Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-4266

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.This issue affects Fireware OS: 12.1 through 12.11.8 and 2025.1 through 2026.1.2. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T-15 and T-35.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
HIGH
Conflicts
0

CVE-2026-42659

Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.

PUBLISHED
Vendor
Nasir Ahmed
Product
Advanced Form Integration
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42658

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.

PUBLISHED
Vendor
Mamunur Rashid
Product
Classified Listing
Provider severity
HIGH
Conflicts
0

CVE-2026-42657

Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.

PUBLISHED
Vendor
Wasiliy Strecker
Product
Contest Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42656

Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.

PUBLISHED
Vendor
Wasiliy Strecker
Product
Contest Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42655

Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.

PUBLISHED
Vendor
WPManageNinja
Product
Best Payments Plugin for WP
Provider severity
HIGH
Conflicts
0

CVE-2026-42654

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.

PUBLISHED
Vendor
WP Swings
Product
Wallet System for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-42653

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This issue affects SliceWP: from n/a through 1.2.6.

PUBLISHED
Vendor
iova.mihai
Product
SliceWP
Provider severity
HIGH
Conflicts
0

CVE-2026-42652

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through <= 5.1.5.

PUBLISHED
Vendor
wpeverest
Product
User Registration
Provider severity
HIGH
Conflicts
0

CVE-2026-42651

Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.

PUBLISHED
Vendor
Mamunur Rashid
Product
Classified Listing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42650

Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.

PUBLISHED
Vendor
Ruben Garcia
Product
AutomatorWP
Provider severity
HIGH
Conflicts
0

CVE-2026-4265

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42649

Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.

PUBLISHED
Vendor
Archetyped
Product
Favicon Rotator
Provider severity
HIGH
Conflicts
0

CVE-2026-42648

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22.

PUBLISHED
Vendor
Brainstorm Force
Product
Spectra
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

PUBLISHED
Vendor
Beardev
Product
JoomSport
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42646

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0.

PUBLISHED
Vendor
Steve Burge
Product
TaxoPress
Provider severity
HIGH
Conflicts
0

CVE-2026-42645

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.11.0.

PUBLISHED
Vendor
Dmitry V. (CEO of "UKR Solution")
Product
Barcode Scanner with Inventory & Order Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42644

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10.

PUBLISHED
Vendor
WPDeveloper
Product
BetterDocs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42643

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.

PUBLISHED
Vendor
StellarWP
Product
Image Widget
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42642

Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.

PUBLISHED
Vendor
StellarWP
Product
GiveWP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42641

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

PUBLISHED
Vendor
ILLID
Product
Share This Image
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42640

Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

PUBLISHED
Vendor
Mamunur Rashid
Product
Classified Listing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42639

Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

PUBLISHED
Vendor
Dev4Press
Product
GD Rating System
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4263

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter  'visitor' in '/api/v1/webchat/message'.

PUBLISHED
Vendor
HiJiffy
Product
HiJiffy Chatbot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42629

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

PUBLISHED
Vendor
Powerpackelements
Product
PowerPack Pro for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-42627

In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based buffer over-read during model optimization. The overflow occurs when multiplying tensor dimensions using 32-bit unsigned arithmetic without overflow detection, causing GetNumBytes() to return an understated allocation size. During Optimize()->InferOutputShapes(), the BatchToSpaceNdLayer reads beyond

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42626

HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can establish a persistent connection to port 9100 and send keep-alive packets, causing the printer's session threads to remain locked in a waiting state. The firmware lacks connection timeouts and concurrent session limits, resulting in a persistent Denial of Service (DoS) that renders the printer unre

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4262

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' in '/api/v1/download/<ID>/'.

PUBLISHED
Vendor
HiJiffy
Product
HiJiffy Chatbot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42615

GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

PUBLISHED
Vendor
GCHQ
Product
CyberChef
Provider severity
HIGH
Conflicts
0

CVE-2026-42613

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registration is enabled and groups or access are included in the configured allowed fields list, an unauthenticated user can self-register with admin.super privileges by injecting these fields into the registration request. This vulnerability is fixed in 2.0.0-beta.2.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42612

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue arises from a blacklist bypass in the detectXss() function when handling unquoted HTML event attributes. This vulnerability is fixed in 2.0.0-beta.2.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
0

CVE-2026-42611

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated to dump the entire system information available under /admin/config/info whenever a Super Admin visits the page; which can further be chained with the use of admin-nonce to do a complete server compromise (RCE). This vulnerability is fixed in 2.0.0-beta.2.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
0

CVE-2026-42610

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programmatically load administrative user objects and extract sensitive data, including Bcrypt password hashes and the security salt. This vulnerability is fixed in 2.0.0-beta.2.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4261

The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_role' meta through the 'save_extra_user_profile_fields' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.

PUBLISHED
Vendor
husobj
Product
Expire Users
Provider severity
HIGH
Conflicts
0

CVE-2026-42609

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary administrator. By creating a new user with a username that already exists, the system updates the existing account's metadata and permissions instead of rejecting the request. This leads to a Denial of Service (DoS) on administrative functions and Privilege De-escal

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
1

CVE-2026-42608

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories and write an index.yaml file containing attacker-controlled data. This vulnerability can lead to unauthorized modification of application behavior, potential data integrity issues, and service disrupt

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
HIGH
Conflicts
0

CVE-2026-42607

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. While the system attempts to block direct .php file uploads, it fails to inspect the contents of uploaded ZIP archives. Once a malicious plugin is extracted, it can execute arbitrary PHP code or drop a persistent web shell on the server. This vulnerability is fixed in 2.0

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42606

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to any user by injecting this header when triggering the forgot-password flow. When the victim clicks the poisoned link, their reset token is exfiltrated to the attacker's server. The attacker then uses th

PUBLISHED
Vendor
AzuraCast
Product
AzuraCast
Provider severity
HIGH
Conflicts
0

CVE-2026-42605

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem storage backend (the default), an authenticated user with media management permissions can write arbitrary files outside the station's media storage directory, achieving remote code execution by writin

PUBLISHED
Vendor
AzuraCast
Product
AzuraCast
Provider severity
HIGH
Conflicts
0

CVE-2026-42604

Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstrap password. The endpoint also lacks authentication and rate limiting, making the bootstrap password brute-forceable. Version 26.5.0 fixes the issue.

PUBLISHED
Vendor
actualbudget
Product
actual
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42603

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out and executes code directly from the attacker's fork, enabling RCE with write permissions. This vulnerability is fixed in 2.1.2.

PUBLISHED
Vendor
OWASP-BLT
Product
BLT
Provider severity
HIGH
Conflicts
1

CVE-2026-42602

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access token for any scope the collector's configured identity can mint for to authenticate to any OpenTelemetry receiver that uses auth: azure_auth. The extension's Authenticate method does not validate incoming bearer tokens as JWTs. Instead, it calls its own configured credential to obtain an access token an

PUBLISHED
Vendor
open-telemetry
Product
opentelemetry-collector-contrib
Provider severity
HIGH
Conflicts
1

CVE-2026-42601

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. At time of publication, there are no publicly available patches.

PUBLISHED
Vendor
ArchiveBox
Product
ArchiveBox
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42600

MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens t

PUBLISHED
Vendor
minio
Product
minio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42599

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does no

PUBLISHED
Vendor
sveltejs
Product
svelte
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42598

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible to request paths such as http://localhost:8080/c:/Windows/System32/drivers/etc/hosts and have the contents returned. This vulnerability is fixed in 2.13.0.

PUBLISHED
Vendor
Badgerati
Product
Pode
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42597

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load their own request-local assets, and those routes apply a per-request AllowedFilePrefixes guard to scope the read. The URL routes never set AllowedFilePrefixes, so the scope guard silently skips. Alice

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42596

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::ffff:127.0.0.1]:... and reach loopback or private HTTP services that the default deny-list is intended to block. This crosses a real security boundary because an external caller can force the server to make o

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42595

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point Chromium at any internal IP — including loopback, RFC 1918 ranges, and cloud metadata endpoints — and receive the response rendered as a PDF. Additionally, even when operators configure a custom deny-list

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
HIGH
Conflicts
0

CVE-2026-42594

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns ErrAsyncProcess and Echo recycles the context back to its sync.Pool. When a concurrent request claims the recycled context, c.Reset() clears the store. If the webhook goroutine reaches hardTimeoutMiddleware at that moment, an unchecked type assertion on a nil store entry panics outside any

PUBLISHED
Vendor
gotenberg
Product
gotenberg
Provider severity
HIGH
Conflicts
0