Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-35187

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authenticated user with ADD permission can make HTTP/HTTPS requests to internal network resources and cloud metadata endpoints, read local files via file:// protocol (pycurl reads the file server-side), inte

PUBLISHED
Vendor
pyload
Product
pyload
Provider severity
HIGH
Conflicts
0

CVE-2026-35186

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For 32-bit tables this means that the result of the operator, internally in Winch, is tagged as a 64-bit value instead of a 32-bit value. This invalid internal representation of Winch's compiler state compounds into further issues depending on how the value is consumed. The pr

PUBLISHED
Vendor
bytecodealliance
Product
wasmtime
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-35185

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information. This vulnerability is fixed in 25.0.0.

PUBLISHED
Vendor
haxtheweb
Product
HAXiam
Provider severity
HIGH
Conflicts
1

CVE-2026-35184

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

PUBLISHED
Vendor
phili67
Product
ecclesiacrm
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-35183

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard/ArticleController.php within the deleteImage method. The endpoint accepts a filename from the URL but does not verify ownership. This allows an authenticated user with edit permissions to delete images attached to articles owned by other users. This vulnerability is fixed in 2.0.6.

PUBLISHED
Vendor
Ajax30
Product
BraveCMS-2.0
Provider severity
HIGH
Conflicts
0

CVE-2026-35182

Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to change account roles and promote themselves to Super Admin. This vulnerability is fixed in 2.0.6.

PUBLISHED
Vendor
Ajax30
Product
BraveCMS-2.0
Provider severity
HIGH
Conflicts
0

CVE-2026-35181

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based security check via ignoreTableSecurityCheck(), removing the only other layer of defense. Combined with SameSite=None cookies, a cross-origin POST can modify the video player appearance on the entire platform.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35180

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-based security check executes. Combined with SameSite=None cookie policy, a cross-origin POST can overwrite the platform's logo with attacker-controlled content.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3518

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

PUBLISHED
Vendor
Progress Software, Progress Software, Progress Software, Progress Software
Product
LoadMaster, MOVEit WAF, ECS Connections Manager, Object Scale Connection Manager
Provider severity
HIGH
Conflicts
1

CVE-2026-35179

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access token, container ID, and Instagram account ID, and passes them directly to the Graph API via InstagramUploader::publishMediaIfIsReady(). This allows any unauthenticated user to make arbitrary Graph API call

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35178

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains remote code execution vulnerability in the timezone conversion flow, which processes attacker-controlled cookie values in an unsafe manner. This vulnerability is fixed in 65.0.0.

PUBLISHED
Vendor
forceworkbench
Product
forceworkbench
Provider severity
CRITICAL
Conflicts
0

CVE-2026-35177

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

PUBLISHED
Vendor
vim
Product
vim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35176

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in POFParser::parseSection() that allows out-of-bounds heap memory access when parsing a crafted .pof file. No FPGA hardware is required to trigger this vulnerability.

PUBLISHED
Vendor
trabucayre
Product
openFPGALoader
Provider severity
HIGH
Conflicts
0

CVE-2026-35175

Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) could install a custom package even if this user is not superuser. This vulnerability is fixed in 2.2.15.

PUBLISHED
Vendor
ajenti
Product
ajenti
Provider severity
HIGH
Conflicts
0

CVE-2026-35174

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to any folder. This vulnerability allows the user to download any file on the server, including config.json.php with database credentials and overwrite critical system files, leading to remote code execution. This vulnerability is fixed in 2026.01.

PUBLISHED
Vendor
xenocrat
Product
chyrp-lite
Provider severity
CRITICAL
Conflicts
1

CVE-2026-35173

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post, Edit Draft, Edit Own Post, Edit Own Draft) to modify posts they do not own and do not have permission to edit. By passing internal class properties such as id into the post_attributes payload, an attacker can alter the object being instantiated. As a result, further actions are performed on another

PUBLISHED
Vendor
xenocrat
Product
chyrp-lite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-35172

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerabilit

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, distribution, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, distribution, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4.14, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4.13, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4.15, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4.16, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Multicluster Engine for Kubernetes, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Container Platform 4.12, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22
Provider severity
HIGH
Conflicts
2

CVE-2026-35171

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration schema supports the special () key, which enables arbitrary callable instantiation. An attacker can exploit this to execute arbitrary system commands during application startup. This is a critical remote code execution (RCE) vulnerability caused by unsafe use of

PUBLISHED
Vendor
kedro-org
Product
kedro
Provider severity
CRITICAL
Conflicts
1

CVE-2026-35170

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in BitParser::parseHeader() that allows out-of-bounds heap memory access when parsing a crafted .bit file. No FPGA hardware is required to trigger this vulnerability.

PUBLISHED
Vendor
trabucayre
Product
openFPGALoader
Provider severity
HIGH
Conflicts
0

CVE-2026-3517

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

PUBLISHED
Vendor
Progress Software, Progress Software, Progress Software, Progress Software
Product
LoadMaster, MOVEit WAF, ECS Connections Manager, Object Scale Connection Manager
Provider severity
HIGH
Conflicts
1

CVE-2026-35169

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result in a reflected cross-site scripting attack if a user is tricked into following an invalid link. The same input vector could also allow an attacker to download arbitrary markdown files on an unpatched

PUBLISHED
Vendor
aces
Product
Loris
Provider severity
HIGH
Conflicts
1

CVE-2026-35168

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via POST and executes them directly against the database without any validation, allowlist, or sanitization. An authenticated attacker with access to the Aggiornamenti module can execute arbitrary SQL stat

PUBLISHED
Vendor
devcode-it
Product
openstamanager
Provider severity
HIGH
Conflicts
0

CVE-2026-35167

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path components, traversal sequences such as ../ are preserved and can escape the intended versioned dataset directory. This is reachable through multiple entry points: catalog.load(..., version=...), DataCatalog.from_config(..., load_

PUBLISHED
Vendor
kedro-org
Product
kedro
Provider severity
HIGH
Conflicts
0

CVE-2026-35166

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.

PUBLISHED
Vendor
gohugoio
Product
hugo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35165

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not correctly verifying access permissions. A user could theoretically download a file that they should not have access to, if they know or can brute force the filename. This vulnerability is fixed in 27.0.3

PUBLISHED
Vendor
aces
Product
Loris
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35164

Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirely on user input. This allows an authenticated user to upload executable PHP scripts and gain Remote Code Execution. This vulnerability is fixed in 2.0.6.

PUBLISHED
Vendor
Ajax30
Product
BraveCMS-2.0
Provider severity
HIGH
Conflicts
0

CVE-2026-35162

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3516

The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in all versions up to, and including, 3.0.18. This is due to insufficient input sanitization and output escaping when handling the Google Maps iframe custom field. The saveCustomFields() function in class-contact-list-custom-fields.php uses a regex to extract <iframe> tags from user input but does not validate or sanitize the iframe's attributes, allowing event handlers like 'onl

PUBLISHED
Vendor
anssilaitila
Product
Contact List – Online Staff Directory & Address Book
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35159

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

PUBLISHED
Vendor
Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell, Dell
Product
Precision Tower 7865, Pro Max Tower T2 FCT2250, Pro Rugged 14 RB14250, Vostro 3910, Vostro 3030S, Pro 13 Premium PA13250, 27 All-in-One EC27250, XPS 16 9640, Precision 3570, Pro Slim Essential QVS1260, Inspiron 14 Plus 7430, Precision 3590, Precision 5860 Tower, Latitude 7320 Detachable, Alienware m16 R2, OptiPlex 7090 Tower, XPS 14 (14 Premium) DA14250, Pro Tower Plus QBT1250/Pro Tower QCT1250, XPS 17 9720, PC16255, Latitude 3320, Latitude 5531, OptiPlex 7000 Micro / OptiPlex 7000 Small Form Factor / OptiPlex 7000 Tower / OptiPlex 7000 XE Micro, Inspiron 14 Plus 7420, Latitude 7530, Vostro 5890, ChengMing 3900, Inspiron 15 3520, XPS 13 9340, Inspiron 16 5630, Precision 7780, Alienware x14 R2, Latitude 9430, Latitude 7340, Inspiron 3020 Desktop, Dell 14 DC14250, Latitude 7420, Latitude 5550, Latitude 7450, Pro 16 PC16250, Inspiron 5410 All-in-One, Alienware 18 Area-51 AA18250, Inspiron 3030, Pro 14 Plus PB14255, Latitude 5320, Latitude 5520, Vostro 3020 Tower Desktop, ChengMing 3910/3911, 16 Plus 2-in-1 DB06250, Vostro 15 3510, Precision 3571, Pro 14 Essential PV14250, Pro 14 PC14250, Pro Max 14 MC14255, XPS 13 9350, Latitude 9450, XPS 9320, G16 7620, Latitude 5530, Precision 3591, Inspiron 14 5440, OptiPlex Micro 7020, Pro Max 14 MC14250, Alienware Area-51 AAT2250, Pro Micro / QCM1255, Alienware m15 R7, Pro Tower Plus QBT1250 / Pro Tower QCT1250, Precision 7960 Tower, Vostro 14 3430, G15 5510, Vostro 16 5630, Pro Rugged 13 RA13250, Inspiron 16 7640 2-in-1, OptiPlex Micro 7010 / OptiPlex Micro Plus 7010, Latitude 5430, Inspiron 7710 All-in-One, Slim ECS1250, Latitude 7440, Precision 5680, OptiPlex 5000 Micro / OptiPlex 5000 Small Form Factor / OptiPlex 5000 Tower, XPS 17 9730, Pro Slim Plus QBS1250 / Pro Slim QCS1250, Inspiron 15 3511, Precision 3561, XPS 13 Plus 9320, Alienware 16X Aurora AC16251, Precision 3460 XE Small Form Factor / Precision 3460 Small Form Factor, OptiPlex 3090 Ultra, Pro Rugged 10 Tablets, 14 Plus 2-in-1 DB04250, Pro Rugged 12 Tablet, Latitude 5340, Latitude 5431, Inspiron 24 5430 All-in-One, OptiPlex 7090 Ultra, Inspiron 16 5620, Pro Slim Plus QBS1250/Pro Slim QCS1250, OptiPlex Tower 7010 / OptiPlex Tower Plus 7010, Pro Laptop PC14250, Inspiron 3030S, Vostro 14 3420, OptiPlex 5090 Micro / OptiPlex 5090 Small Form Factor / OptiPlex 5090 Tower, OptiPlex 7000 OEM MT+, Latitude 7320, Precision 3260 XE Compact / Precision 3260 Compact, Inspiron 16 Plus 7630, Precision 3580, Pro Slim / QCS1255, OptiPlex XE4 SFF, Latitude 7330 Rugged Laptop, Latitude 3340, Latitude 7430, 14 Plus DB14250, Inspiron 14 7440 2-in-1, Inspiron 14 5430, Latitude 9520, Precision 3490, XPS 15 9520, G15 5520, Precision 5470, Precision 7680, Precision 5570, Inspiron 16 Plus 7640, OptiPlex 3000 Micro / OptiPlex 3000 Small Form Factor / OptiPlex 3000 Tower, Alienware 16 Area-51 AA16250, XPS 15 9530, G15 5530, OptiPlex SFF 7020, Alienware x16 R1, OptiPlex 5400 All-In-One, OptiPlex Tower 7020, Precision 5770, Vostro 15 3530, Latitude 5350, Latitude 7230 Rugged Extreme, Inspiron 13 5330, 24 All-in-One EC24250, Latitude 7330, Latitude 7030 Rugged Extreme, Inspiron 14 Plus 7440, Latitude 7640, Vostro 3020 Small Desktop, Precision 3581, Latitude 7650, Precision 7875 Tower, Precision 3280 CFF, Alienware m16 R1, OptiPlex 3000 Thin Client, Alienware M18 R2, G15 5511, Inspiron 16 5640, OptiPlex AIO 7420, Pro Precision 7 T1, Inspiron 16 Plus 7620, Latitude 5540, Pro Micro/Micro Plus QCM1250/QBM1250, Vostro 7620, OptiPlex 7490 AIO, Pro Max 16 MC16255, Inspiron 14 7430 2-in-1, Inspiron 27 7720 All-in-One, Precision 5490, OptiPlex 5490 AIO, 16 Plus DB16250, Inspiron 14 5420, Precision 7670, Precision 3450, Vostro 14 3440, Latitude 9330, XPS 16 (16 Premium) DA16250, Inspiron 24 5420 All-in-One, Precision 5480, Pro 14 Plus PB14250, Pro Tower Essential QVT1260, Vostro 15 3520, Pro 24 All-In-One Plus QB24250 / Pro 24 All-In-One QC24250 / Pro 24 All-In-One QC24251, G16 7630, Precision 3660, Pro Max 16 MC16250, PC14255, Tower ECT1250, Inspiron 15 3530, Latitude 7350, Pro 13 Plus PB13255, Pro 16 Plus PB16250, Precision 3480, Latitude 5521, Precision 7770, XPS 13 9315, Alienware m18 R1, Vostro 16 5640, Precision 7760, Alienware Aurora ACT1250, Precision 5690, Precision 5560, Precision 3560, Vostro 3030, Pro 14 Premium PA14250, Inspiron 3020 S, XPS 15 9510, Inspiron 27 7730 All-in-One, Precision 3680 Tower, Alienware m15 R6, Latitude 5440, Alienware X16 R2, OptiPlex 7400 All-In-One, Pro Laptop PC16250, Pro Tower / QCT1255, Latitude 5450, Pro Max Micro FCM2250, Latitude 5421, Inspiron 16 7630 2-in-1, Precision 7560, Vostro 5620, Latitude 5330, Pro Micro Plus QBM1250 / Pro Micro QCM1250, Precision 3650 MT, Latitude 5430 Rugged Laptop, Pro Max Slim FCS1250, Latitude 9420, OptiPlex All-in-One 7410, Latitude 7520, XPS 14 9440, OptiPlex Small Form Factor 7010 / OptiPlex Small Form Factor Plus 7010, Alienware 16 Aurora AC16250, Pro 13 Plus PB13250, Precision 3470, 15 DC15250, Latitude 9440 2-in-1, Pro 16 Plus PB16255
Provider severity
MEDIUM
Conflicts
1

CVE-2026-35157

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.

PUBLISHED
Vendor
Dell, Dell
Product
ECS, ObjectScale
Provider severity
MEDIUM
Conflicts
1

CVE-2026-35155

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.

PUBLISHED
Vendor
Dell
Product
iDRAC10
Provider severity
HIGH
Conflicts
0

CVE-2026-35154

Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Domain appliances
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35153

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Domain
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35152

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with permission to run reports to inject arbitrary SQL via crafted parameter values. This can be leveraged to perform unauthorized access to data beyond what the report was designed to expose. Users are recommended to upgrade t

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Fineract
Provider severity
HIGH
Conflicts
0

CVE-2026-3515

A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, leading to potential Server-Side Request Forgery (SSRF), credential theft, or remote code execution (RCE)

PUBLISHED
Vendor
prefecthq
Product
prefecthq/prefect
Provider severity
HIGH
Conflicts
0

CVE-2026-35149

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.

PUBLISHED
Vendor
HCL Software
Product
DFXServer
Provider severity
HIGH
Conflicts
0

CVE-2026-35148

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.

PUBLISHED
Vendor
HCL Software
Product
DFXServer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35147

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.

PUBLISHED
Vendor
HCL Software
Product
DFXServer
Provider severity
HIGH
Conflicts
0

CVE-2026-35146

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.

PUBLISHED
Vendor
HCLSoftware
Product
DFXServer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35145

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
LOW
Conflicts
0

CVE-2026-35143

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
LOW
Conflicts
0

CVE-2026-35142

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
LOW
Conflicts
0

CVE-2026-35141

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a mechanism to include timestamps with every message, ensuring that messages exceeding a specific age threshold are automatically rejected by the recipient system.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
LOW
Conflicts
0

CVE-2026-35140

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.

PUBLISHED
Vendor
HCL Software
Product
DFXAnalytics
Provider severity
LOW
Conflicts
0

CVE-2026-3514

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication checks. This allows an attacker to create resources with names ending in 'health' or 'ready' and access them without authentication. Affected endpoints include those for variables, flows, work pools, work queues, and dep

PUBLISHED
Vendor
prefecthq
Product
prefecthq/prefect
Provider severity
HIGH
Conflicts
0

CVE-2026-3513

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'class', 'help_link', 'popup_title', and 'help_title'. The do_shortcode_button() function extracts these attributes without sanitization and passes them to TABLEON_HELPER::draw_html_item(), whic

PUBLISHED
Vendor
realmag777
Product
TableOn – WordPress Posts Table Filterable
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3512

The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and including 0.1. This is due to insufficient input sanitization and output escaping in the bjl_wprintstylo_comments_nav() function. The function directly outputs the $_GET['p'] parameter into an HTML href attribute without any escaping. This makes it possible for authenticated attackers with Contributor-level permissions or higher to inject arbitrary we

PUBLISHED
Vendor
alhadeff
Product
Writeprint Stylometry
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3511

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by t

PUBLISHED
Vendor
Slovensko.Digital
Product
Autogram
Provider severity
HIGH
Conflicts
0

CVE-2026-35099

Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.

PUBLISHED
Vendor
Lakeside Software
Product
SysTrack Agent
Provider severity
HIGH
Conflicts
0

CVE-2026-35098

KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform unlimited authentication requests. This lack of rate‑limiting enables efficient brute‑force attacks against user accounts. When combined with vulnerability CVE-2026-35097, where passwords are restricted to a six‑digit numeric format, this becomes a critical issue, as such passwords can be brute‑forced in a relatively short time. This issue was fixed in the patch published in J

PUBLISHED
Vendor
KTM System
Product
e-BOK
Provider severity
MEDIUM
Conflicts
0