Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-40731

Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
ChapterOne
Provider severity
HIGH
Conflicts
0

CVE-2026-40730

Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6.

PUBLISHED
Vendor
ThemeGrill
Product
ThemeGrill Demo Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4073

The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions up to, and including, 1.0.5. This is due to insufficient input sanitization and output escaping on the 'text' shortcode attribute. The output_shortcode() function directly concatenates the user-supplied $text variable into HTML output without applying esc_html() or any other escaping function. This makes it possible for authenticated attackers, with Contributor-level access an

PUBLISHED
Vendor
dougblackjr
Product
pdfl.io
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40729

Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer – Embed 3D Models: from n/a through <= 1.8.5.

PUBLISHED
Vendor
bPlugins
Product
3D viewer – Embed 3D Models
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40728

Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.

PUBLISHED
Vendor
BlockArt
Product
Magazine Blocks
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40727

Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.

PUBLISHED
Vendor
Groundhogg
Product
Groundhogg
Provider severity
HIGH
Conflicts
0

CVE-2026-40726

Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.

PUBLISHED
Vendor
ThemeGrill
Product
User Registration Stripe
Provider severity
HIGH
Conflicts
0

CVE-2026-40725

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

PUBLISHED
Vendor
Barn2 Media Ltd
Product
WooCommerce Product Filters
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40724

CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.

PUBLISHED
Vendor
Client Portal Ltd.
Product
Client Portal (Pro)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40723

Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.

PUBLISHED
Vendor
Bricks
Product
Bricks Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40722

Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.

PUBLISHED
Vendor
Yoast BV
Product
Yoast SEO Premium
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40721

Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.

PUBLISHED
Vendor
BdThemes
Product
Element Pack Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-40720

Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.

PUBLISHED
Vendor
Royal Elementor Addons
Product
Royal Elementor Addons Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-4072

The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'amount', 'email', 'title', 'return_url', 'cancel_url', 'ccode', and 'image'. The wordpress_paypal_donation_create() function uses extract(shortcode_atts(...)) to process shortcode attributes and then directly interpolat

PUBLISHED
Vendor
tstachl
Product
WordPress PayPal Donation
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40719

Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.

PUBLISHED
Vendor
MaraDNS
Product
MaraDNS
Provider severity
HIGH
Conflicts
0

CVE-2026-40717

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

PUBLISHED
Vendor
Dell
Product
Monitor driver
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40715

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

PUBLISHED
Vendor
Dell
Product
ThinOS 10
Provider severity
HIGH
Conflicts
0

CVE-2026-40714

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-40713

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.

PUBLISHED
Vendor
Dell
Product
ThinOS 10
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40712

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Manager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

PUBLISHED
Vendor
Dell
Product
Container Storage Modules
Provider severity
HIGH
Conflicts
0

CVE-2026-4071

The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the database via update_option() without verifying a nonce. This makes it possible for unauthenticated attackers to change the plugin's BirdSeed token setting via a forged request, granted they can trick a site adm

PUBLISHED
Vendor
birdseedapp
Product
BirdSeed
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40706

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.

PUBLISHED
Vendor
Tuxera
Product
NTFS-3G
Provider severity
HIGH
Conflicts
0

CVE-2026-40703

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40702

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.

PUBLISHED
Vendor
EVoke
Product
EVoke CSMS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-40701

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond its control that may cause a heap-use-after-free error in the NGINX worker process. This vulnerability may result in limited modification of data or

PUBLISHED
Vendor
F5, F5
Product
NGINX Plus, NGINX Open Source
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4070

The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_manage() function which handles feed deletion via the 'delete' GET parameter. This makes it possible for unauthenticated attackers to delete arbitrary plugin feed data (from alfie_colindex, alfie_producten, alfie_reactions, and alfie_searchproduct tables) via a forged request granted they can trick a site admini

PUBLISHED
Vendor
pftool
Product
Alfie – Feed Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40699

A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-40698

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
BIG-IP, BIG-IQ
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40691

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
HIGH
Conflicts
1

CVE-2026-40690

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4069

The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_option_page() function combined with insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject malicious web scripts that will be stored in the plugin's database and execute whenever a user accesses the page displaying the inject

PUBLISHED
Vendor
pftool
Product
Alfie – Feed Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40688

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

PUBLISHED
Vendor
Fortinet
Product
FortiWeb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40687

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

PUBLISHED
Vendor
Exim
Product
Exim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40686

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

PUBLISHED
Vendor
Exim
Product
Exim
Provider severity
LOW
Conflicts
0

CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

PUBLISHED
Vendor
Exim
Product
Exim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40684

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

PUBLISHED
Vendor
Exim
Product
Exim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40683

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_enabled_invert was True. When False, the raw string value from LDAP (e.g., "FALSE") was used directly. Since non-empty strings are truthy in Python, users marked as disabled in LDAP were treated as ena

PUBLISHED
Vendor
OpenStack
Product
Keystone
Provider severity
HIGH
Conflicts
0

CVE-2026-40682

A flaw was found in Apache OpenNLP. A remote attacker can exploit this vulnerability by providing a specially crafted dictionary file. This can lead to an XML External Entity (XXE) injection, which allows for the disclosure of local files or enables server-side request forgery (SSRF), where the server makes unauthorized requests to other systems.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Fuse 7, Red Hat Fuse 7, Apache OpenNLP, Red Hat build of Apache Camel for Spring Boot 4, Red Hat Data Grid 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform 8
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-4068

The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add field' operation (line 24-36), but the 'delete field' operation (lines 38-49) processes the $_GET['delete'] parameter and calls update_option() without any nonce verification. This makes it possible fo

PUBLISHED
Vendor
pattihis
Product
Add Custom Fields to Media
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40677

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.

PUBLISHED
Vendor
AMD, AMD, AMD
Product
AMD µProf, AMD Ryzen™ Master, AMD Management Console (AMC)
Provider severity
HIGH
Conflicts
1

CVE-2026-4067

The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input sanitization and output escaping on the 'client' shortcode attribute. The ad_func() shortcode handler at line 71 accepts a 'client' attribute via shortcode_atts() and directly concatenates it into a double-quoted HTML attribute (data-ad-client) at line 130 without applying esc_attr() or any other sa

PUBLISHED
Vendor
nocaredev
Product
Ad Short
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4066

The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private and draft post content from other authors via the smart-cf-relational-posts-search AJAX action. The function queries posts with post_status=any and returns full WP_Post objects inc

PUBLISHED
Vendor
inc2734
Product
Smart Custom Fields
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4065

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires unfiltered_html capability), and several controller actions only validate the nonce (validateToken()) without calling validatePermission(). This makes it possible for authenticated attacke

PUBLISHED
Vendor
nextendweb
Product
Smart Slider 3
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40641

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4064

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.

PUBLISHED
Vendor
Devolutions
Product
PowerShell Universal
Provider severity
HIGH
Conflicts
0

CVE-2026-40639

Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

PUBLISHED
Vendor
Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell
Product
Latitude 7220 Rugged Extreme, Latitude Rugged 5420, Dell Edge Gateway 5000, Dell Edge Gateway 3000, Dell Precision 3630 Tower, DELL EMBEDDED PC 3000, Precision 3930 Rack, Latitude Rugged 5424, Latitude Rugged 7424, Latitude Rugged 7220EX, Dell Precision 3930 Rack, DELL EMBEDDED PC 5000
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40638

Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

PUBLISHED
Vendor
Dell
Product
PowerScale InsightIQ
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40636

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker.

PUBLISHED
Vendor
Dell, Dell
Product
ObjectScale, ECS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-40633

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS
Provider severity
HIGH
Conflicts
0