Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-4285

A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-module-digitalcourse/yudao-module-digitalcourse-biz/src/main/java/cn/iocoder/yudao/module/digitalcourse/util/Pdf2MdUtil.java. Such manipulation of the argument fileUrl leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling

PUBLISHED
Vendor
taoofagi
Product
easegen-admin
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-42849

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.

PUBLISHED
Vendor
goauthentik
Product
authentik
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42847

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) vulnerability in ClipBucket, exploitable through the type parameter on the authenticated admin endpoint admin_area/action_logs.php. The endpoint admin_area/action_logs.php reads $_GET['type'], stores it in $result_array['type'], and forwards it into fetch_action_logs(), where the value is concatenated directly into a SQL WHERE condition on action_type without parameterization.

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
HIGH
Conflicts
0

CVE-2026-42846

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #14

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42845

The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content extensions (`md`, `yaml`, `yml`, `json`, `twig`, `ini`) regardless of the configurable dangerous-extensions list. A permissive `accept` policy combined with the default `destination: self@` could otherwise let an attacke

PUBLISHED
Vendor
getgrav
Product
grav-plugin-form
Provider severity
HIGH
Conflicts
0

CVE-2026-42844

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created account with api.super privileges. This results in full administrative compromise of the Grav API. This vulnerability is fixed in API 1.0.0-beta.17.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-42843

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15, an insecure direct object reference and logic flaw in the Grav API plugin (UsersController::update) allows any authenticated user with basic API access (api.access) to modify their own permission configuration. An attacker can exploit this to escalate their privileges to Super Administrator (admin.super and api.super)

PUBLISHED
Vendor
getgrav
Product
grav-plugin-api
Provider severity
HIGH
Conflicts
0

CVE-2026-42842

The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered with the Twig |raw filter in the admin panel, bypassing the global autoescape protection. An editor-level user can inject arbitrary JavaScript that executes in any administrator's browser session when they view or edit any page in the admin panel. This vulnerab

PUBLISHED
Vendor
getgrav, getgrav
Product
grav, grav-plugin-form
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42841

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML through Grav's Markdown media action syntax. The issue is caused by Markdown image query parameters being converted into callable media actions. The public attribute() media method can be reached this way, allowing an editor to set an arbitrary HTML attribute name and value on the generated image element

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42840

An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. This issue affects ERPNext: 16.16.0.

PUBLISHED
Vendor
Frappe
Product
ERPNext
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4284

A vulnerability was determined in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. This issue affects the function downloadFile of the file - yudao-module-digitalcourse/yudao-module-digitalcourse-biz/src/main/java/cn/iocoder/yudao/module/digitalcourse/util/PPTUtil.java of the component PPT File Handler. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be

PUBLISHED
Vendor
taoofagi
Product
easegen-admin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42839

An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger unescaped rendering in the Point of Sale (POS) cart interface for every operator who adds that item to a transaction.This issue affects ERPNext: 16.16.0.

PUBLISHED
Vendor
Frappe
Product
ERPNext
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42838

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42837

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2022, Windows 11 version 23H2, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-42836

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 11 version 26H1, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2019, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2022, Windows 10 Version 1607, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-42835

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Teams for Android
Provider severity
HIGH
Conflicts
0

CVE-2026-42834

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center in Azure Portal
Provider severity
HIGH
Conflicts
0

CVE-2026-42833

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Dynamics 365 (on-premises) version 9.1
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Excel for Android, Microsoft Office LTSC for Mac 2024, Microsoft Word for Android, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-42831

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office for Android
Provider severity
HIGH
Conflicts
1

CVE-2026-42830

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor Agent Metrics Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4283

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated attackers to permanently destroy any non-administrator user account (password randomiz

PUBLISHED
Vendor
legalweb
Product
WP DSGVO Tools (GDPR)
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42829

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-42828

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 23H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-42827

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42826

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure DevOps
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42825

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2012, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2026-42824

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Logic Apps
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Local
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4282

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulting in privilege escalation.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.11, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.11, Red Hat build of Keycloak 26.2.15, Red Hat build of Keycloak 26.2
Provider severity
HIGH
Conflicts
1

CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata files. For a table already registered in a Polaris-managed catalog, changing only that property through an `ALTER TABLE`-style settings change (not a row-level `INSERT`, `SELECT`, `UPDATE`, or `DELETE`) bypasses the commit-time branch that is

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Polaris
Provider severity
CRITICAL
Conflicts
2

CVE-2026-42811

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google Cloud Storage downscoped credentials by creating a Credential Access Boundary (CAB) with CEL conditions that are intended to restrict access to the requested table's storage path. The relevant CEL string is built from the bucket name an

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Polaris
Provider severity
CRITICAL
Conflicts
2

CVE-2026-42810

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions. In S3 IAM policy matching, `*` is treated as a wildcard rather than as ordinary text. That means temporary credentials issued for one crafted table can match the storage path of a different table. In private testing against Polaris

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Polaris
Provider severity
CRITICAL
Conflicts
2

CVE-2026-4281

The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the connect() and listen_for_tokens() methods of the FormLift_Infusionsoft_Manager class, both of which are hooked to 'plugins_loaded' and execute on every page load. The connect() function generates an OAuth connection password and leaks it in the redirect Location header without verifying the requesting use

PUBLISHED
Vendor
trainingbusinesspros
Product
FormLift for Infusionsoft Web Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation becomes attacker- directed because the attacker can choose a reachable target location. In the confirmed variant, if the caller supplies a custom `location` during stage create and requests credent

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Polaris
Provider severity
CRITICAL
Conflicts
2

CVE-2026-42800

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c.

PUBLISHED
Vendor
ASR
Product
Lapwing_Linux
Provider severity
HIGH
Conflicts
0

CVE-2026-4280

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpoint lacking both authorization checks and CSRF verification, combined with insufficient path validation when the brnwp_theme option value is passed directly to an include() statement in the brnwp_show_breaking_news_wp() shortcode handler. While sanitize_text_field() is applied to user input, it does not strip directory traversal s

PUBLISHED
Vendor
doctorwp
Product
Breaking News WP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42799

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.

PUBLISHED
Vendor
ASR
Product
Kestrel
Provider severity
HIGH
Conflicts
0

CVE-2026-42798

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

PUBLISHED
Vendor
littlecms
Product
little cms color engine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42797

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restr

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Syncope
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42796

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file through the plugins parameter, causing the Arelle webserver to download and execute the attacker-controlled code within the Arelle process with its privileges.

PUBLISHED
Vendor
Arelle
Product
Arelle
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42795

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the pro

PUBLISHED
Vendor
Gleam, Gleam, Gleam
Product
Gleam, Gleam, Gleam
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42794

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows reflected cross-site scripting via the GraphiQL interface. 'Elixir.Absinthe.Plug.GraphiQL':js_escape/1 in lib/absinthe/plug/graphiql.ex escapes single quotes and newlines in the query GET parameter before embedding it in an inline JavaScript string, but does not escape backslashes. An attacker can bypass the escaping by prefixing a quote with a backslash (e.g. \'), breaking o

PUBLISHED
Vendor
absinthe-graphql, absinthe-graphql
Product
absinthe_plug, absinthe_plug
Provider severity
LOW
Conflicts
1

CVE-2026-42793

Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom table exhaustion when parsing attacker-controlled GraphQL SDL. Multiple Blueprint.Draft.convert/2 implementations in Absinthe's SDL language modules call String.to_atom/1 on attacker-controlled names from parsed GraphQL SDL documents, including directive names, field names, type names, and argument names. Because atoms are never garbage-collected and

PUBLISHED
Vendor
absinthe-graphql, absinthe-graphql
Product
absinthe, absinthe
Provider severity
HIGH
Conflicts
1

CVE-2026-42792

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns EMFILE (per-process file descriptor limit reached) or ENFILE (system-wide file descriptor limit reached), rather than treating these as recoverable conditions. An attacker can exh

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42791

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP response verification in pubkey_ocsp:verify_response/5 and pubkey_ocsp:is_authorized_responder/3 in lib/public_key/src/pubkey_ocsp.erl does not check the validity period (notBefore/notAfter) of the OCSP responder certificate. An attacker who has obtained the private key of an expired CA-designated OCSP

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42790

A flaw was found in Erlang OTP public_key. This improper certificate validation vulnerability allows a subordinate Certificate Authority (CA) with restricted DNS nameConstraints to bypass these restrictions. By issuing a leaf certificate that lacks a Subject Alternative Name (SAN) but contains a crafted CommonName (CN), an attacker can trick an Erlang OTP TLS client into accepting it as valid for an out-of-scope hostname. This can lead to hostname spoofing and potential man-in-the-middle attacks

PUBLISHED
Vendor
Erlang, Erlang, Red Hat, Red Hat, Red Hat
Product
OTP, OTP, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1
Provider severity
HIGH
Conflicts
3

CVE-2026-4279

The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versions up to, and including, 8.2.0.25. This is due to insufficient input sanitization and output escaping on the 'event' shortcode attribute. The customEventShortCodeButton() function takes the 'event' attribute value and directly interpolates it into a JavaScript string within an onclick HTML attribute without applying esc_attr() or esc_js(). Notably,

PUBLISHED
Vendor
breadbutter
Product
Bread & Butter: AI-Powered Lead Intelligence
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42789

A flaw was found in Erlang OTP's public_key module. This vulnerability (CWE-295), related to improper certificate validation, allows a non-Certificate Authority (CA) certificate to be accepted as an intermediate issuer. A remote attacker, holding an end-entity certificate issued by a trusted CA, can exploit this by forging leaf certificates for arbitrary identities. This can lead to compromised server identity verification on the client side and client certificate verification on mutual Transpor

PUBLISHED
Vendor
Erlang, Red Hat, Red Hat, Erlang, Red Hat
Product
OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, OTP, Red Hat OpenStack Platform 18.0
Provider severity
HIGH
Conflicts
3