Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-43866

Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes the payload of an incoming JMS ObjectMessage via jakarta.jms.ObjectMessage.getObject() whenever the mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer. The CVE-2026-40860 hardening added a post-deserialization class check that rejects classes outside the default allow-lis

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation
Product
Apache Camel, Apache Camel
Provider severity
HIGH
Conflicts
1

CVE-2026-43865

Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself - that is, when no user-supplied HazelcastInstance, hazelcastConfigUri, or referenced Config bean is provided - neither Hazelcast's JavaSerializationFilterConfig nor a Camel-side ObjectInputFilter is configured, so objects

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-43864

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

PUBLISHED
Vendor
mutt
Product
mutt
Provider severity
LOW
Conflicts
0

CVE-2026-43863

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

PUBLISHED
Vendor
mutt
Product
mutt
Provider severity
LOW
Conflicts
0

CVE-2026-43862

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

PUBLISHED
Vendor
mutt
Product
mutt
Provider severity
LOW
Conflicts
0

CVE-2026-43861

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

PUBLISHED
Vendor
mutt
Product
mutt
Provider severity
LOW
Conflicts
0

CVE-2026-43860

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

PUBLISHED
Vendor
mutt
Product
mutt
Provider severity
LOW
Conflicts
0

CVE-2026-43859

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

PUBLISHED
Vendor
mutt
Product
mutt
Provider severity
LOW
Conflicts
0

CVE-2026-43833

Full details and mitigation steps are currently restricted and will be published at a later date.

PUBLISHED
Vendor
tbc
Product
tbc
Provider severity
MEDIUM
Conflicts
0

CVE-2026-43832

Full details and mitigation steps are currently restricted and will be published at a later date.

PUBLISHED
Vendor
tbc
Product
tbc
Provider severity
HIGH
Conflicts
0

CVE-2026-43831

Full details and mitigation steps are currently restricted and will be published at a later date.

PUBLISHED
Vendor
tbc
Product
tbc
Provider severity
HIGH
Conflicts
0

CVE-2026-43830

Full details and mitigation steps are currently restricted and will be published at a later date.

PUBLISHED
Vendor
tbc
Product
tbc
Provider severity
CRITICAL
Conflicts
0

CVE-2026-43829

Full details and mitigation steps are currently restricted and will be published at a later date.

PUBLISHED
Vendor
tbc
Product
tbc
Provider severity
HIGH
Conflicts
0

CVE-2026-43828

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Shiro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-43827

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Shiro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-43826

The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-opensearch` 1.9.1 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than e

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow Providers OpenSearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-43825

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled stream with java.io.ObjectInputStream and calls readObject() without an ObjectInputFilter installed. ObjectInputStream materialises every class referenced in the stream before the resulting object is cast to SvmD

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache OpenNLP :: Core :: ML :: LibSVM
Provider severity
HIGH
Conflicts
0

CVE-2026-43824

A flaw was found in Argo CD. The ServerSideDiff feature allows for the reading of cleartext Kubernetes Secret data. This vulnerability could lead to information disclosure, potentially exposing sensitive configuration details within the Kubernetes environment.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, argoproj, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4, Red Hat OpenShift GitOps, Argo CD, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps, Red Hat OpenShift GitOps
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-43823

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.

PUBLISHED
Vendor
Apple
Product
swift-crypto
Provider severity
HIGH
Conflicts
1

CVE-2026-43822

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, tvOS, visionOS, watchOS, iOS and iPadOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43821

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
macOS, Safari, tvOS, visionOS, iOS and iPadOS, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43820

NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.

PUBLISHED
Vendor
Apple
Product
swift-nio-ssl
Provider severity
HIGH
Conflicts
1

CVE-2026-43819

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43818

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43817

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
watchOS, visionOS, tvOS, macOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43816

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, watchOS, iOS and iPadOS, tvOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43814

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, watchOS, macOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43813

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, macOS, visionOS, watchOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43812

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
tvOS, iOS and iPadOS, macOS, visionOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43811

A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43810

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, macOS, tvOS, visionOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43809

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-43807

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, tvOS, watchOS, iOS and iPadOS, visionOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43806

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cause a denial of service.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43805

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
watchOS, macOS, iOS and iPadOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43804

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
iOS and iPadOS, Safari, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43803

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, visionOS, watchOS, macOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43802

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-43801

This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
tvOS, macOS, watchOS, visionOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43800

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, macOS, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43799

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
visionOS, macOS, iOS and iPadOS, tvOS, watchOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-43797

This issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43796

This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
watchOS, macOS, tvOS, iOS and iPadOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-43793

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-43792

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple
Product
macOS, Safari
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4379

The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in all versions up to, and including, 2.3.4. This is due to the plugin modifying gallery shortcode output to include the `group` attribute value without proper escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injec

PUBLISHED
Vendor
firelightwp
Product
LightPress Lightbox
Provider severity
MEDIUM
Conflicts
0

CVE-2026-43782

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43781

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-43780

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, watchOS, macOS, visionOS, tvOS
Provider severity
HIGH
Conflicts
2

CVE-2026-43779

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to intercept network connections intended for another process.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1