and the Instana API key are exposed to the attacker. This vulnerabi

PUBLISHED
Vendor
open-telemetry
Product
opentelemetry-dotnet-contrib
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44212

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in the database and executed when a back-office employee opens the affected customer thread, enabling session hijacking and full back-office takeover. This vulnerability is fixed in 8.2

PUBLISHED
Vendor
PrestaShop
Product
PrestaShop
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44211

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.

PUBLISHED
Vendor
cline
Product
cline
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44210

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override

PUBLISHED
Vendor
kata-containers
Product
kata-containers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44209

A flaw was found in banks. This vulnerability, known as Server-Side Template Injection (SSTI), allows a remote attacker to achieve Remote Code Execution (RCE) on the host system. This occurs when applications using banks pass user-supplied strings directly as template arguments to the Prompt() function, which then renders these templates in an unsandboxed environment.

PUBLISHED
Vendor
Red Hat, Red Hat, masci, Red Hat, Red Hat, Red Hat
Product
Exploit Intelligence, OpenShift Lightspeed, banks, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, OpenShift Lightspeed
Provider severity
HIGH
Conflicts
2

CVE-2026-44208

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.0 and 16.17.0.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44207

Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows authenticated users to access other users' email configuration details. This issue has been patched in versions 15.107.0 and 16.17.0.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44206

Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possible through exploiting an endpoint. This issue has been patched in versions 15.107.2 and 16.17.4.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44205

Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user profile image section allows an attacker to execute malicious scripts in the browsers of other users. This issue has been patched in version 15.106.0.

PUBLISHED
Vendor
frappe
Product
frappe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44204

Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortBy query parameter on the /assets route allows any authenticated user (any role) to execute arbitrary SQL and read data from any table in the database, including data belonging to other organizations. This vulnerability is fixed in 1.20.1.

PUBLISHED
Vendor
Shelf-nu
Product
shelf.nu
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44201

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

PUBLISHED
Vendor
wagtail
Product
wagtail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44200

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

PUBLISHED
Vendor
wagtail
Product
wagtail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4420

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges (such as Author, Editor, or Administrator) can embed a malicious JavaScript payload in the tags field of a newly created article. This payload will be executed when a victim visits the URL of the uploaded resource. The uploaded resource itself is accessible without authentication. Critically, this vulnerability could be used to automatically create

PUBLISHED
Vendor
Bludit
Product
Bludit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44199

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they do have access to for submissions they don't. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

PUBLISHED
Vendor
wagtail
Product
wagtail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44198

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

PUBLISHED
Vendor
wagtail
Product
wagtail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44197

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

PUBLISHED
Vendor
wagtail
Product
wagtail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the user's password to reach this stage. This vulnerability is fixed in 1.16.3.

PUBLISHED
Vendor
smp46
Product
pingvin-share-x
Provider severity
CRITICAL
Conflicts
1

CVE-2026-44195

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or "Successful login") between normal brute-force attempts, an attacker can prevent the failure counter from ever reaching the lockout threshold. This vulnerability is fixed in 26.1.7.

PUBLISHED
Vendor
opnsense
Product
core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-44194

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underlying operating system. The flaw exists in the local user synchronization flow, within core/src/opnsen

PUBLISHED
Vendor
opnsense
Product
core
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44193

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

PUBLISHED
Vendor
opnsense
Product
core
Provider severity
CRITICAL
Conflicts
0

CVE-2026-44192

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system. This can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44191

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim's mac

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
HIGH
Conflicts
1

CVE-2026-44190

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the u

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
HIGH
Conflicts
1

CVE-2026-44189

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modificat

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
HIGH
Conflicts
1

CVE-2026-44188

A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to invalidate the token on the backend, leaving it valid until its natural expiration. This can lead to una

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-44187

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files. This information disclosure can lead to the attacker obtaining the API credential and potentially consuming the user's API quota.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
LOW
Conflicts
1

CVE-2026-44186

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Provider severity
HIGH
Conflicts
0