Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-35554

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated and returned to the buffer pool. If a subsequent producer batch—potentially destined for a different topic—reuses this freed buffer before the original network request completes,

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Kafka Clients
Provider severity
HIGH
Conflicts
1

CVE-2026-35553

Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values.

PUBLISHED
Vendor
Dynabook Inc., Dynabook Inc.
Product
DRFEC.SYS, TOSRFEC.SYS
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-35552

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2026-3555

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. User interaction is required to exploit this vulnerability in that the user must initiate the device pairing process. The specific flaw exists within the handling of custom Zigbee ZCL frames in the Model Info download functionality. The issue results f

PUBLISHED
Vendor
Philips
Product
Hue Bridge
Provider severity
HIGH
Conflicts
0

CVE-2026-35549

An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.

PUBLISHED
Vendor
MariaDB
Product
MariaDB
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35548

An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing Enrichment Source, previously stored credentials were retained even if the connection endpoint was changed. An authenticated Operator user could redirect the database connection to unintended internal systems, resulting in

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2026-35547

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an unprivileged user to exploit the bug to elevate their privileges.

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
1

CVE-2026-35546

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

PUBLISHED
Vendor
Anviz, Anviz
Product
Anviz CX2 Lite Firmware, Anviz CX7 Firmware
Provider severity
CRITICAL
Conflicts
1

CVE-2026-35545

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35544

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35543

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35542

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35541

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35540

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3554

The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in all versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping on the 'title' attribute of the 'sherkcptdisplays' shortcode. Specifically, in the sherkcptdisplays_func() function in includes/SherkCPTDisplaysShortcode.php, the 'title' attribute value is extracted from shortcode_atts() on line 19 and directly conc

PUBLISHED
Vendor
sherkspear
Product
Sherk Custom Post Type Displays
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35539

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35538

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
LOW
Conflicts
0

CVE-2026-35537

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
LOW
Conflicts
0

CVE-2026-35536

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

PUBLISHED
Vendor
tornadoweb
Product
Tornado
Provider severity
HIGH
Conflicts
0

CVE-2026-35535

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Siemens, Red Hat, Sudo project, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat OpenShift Container Platform 4.16, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4.15, Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION, RUGGEDCOM RST2428P, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Sudo, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat OpenShift Container Platform 4.12, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.18, Red Hat AI Inference Server 3.3, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat OpenShift Container Platform 4.14
Provider severity
HIGH
Conflicts
2

CVE-2026-35534

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() as an output sanitizer for HTML attribute context. The function only strips HTML tags, it does not escape quote characters allowing an attacker to break out of the href attribute and inject arbitrary JavaScript event handlers. Any authenticated user with the EditRecords role can store the payload in a person's Facebook f

PUBLISHED
Vendor
ChurchCRM
Product
CRM
Provider severity
HIGH
Conflicts
1

CVE-2026-35533

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.

PUBLISHED
Vendor
jdx
Product
mise
Provider severity
HIGH
Conflicts
0

CVE-2026-3553

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
LOW
Conflicts
0

CVE-2026-35527

Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be reje

PUBLISHED
Vendor
lxc
Product
incus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35526

Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graphql-ws protocols allocate an asyncio.Task and associated Operation object for every incoming subscribe message without enforcing any limit on the number of active subscriptions per connection. An unauthenticated attacker can open a single WebSocket connection, send connection_init, and then flood subscribe messages with

PUBLISHED
Vendor
strawberry-graphql
Product
strawberry
Provider severity
HIGH
Conflicts
0

CVE-2026-35525

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots before reading it. That check is path-based, not realpath-based. Because of that, a file like partials/link.liquid passes the directory containment check as long as its pathname is under the allowed root. If link.liquid is actually a symlink to a file o

PUBLISHED
Vendor
harttle
Product
liquidjs
Provider severity
HIGH
Conflicts
0

CVE-2026-35523

Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a connection_init handshake has been completed before processing start (subscription) messages. This allows a remote attacker to skip the on_ws_connect authentication hook entirely by connecting with the graphql-ws subprotocol and sending a start message directly

PUBLISHED
Vendor
strawberry-graphql
Product
strawberry
Provider severity
HIGH
Conflicts
0

CVE-2026-35521

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP hosts configuration parameter (dhcp.hosts). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in 6.6.

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
HIGH
Conflicts
1

CVE-2026-35520

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configuration parameter (dhcp.leaseTime). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
HIGH
Conflicts
1

CVE-2026-3552

The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410, ajax_delete_410, ajax_bulk_410_delete, ajax_empty_41

PUBLISHED
Vendor
surflabtech
Product
SurfLink – Link Manager & Backup Restore
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35519

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configuration parameter (dns.hostRecord). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixed in

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
HIGH
Conflicts
1

CVE-2026-35518

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS CNAME records configuration parameter (dns.cnameRecords). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixe

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
HIGH
Conflicts
1

CVE-2026-35517

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the upstream DNS servers configuration parameter (dns.upstreams). This vulnerability allows an authenticated attacker to inject arbitrary dnsmasq configuration directives through newline characters, ultimately achieving command execution on the underlying system. This vulnerability is fixe

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
HIGH
Conflicts
1

CVE-2026-35516

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An authenticated user can read responses from internal services (AWS IMDSv1, cloud metadata, internal APIs) by creating a link with a public URL and then updating it to a private IP. The links:check cron job makes the request server-side without IP filtering. This can expose cloud credentials, internal service data, and network topology.

PUBLISHED
Vendor
Kovah
Product
LinkAce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35515

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-Sent Events text protocol output without sanitizing newline characters (\r, \n). Since the SSE protocol treats both \r and \n as field delimiters and \n\n as event boundaries, an attacker who can influence these fields through upstream data sources can inject arbitrary SSE events, spoof event types, and corrupt reconnec

PUBLISHED
Vendor
nestjs
Product
nest
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35514

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint directly to create a fully active account and receive a valid JWT — even when the instance has existing users and signupRestricted is enabled. This bypass is distinct from the normal registration endp

PUBLISHED
Vendor
chartbrew
Product
chartbrew
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35512

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they shou

PUBLISHED
Vendor
neutrinolabs
Product
xrdp
Provider severity
HIGH
Conflicts
0

CVE-2026-3551

The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on multiple settings fields including 'User Mail Subject', 'User From Name', 'User From Email', 'Admin Mail Subject', 'Admin From Name', and 'Admin From Email'. The settings are registered via register_setting() without sanitize callbacks, and the values re

PUBLISHED
Vendor
rafasashi
Product
Custom New User Notification
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35508

Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,

PUBLISHED
Vendor
milesmcc
Product
Shynet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35507

Shynet before 0.14.0 allows Host header injection in the password reset flow.

PUBLISHED
Vendor
milesmcc
Product
Shynet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35506

ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WRC-BE72XSD-B, WRC-W702-B, WRC-BE65QSD-B, WRC-BE72XSD-BA
Provider severity
HIGH
Conflicts
2

CVE-2026-35505

An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.

PUBLISHED
Vendor
OFFIS DICOM
Product
DCMTK Toolkit
Provider severity
HIGH
Conflicts
1

CVE-2026-35504

PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.

PUBLISHED
Vendor
Subnet Solutions, Subnet Solutions, Subnet Solutions
Product
PowerSYSTEM Center 2020, PowerSYSTEM Center 2024, PowerSYSTEM Center 2026
Provider severity
MEDIUM
Conflicts
2

CVE-2026-35503

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these exposed parameters and gain unauthorized access to administrative functionality.

PUBLISHED
Vendor
SenseLive
Product
X3050
Provider severity
CRITICAL
Conflicts
1

CVE-2026-3550

The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capability checks on multiple AJAX actions (rockpress_import, rockpress_import_status, rockpress_last_import, rockpress_reset_import, and rockpress_check_services) combined with the plugin's nonce being exposed to all authenticated users via an unconditionally enqueued admin script. The plugin enqueues the 'rockpress-admin' script on all admin pages (incl

PUBLISHED
Vendor
firetree
Product
RockPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35496

A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should not be accessible.

PUBLISHED
Vendor
CubeCart Limited
Product
CubeCart
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-35492

Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (loca

PUBLISHED
Vendor
kedro-org
Product
kedro-plugins
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35491

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, Pi-hole FTL supports a CLI password feature (webserver.api.cli_pw) that creates “CLI” API sessions intended to be read-only for configuration changes. While /api/config correctly blocks CLI sessions from mutating configuration, /api/teleporter allowed Teleporter imports for CLI sessions, enabling a CLI-scoped session to overwrite configuration via a Teleporter archiv

PUBLISHED
Vendor
pi-hole
Product
FTL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35490

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these routes. This vulnerabilit

PUBLISHED
Vendor
dgtlmoon
Product
changedetection.io
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3549

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

PUBLISHED
Vendor
wofSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0