Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-4039

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. Upgrading to version 2026.2.21-beta.1 is able to resolve this issue. This patch is called 8c9f35cdb51692b650ddf05b259ccdd75cc9a83c. It is recommended to upgrade the affected component.

PUBLISHED
Vendor
n/a
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
2

CVE-2026-40386

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

PUBLISHED
Vendor
libexif project
Product
libexif
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40385

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

PUBLISHED
Vendor
libexif project
Product
libexif
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40384

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

PUBLISHED
Vendor
Joomla! Project
Product
Joomla! CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40383

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

PUBLISHED
Vendor
Joomla! Project
Product
Joomla! CMS
Provider severity
HIGH
Conflicts
0

CVE-2026-40382

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 version 23H2, Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 11 version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-40381

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Connected Machine Agent
Provider severity
HIGH
Conflicts
0

CVE-2026-40380

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows 10 Version 1809, Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2016, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4038

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions such as 'update_option' to update the default role for registration to administrator and enable user registration for attackers to gain administrative user acces

PUBLISHED
Vendor
CodeRevolution
Product
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40379

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Entra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40378

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 11 version 23H2, Windows Server 2012 R2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-40377

Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2016, Windows Server 2025, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows 11 version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-40376

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
HIGH
Conflicts
0

CVE-2026-40374

Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Power Automate for Desktop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40372

A flaw was found in ASP.NET Core due to improper verification of cryptographic signatures. An unauthorized attacker can exploit this vulnerability remotely over a network, leading to privilege escalation.

PUBLISHED
Vendor
Red Hat, Red Hat, Microsoft, Microsoft, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Enterprise Linux 10, ASP.NET Core 10.0, Microsoft Visual Studio 2026 version 18.5, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Provider severity
CRITICAL
Conflicts
3

CVE-2026-40371

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Dynamics 365 (on-premises) version 9.1
Provider severity
HIGH
Conflicts
0

CVE-2026-40370

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2017 (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft SQL Server 2025 (CU 4), Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2022 for x64-based Systems (CU 24)
Provider severity
HIGH
Conflicts
1

CVE-2026-40369

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-40368

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-40367

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft Office LTSC 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, Microsoft Word 2016, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-40366

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft Word 2016, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-40365

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft Word 2016, Microsoft Office 2019
Provider severity
HIGH
Conflicts
2

CVE-2026-40363

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2021, Microsoft Office 2016, Microsoft Office LTSC 2024, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft Office for Android, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-40362

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021, Office Online Server, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-40361

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office LTSC for Mac 2024, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Word 2016, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-40360

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2019, Microsoft Excel 2016, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021, Office Online Server
Provider severity
HIGH
Conflicts
1

CVE-2026-40359

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Office Online Server, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2024, Microsoft Excel 2016, Microsoft Office 2019, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC for Mac 2021
Provider severity
HIGH
Conflicts
1

CVE-2026-40358

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft Office LTSC 2024
Provider severity
HIGH
Conflicts
1

CVE-2026-40357

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-40356

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

PUBLISHED
Vendor
MIT
Product
Kerberos 5
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40355

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

PUBLISHED
Vendor
Siemens, MIT, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Kerberos 5, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40354

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.

PUBLISHED
Vendor
Flatpak
Product
xdg-desktop-portal
Provider severity
LOW
Conflicts
0

CVE-2026-40353

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django's |safe filter. An authenticated user can create an ingredient with a malicious license_author value containing JavaScript, which executes in the browser of any visitor viewing the ingredient page, res

PUBLISHED
Vendor
wger-project
Product
wger
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40352

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed

PUBLISHED
Vendor
labring
Product
FastGPT
Provider severity
HIGH
Conflicts
0

CVE-2026-40351

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. This issue has been fixed in version 4.14.9.5.

PUBLISHED
Vendor
labring
Product
FastGPT
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40350

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the route definitions do not enforce admin-only middleware, and the controller-level authorization check uses a broken boolean condition. As a result, any user with a valid web session cookie can reach functionali

PUBLISHED
Vendor
leepeuker
Product
movary
Provider severity
HIGH
Conflicts
0

CVE-2026-4035

A flaw was found in MLflow. This vulnerability allows an attacker to exfiltrate sensitive server-side environment credentials. It occurs because the AI Gateway secrets can resolve environment variables, which are then sent to an attacker-controlled endpoint. This could lead to unauthorized access to cloud resources and potentially enable cross-boundary code execution.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, mlflow, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), mlflow/mlflow, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-40349

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a user edit their own profile, but it updates the sensitive `isAdmin` field without any admin-only authorization check. Version 0.71.1 patches the issue.

PUBLISHED
Vendor
leepeuker
Product
movary
Provider severity
HIGH
Conflicts
0

CVE-2026-40348

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoint accepts a user-controlled URL, appends `/system/info/public`, and sends a server-side HTTP request with Guzzle. Because there is no restriction on internal hosts, loopback addresses, or private network ranges, this can be abused for SSRF an

PUBLISHED
Vendor
leepeuker
Product
movary
Provider severity
HIGH
Conflicts
0

CVE-2026-40347

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.

PUBLISHED
Vendor
Kludex
Product
python-multipart
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40346

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An authenticated user can access internal network services, cloud metadata endpoints, and localhost. Version 2.0.37 contains a patch.

PUBLISHED
Vendor
nocobase
Product
@nocobase/plugin-workflow-request
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40344

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows any user who knows a valid access key to write arbitrary objects to any bucket without knowing the secret key or providing a valid cryptographic signature. Any MinIO deployment is impacted. The attack requires only a valid access key (the well-known

PUBLISHED
Vendor
minio
Product
minio
Provider severity
HIGH
Conflicts
1

CVE-2026-40343

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors. This may allow unintended creation of Policy Data notification subscriptions with invalid, empty, or partially processe

PUBLISHED
Vendor
free5gc
Product
udr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a filesystem path without filtering path separators or .. components. An authenticated user with CREATE FUNCTION privileges can use a crafted ENGINE name to load an arbitrary shared library from anywhere on the filesystem via path traversal. The library's initialization code executes immediately during load

PUBLISHED
Vendor
FirebirdSQL
Product
firebird
Provider severity
CRITICAL
Conflicts
1

CVE-2026-40341

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.

PUBLISHED
Vendor
gphoto
Product
libgphoto2
Provider severity
LOW
Conflicts
0

CVE-2026-40340

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). The function validates `len < PTP_oi_SequenceNumber` (i.e., len < 48) but subsequently accesses offsets 48–56, up to 9 bytes beyond the validated boundary, via the Samsung Galaxy 64-bit objectsize detection heuristic. Commit 7c7f515bc88c3d0c4098ac965d313518e0ccbe33 fixes the issue.

PUBLISHED
Vendor
gphoto
Product
libgphoto2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40339

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without a prior bounds check. The standard `ptp_unpack_DPD()` at lines 686–687 correctly validates `*offset + sizeof(uint8_t) > dpdlen` before this same read, but the Sony variant omits this check entirely. Commit 09f8a940b1e418b5693f5c11e3016a1ad2cea6

PUBLISHED
Vendor
gphoto
Product
libgphoto2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40338

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8c

PUBLISHED
Vendor
gphoto
Product
libgphoto2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40337

The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to interact with another task's IRQ line through the __sys_int_* syscall familly. Prior to version 0.4.7, this can lead to DoS and covert-channels between this task and the outer world. A patch is available in version 0.4.7. As a workaround, reduce tasks that have the DEV and IO capability to a single one.

PUBLISHED
Vendor
camelot-os
Product
sentry-kernel
Provider severity
MEDIUM
Conflicts
0