Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42177

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a | or || anchor is substring-matched against the full request URL. The same applied rule action is modifyHeaders that attaches the Entra ID Primary Refresh Token cookie. The Firefox adapter in platform/

PUBLISHED
Vendor
siemens
Product
linux-entra-sso
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42176

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configuration value to be modified through /api/config/set/admins with a forged Bearer token that is accepted as an admin API token. Once that setting is changed, the target email address is written to the application configuration file. The change does not become active immediately in the current process, because the ADMINS set is loaded once at startup. After a Scoold restart, though,

PUBLISHED
Vendor
Erudika
Product
scoold
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42175

requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addresses within the RFC 6598 Shared Address Space (100.64.0.0/10). An attacker who can supply arbitrary URLs to requests-hardened could exploit this gap to access internal services hosted within 100.64.0.0/10. This is for example relevant in environments such as AWS EKS where 100.64.0.0/10 is commonly u

PUBLISHED
Vendor
saleor
Product
requests-hardened
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42174

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.

PUBLISHED
Vendor
getkirby
Product
kirby
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42172

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until manually revoked. This issue is fixed in version 4.0.0-beta.474.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
LOW
Conflicts
0

CVE-2026-42171

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

PUBLISHED
Vendor
Nullsoft
Product
Nullsoft Scriptable Install System
Provider severity
HIGH
Conflicts
0

CVE-2026-4217

A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function of the file in ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the component ai.nreal.nebula.universal. Such manipulation of the argument accessKey/secretAccessKey/securityToken leads to unprotected storage of credentials. The attack can only be performed from a local environment. The attack requires a high level of complexity. The exploitability is said to be difficul

PUBLISHED
Vendor
XREAL
Product
Nebula App
Provider severity
LOW
Conflicts
2

CVE-2026-42168

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when an AS2 message is received or sent.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42167

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

PUBLISHED
Vendor
ProFTPD
Product
ProFTPD
Provider severity
HIGH
Conflicts
0

CVE-2026-42160

Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered "PENDING" organization / user accounts. This issue has been patched in version 7.3.2.

PUBLISHED
Vendor
sovity
Product
dataspace-portal
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4216

A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor explains: "The function referenced in the report currently exists in our deployed system. It is related to a developer mode used during the configuration process for Bl

PUBLISHED
Vendor
i-SENS
Product
SmartLog App
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42159

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites, etc) within these nodes and relationships. A remote attacker can create a node with a malicious desc

PUBLISHED
Vendor
reconurge
Product
flowsint
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42158

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metadata of an investigation of another user. This vulnerability is fixed in 1.2.3.

PUBLISHED
Vendor
reconurge
Product
flowsint
Provider severity
LOW
Conflicts
0

CVE-2026-42157

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a map node with a malicious label that contains arbitrary HTML. When the map tab is selected and a map node marker is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixed in 1.2.3.

PUBLISHED
Vendor
reconurge
Product
flowsint
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42156

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a node with a malicious type that can escape an existing Cypher query and an adversary can execute an arbitrary Cypher query. This vulnerability is fixed in 1.2.3.

PUBLISHED
Vendor
reconurge
Product
flowsint
Provider severity
HIGH
Conflicts
0

CVE-2026-42155

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, the XML-RPC / SOAP API session ID is generated using an outdated, time-based construction rather than a Cryptographically Secure Pseudo-Random Number Generator (CSPRNG). All inputs to the MD5 hash are time-derived and non-secure. Because the resulting digest relies entirely on the tim

PUBLISHED
Vendor
OpenMage
Product
magento-lts
Provider severity
CRITICAL
Conflicts
1

CVE-2026-42154

A flaw was found in Prometheus. An unauthenticated attacker can exploit the remote read endpoint (`/api/v1/read`) by sending a specially crafted, small snappy-compressed payload. This payload causes a disproportionately large memory allocation, leading to memory exhaustion and a Denial of Service (DoS) by crashing the Prometheus process.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, prometheus, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1, Red Hat Hardened Images, Red Hat multicluster global hub 1.6.0, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.0, Network Observability Operator, Red Hat OpenShift Container Platform 4, File Integrity Operator, Red Hat OpenShift GitOps, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 7, Red Hat Ceph Storage 5, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, File Integrity Operator, Logging Subsystem for Red Hat OpenShift 6.4, Red Hat Hardened Images, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager 1.1, RHEM 1.1 for RHEL 10, Red Hat Trusted Artifact Signer 1.3, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Quay 3.1, Red Hat Advanced Cluster Management for Kubernetes 2, OpenShift Service Mesh 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4.21, Multicluster Global Hub 1.7.1, OpenShift Service Mesh 2, Multicluster Global Hub 1.5.4, Network Observability Operator, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager 1.1, OpenShift Lightspeed, Red Hat Edge Manager 1.1, OpenShift Service Mesh 2, Red Hat Ceph Storage 6, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift Container Platform 4, Logging for Red Hat OpenShift 6.2, Red Hat Edge Manager 1.1, Red Hat Ceph Storage 9, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager 1.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2, RHEM 1.1 for RHEL 9, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat multicluster global hub 1.4.4, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenStack Platform 18.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Quay 3.15, Red Hat OpenShift Container Platform 4.2, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, File Integrity Operator, Red Hat Ceph Storage 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 7, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Ceph Storage 8, Red Hat Edge Manager 1.0, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Trusted Artifact Signer 1.3, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 9, OpenShift Service Mesh 3, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Logging for Red Hat OpenShift 6.2, OpenShift Service Mesh 2, Red Hat Hardened Images, Red Hat Edge Manager 1.1, Red Hat Trusted Artifact Signer 1.3, Red Hat Quay 3.16, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Trusted Artifact Signer 1.3, Red Hat OpenShift AI (RHOAI), File Integrity Operator, OpenShift Service Mesh 3, RHEM 1.0 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8, Logging for Red Hat OpenShift 6.2, Red Hat Edge Manager 1.1, Red Hat Edge Manager 1.1, Red Hat Quay 3.9, Red Hat Ceph Storage 6, prometheus, Red Hat Edge Manager 1.0, Red Hat Edge Manager 1.0, Red Hat Quay 3.12, File Integrity Operator, File Integrity Operator, OpenShift Service Mesh 3, Red Hat Hardened Images, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.1
Provider severity
HIGH
Conflicts
2

CVE-2026-42153

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands executed in the database container. This issue is fixed in version 4.0.0-beta.474.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
HIGH
Conflicts
0

CVE-2026-42151

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, prometheus, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Multicluster Global Hub 1.7.1, Red Hat OpenShift Container Platform 4.22, File Integrity Operator, Red Hat Ceph Storage 8, Red Hat OpenShift distributed tracing 3, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux AppStream (v. 9), Red Hat Quay 3.1, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Logging for Red Hat OpenShift 6.2, Red Hat Quay 3.9, Red Hat Edge Manager 1.1, OpenShift Lightspeed, Red Hat Trusted Artifact Signer 1.4, Red Hat Enterprise Linux 7, Red Hat OpenShift GitOps, Red Hat Ceph Storage 7, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux 8, Red Hat OpenStack Platform 18.0, Red Hat Trusted Artifact Signer 1.3, OpenShift Service Mesh 2, Red Hat OpenShift AI (RHOAI), prometheus, Custom Metric Autoscaler operator for Red Hat Openshift, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.6.0, Network Observability Operator, RHEM 1.1 for RHEL 9, Red Hat Quay 3.16, Red Hat multicluster global hub 1.4.4, RHEM 1.1 for RHEL 10, RHEM 1.0 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat Edge Manager 1.0, Red Hat Ceph Storage 6, OpenShift Service Mesh 3, Red Hat Quay 3.12, Red Hat Ceph Storage 5, Red Hat Quay 3.15, Red Hat Enterprise Linux 9, Red Hat Ceph Storage 9, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2
Provider severity
HIGH
Conflicts
2

CVE-2026-42150

wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser. This issue has been patched in version 2.0.0.

PUBLISHED
Vendor
WeblateOrg
Product
wlc
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4215

A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of the file core/src/main/java/com/flowci/core/config/service/ConfigServiceImpl.java of the component SMTP Host Handler. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
FlowCI
Product
flow-core-x
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42148

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell escaping, allowing an attacker who can set the helper version and trigger the helper image build in a development environment to execute arbitrary commands on the server. This issue is fixed in version 4.0.0-beta.474.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
LOW
Conflicts
0

CVE-2026-42147

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endpoint, allowing an authenticated user with storage management permissions to make Coolify request internal or metadata-service URLs. This issue is fixed in version 4.0.0-beta.474.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42146

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A crafted BMP file with a large nb_colors value triggers an out-of-memory condition, crashing any application that uses CImg to load untrusted BMP files. This issue has been patched via commit c3aacf5.

PUBLISHED
Vendor
GreycLab
Product
CImg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42145

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
LOW
Conflicts
1

CVE-2026-42144

CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability in the W*H*D size computation inside _load_pnm() that can bypass the memory allocation guard. A crafted PNM/PGM/PPM file with large dimension values causes the overflow to wrap around, allocating an undersized buffer and potentially triggering a heap buffer overflow. Any application using CImg to load untrusted image files is affected. This issue has been patched via commit 4ca

PUBLISHED
Vendor
GreycLab
Product
CImg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42143

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on managed servers without escaping or validation, allowing an authenticated member to inject shell metacharacters and execute commands as root when volume operations are triggered. This issue appears to be fixed in version 4.0.0-beta.471.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
HIGH
Conflicts
0

CVE-2026-42141

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be exploited to scan internal infrastructure, access local cloud metadata endpoints (e.g., AWS IMDS), interact with internal servic

PUBLISHED
Vendor
xibosignage
Product
xibo-cms
Provider severity
HIGH
Conflicts
0

CVE-2026-42140

PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro is vulnerable to Server-Side Request Forgery (SSRF). The macro allows users to specify an alternative PlantUML server via the server parameter. However, the application does not validate the supplied URL. An attacker can supply an internal IP address or a malicious external URL. The XWiki server will attempt to connect to this URL to "render" the diagram. This issue has be

PUBLISHED
Vendor
xwiki-contrib
Product
macro-plantuml
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4214

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnP_AV_Server_Path_Setting of the file /cgi-bin/app_mgr.cgi. Executing a manipulation can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DNS-120, DNR-202L, DNS-1550-04, DNS-340L, DNR-326, DNS-321, DNS-343, DNS-327L, DNS-325, DNS-1100-4, DNS-315L, DNS-1200-05, DNS-726-4, DNS-326, DNS-345, DNS-320L, DNS-320, DNS-320LW, DNR-322L, DNS-323
Provider severity
HIGH
Conflicts
3

CVE-2026-42138

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1.

PUBLISHED
Vendor
langgenius
Product
dify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42137

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. This issue has been patched in versions 4.9.0 and 5.4.0.

PUBLISHED
Vendor
getkirby
Product
kirby
Provider severity
HIGH
Conflicts
1

CVE-2026-4213

A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function cgi_myfavorite_del_user/cgi_myfavorite_verify of the file /cgi-bin/gui_mgr.cgi. Performing a manipulation results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DNS-323, DNR-322L, DNS-320LW, DNS-325, DNS-321, DNS-343, DNS-315L, DNS-327L, DNS-120, DNR-326, DNS-726-4, DNS-1100-4, DNS-345, DNS-320, DNS-326, DNS-320L, DNS-1550-04, DNS-1200-05, DNR-202L, DNS-340L
Provider severity
HIGH
Conflicts
3

CVE-2026-42129

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

PUBLISHED
Vendor
Grafana
Product
Grafana OSS
Provider severity
HIGH
Conflicts
1

CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

PUBLISHED
Vendor
Grafana, Grafana
Product
Grafana OSS, Grafana Enterprise
Provider severity
HIGH
Conflicts
2

CVE-2026-4212

A security vulnerability has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects the function Downloads_Schedule_Info of the file /cgi-bin/download_mgr.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and ma

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DNS-1550-04, DNS-726-4, DNS-345, DNS-315L, DNS-326, DNS-325, DNS-320L, DNS-321, DNS-343, DNR-202L, DNS-320LW, DNS-340L, DNS-323, DNS-1100-4, DNS-1200-05, DNR-326, DNS-327L, DNR-322L, DNS-320, DNS-120
Provider severity
HIGH
Conflicts
3

CVE-2026-4211

A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this issue is the function Local_Backup_Info of the file /cgi-bin/local_backup_mgr.cgi. This manipulation of the argument f_idx causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DNS-323, DNS-315L, DNS-120, DNS-345, DNS-320LW, DNR-322L, DNS-320, DNS-320L, DNS-321, DNS-340L, DNS-327L, DNS-326, DNS-1100-4, DNS-325, DNR-326, DNS-1200-05, DNS-1550-04, DNS-343, DNS-726-4, DNR-202L
Provider severity
HIGH
Conflicts
3

CVE-2026-42100

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.  The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and mi

PUBLISHED
Vendor
Sparx Systems
Product
Pro Cloud Server
Provider severity
HIGH
Conflicts
0

CVE-2026-4210

A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function cgi_tm_set_share of the file /cgi-bin/time_machine.cgi. The manipulation of the argument Name results in command injection. It is possible to launch the attack remotely. The exploit has be

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DNS-1200-05, DNS-321, DNS-320L, DNS-343, DNR-326, DNS-327L, DNS-326, DNS-325, DNR-202L, DNS-315L, DNS-323, DNS-320LW, DNS-1100-4, DNR-322L, DNS-1550-04, DNS-120, DNS-345, DNS-726-4, DNS-320, DNS-340L
Provider severity
MEDIUM
Conflicts
3

CVE-2026-42099

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__DIR__) under the specified name. An attacker with repository access can control both the filename and file contents, allowing the creation of a malicious PHP file in a current directory. Although the file is deleted after processing, a race condition exists: if

PUBLISHED
Vendor
Sparx Systems
Product
Pro Cloud Server
Provider severity
HIGH
Conflicts
0

CVE-2026-42098

Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g. using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to the repository. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and bel

PUBLISHED
Vendor
Sparx Systems
Product
Enterprise Architect
Provider severity
HIGH
Conflicts
0

CVE-2026-42097

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might als

PUBLISHED
Vendor
Sparx Systems
Product
Pro Cloud Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42096

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

PUBLISHED
Vendor
Sparx Systems
Product
Pro Cloud Server
Provider severity
HIGH
Conflicts
0

CVE-2026-42095

bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.

PUBLISHED
Vendor
KDE
Product
Arianna
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42092

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and google_clientid. At time of publication no public patch is available.

PUBLISHED
Vendor
titraio
Product
titra
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42091

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unconditional Access-Control-Allow-Origin: * on the OPTIONS preflight handler (httpserver/server.go), any website can write arbitrary files to a goshs instance through the victim's browser — bypassing network isolation (e.g. localhost, internal network). This issu

PUBLISHED
Vendor
patrickhener
Product
goshs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42090

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML template without HTML escaping. When the note is later exported to PDF, Notesnook renders that HTML in

PUBLISHED
Vendor
streetwriters
Product
notesnook
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4209

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function cgi_create_import_users/cgi_user_batch_create/cgi_user_set_quota/cgi_user_del/cgi_user_modify/cgi_group_set_quota/cgi_group_modify/cgi_group_add/cgi_user_add/cgi_get_modify_group_info/cgi_chg_admin_pw of the file /c

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DNS-321, DNR-202L, DNS-120, DNR-326, DNS-326, DNS-340L, DNS-1100-4, DNS-325, DNS-1200-05, DNS-315L, DNS-343, DNS-345, DNS-1550-04, DNS-323, DNS-320LW, DNR-322L, DNS-726-4, DNS-320L, DNS-327L, DNS-320
Provider severity
MEDIUM
Conflicts
3

CVE-2026-42089

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package installation and code execution during CLI bootstrap. The vulnerable method is installLocalGenerators(), wh

PUBLISHED
Vendor
yeoman
Product
environment
Provider severity
HIGH
Conflicts
0

CVE-2026-42088

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Red

PUBLISHED
Vendor
OpenC3
Product
cosmos
Provider severity
CRITICAL
Conflicts
0