Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-35097

KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in the patch published in June 2026.

PUBLISHED
Vendor
KTM System
Product
e-BOK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35096

KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the application. This allows the attacker to trigger an unauthorized email or password change on behalf of the victim without their knowledge or interaction. This issue was fixed in the patch published in June 2026.

PUBLISHED
Vendor
KTM System
Product
e-BOK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35095

KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful login. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in the patch published in June 2026.

PUBLISHED
Vendor
KTM System
Product
e-BOK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35094

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10
Provider severity
LOW
Conflicts
1

CVE-2026-35093

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
1

CVE-2026-35092

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
1

CVE-2026-35091

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
1

CVE-2026-35090

In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telephone with a specific caller ID. This allows them to bypass admin authentication and gain full access to the service protocol and configuration panel. This vulnerability is independent of the telephone exchanges configuration. If remote access is disabled, calling with this caller ID will temporarily enable it. This issue was fixed in versions below:

PUBLISHED
Vendor
Slican, Slican, Slican, Slican, Slican
Product
IPM-032, CCT-1668, MAC-6400, CXS-0424, IPL-256
Provider severity
CRITICAL
Conflicts
1

CVE-2026-3509

An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.

PUBLISHED
Vendor
CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS, CODESYS
Product
CODESYS Control for Linux SL, CODESYS Control for Linux ARM SL, CODESYS Control for IOT2000 SL, CODESYS Control Win (SL), CODESYS Control for BeagleBone SL, CODESYS Virtual Control SL, CODESYS Control RTE (SL), CODESYS Control for PLCnext SL, CODESYS Runtime Toolkit, CODESYS Control for PFC100 SL, CODESYS Control for WAGO Touch Panels 600 SL, CODESYS Control for PFC200 SL, CODESYS Control for Raspberry Pi SL, CODESYS Control RTE (for Beckhoff CX) SL, CODESYS Control for emPC-A/iMX6 SL
Provider severity
HIGH
Conflicts
1

CVE-2026-35089

In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthenticated attacker can deduce the secure key and obtain admin credentials. This issue was fixed in versions below: - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below:

PUBLISHED
Vendor
Slican, Slican, Slican, Slican
Product
CXS-0424, IPx, CCT-1668, MAC-6400
Provider severity
HIGH
Conflicts
1

CVE-2026-35087

Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executing the appropriate command. This issue was fixed in versions below: - NCP: version 1.24.0250 - IPx series: version 6.61.0040 - CCT-1668: version 6.56.0430 - MAC-6400: version 6.56.0430 - CXS-0424: version 6.30.0510 The issue STILL EXISTS in End-Of-Life telephone exchanges in versions 4.xx and below: - CCT-1668 (CCT1CPU) - MAC-6400 - CXS-0424 Thes

PUBLISHED
Vendor
Slican, Slican, Slican, Slican, Slican
Product
IPx, NCP, MAC-6400, CCT-1668, CXS-0424
Provider severity
CRITICAL
Conflicts
1

CVE-2026-35086

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache OFBiz
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35085

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Triple-X KNX+M-Bus, Triple-X KNX+LON, Double-X LON, Double-X M-Bus, Double-X PROFINET, Single-A, Double-X KNX, Double-X DALI, Double-A Profibus, Triple-X PROFINET+LON, Double-A x-link, Triple-X PROFINET+DALI, Single-X, Double-X CAN, Double-X x-link, Triple-X KNX+DALI, Triple-X PROFINET+KNX, Triple-X PROFINET+M-Bus
Provider severity
HIGH
Conflicts
2

CVE-2026-35084

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-X M-Bus, Triple-X KNX+LON, Double-X KNX, Double-X x-link, Double-A Profibus, Triple-X KNX+DALI, Double-X LON, Double-X CAN, Triple-X PROFINET+M-Bus, Single-A, Triple-X PROFINET+KNX, Triple-X PROFINET+DALI, Double-X DALI, Single-X, Triple-X KNX+M-Bus, Double-A x-link, Triple-X PROFINET+LON, Double-X PROFINET
Provider severity
HIGH
Conflicts
2

CVE-2026-35083

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Triple-X KNX+LON, Double-X x-link, Double-A Profibus, Single-X, Double-X DALI, Triple-X PROFINET+LON, Double-X PROFINET, Double-X CAN, Double-X KNX, Double-A x-link, Double-X M-Bus, Single-A, Triple-X PROFINET+DALI, Triple-X KNX+M-Bus, Double-X LON, Triple-X PROFINET+M-Bus, Triple-X KNX+DALI, Triple-X PROFINET+KNX
Provider severity
HIGH
Conflicts
2

CVE-2026-35082

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-X x-link, Double-X M-Bus, Single-X, Triple-X PROFINET+M-Bus, Double-X LON, Triple-X PROFINET+LON, Double-X CAN, Triple-X KNX+DALI, Double-X KNX, Double-A x-link, Triple-X KNX+M-Bus, Triple-X PROFINET+DALI, Triple-X PROFINET+KNX, Double-X PROFINET, Double-A Profibus, Single-A, Triple-X KNX+LON, Double-X DALI
Provider severity
HIGH
Conflicts
2

CVE-2026-35081

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-X DALI, Triple-X KNX+M-Bus, Triple-X KNX+DALI, Double-X PROFINET, Triple-X PROFINET+LON, Triple-X PROFINET+DALI, Triple-X PROFINET+KNX, Double-A Profibus, Double-X x-link, Triple-X PROFINET+M-Bus, Single-X, Double-X KNX, Double-X M-Bus, Double-X CAN, Double-A x-link, Single-A, Double-X LON, Triple-X KNX+LON
Provider severity
HIGH
Conflicts
2

CVE-2026-35080

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-X KNX, Triple-X PROFINET+LON, Triple-X PROFINET+KNX, Single-X, Triple-X PROFINET+M-Bus, Double-X CAN, Single-A, Double-X LON, Double-X PROFINET, Double-X M-Bus, Triple-X PROFINET+DALI, Double-A Profibus, Double-X DALI, Double-X x-link, Double-A x-link, Triple-X KNX+LON, Triple-X KNX+M-Bus, Triple-X KNX+DALI
Provider severity
HIGH
Conflicts
2

CVE-2026-3508

An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information.

PUBLISHED
Vendor
ASUS
Product
ASUS System Control Interface
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35079

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-X KNX, Double-X DALI, Single-X, Double-X CAN, Double-A Profibus, Triple-X KNX+LON, Triple-X PROFINET+LON, Triple-X PROFINET+M-Bus, Double-X LON, Double-X PROFINET, Double-X M-Bus, Double-X x-link, Triple-X PROFINET+KNX, Double-A x-link, Single-A, Triple-X PROFINET+DALI, Triple-X KNX+M-Bus, Triple-X KNX+DALI
Provider severity
HIGH
Conflicts
2

CVE-2026-35078

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Triple-X KNX+DALI, Single-A, Double-X PROFINET, Double-X CAN, Triple-X PROFINET+M-Bus, Double-X M-Bus, Double-A Profibus, Triple-X PROFINET+KNX, Double-X x-link, Double-A x-link, Double-X KNX, Triple-X PROFINET+DALI, Single-X, Triple-X PROFINET+LON, Double-X LON, Triple-X KNX+M-Bus, Double-X DALI, Triple-X KNX+LON
Provider severity
HIGH
Conflicts
2

CVE-2026-35077

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-A x-link, Single-A, Triple-X PROFINET+DALI, Double-X KNX, Double-X M-Bus, Triple-X PROFINET+M-Bus, Triple-X PROFINET+LON, Triple-X KNX+LON, Double-X PROFINET, Triple-X KNX+DALI, Single-X, Double-A Profibus, Double-X x-link, Triple-X KNX+M-Bus, Triple-X PROFINET+KNX, Double-X LON, Double-X DALI, Double-X CAN
Provider severity
HIGH
Conflicts
2

CVE-2026-35076

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Triple-X PROFINET+LON, Double-A x-link, Triple-X PROFINET+DALI, Single-A, Double-X PROFINET, Double-X LON, Triple-X PROFINET+KNX, Triple-X KNX+M-Bus, Single-X, Triple-X PROFINET+M-Bus, Triple-X KNX+DALI, Double-X M-Bus, Double-A Profibus, Double-X DALI, Double-X KNX, Double-X x-link, Double-X CAN, Triple-X KNX+LON
Provider severity
HIGH
Conflicts
2

CVE-2026-35075

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

PUBLISHED
Vendor
MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS, MBS
Product
Double-A Profibus, Triple-X KNX+DALI, Single-A, Double-X x-link, Triple-X PROFINET+M-Bus, Double-X KNX, Triple-X PROFINET+KNX, Double-A x-link, Triple-X PROFINET+LON, Double-X LON, Double-X PROFINET, Double-X M-Bus, Double-X CAN, Triple-X KNX+LON, Triple-X PROFINET+DALI, Double-X DALI, Single-X, Triple-X KNX+M-Bus
Provider severity
CRITICAL
Conflicts
2

CVE-2026-35074

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS Command Injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Domain
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35073

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Domain
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35072

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Domain
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35071

Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.

PUBLISHED
Vendor
Dell
Product
PowerScale InsightIQ
Provider severity
HIGH
Conflicts
0

CVE-2026-35070

Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

PUBLISHED
Vendor
Dell
Product
SmartFabric Storage Software
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35069

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35068

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
LOW
Conflicts
0

CVE-2026-35067

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35066

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
HIGH
Conflicts
0

CVE-2026-35065

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
HIGH
Conflicts
0

CVE-2026-35064

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are exposed by the underlying service rather than gated by authentication, an attacker on the same network segment can rapidly enumerate targeted devices.

PUBLISHED
Vendor
SenseLive
Product
X3050
Provider severity
HIGH
Conflicts
1

CVE-2026-35063

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator access.

PUBLISHED
Vendor
OpenPLC_V3
Product
OpenPLC_V3
Provider severity
HIGH
Conflicts
0

CVE-2026-35062

An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-35061

Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operational imagery.

PUBLISHED
Vendor
Anviz
Product
Anviz CX7 Firmware
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3506

The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the site's MobileMonkey API token and company ID options, which can be used to hijack chatbot configuration and redirect visitor conversations to an attacker-controlled MobileMonkey account.

PUBLISHED
Vendor
larrykim
Product
WP-Chatbot for Messenger
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35058

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.

PUBLISHED
Vendor
OpenVPN
Product
OpenVPN
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35057

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

PUBLISHED
Vendor
XenForo
Product
XenForo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-35056

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

PUBLISHED
Vendor
XenForo
Product
XenForo
Provider severity
HIGH
Conflicts
1

CVE-2026-35055

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

PUBLISHED
Vendor
XenForo
Product
XenForo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-35054

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

PUBLISHED
Vendor
XenForo
Product
XenForo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-35053

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who can obtain or guess a workflow ID can trigger arbitrary workflow execution with attacker-controlled input data, enabling JavaScript code execution, notification abuse, and data manipulation. This issue h

PUBLISHED
Vendor
OneUptime
Product
oneuptime
Provider severity
CRITICAL
Conflicts
0

CVE-2026-35052

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.

PUBLISHED
Vendor
man-group
Product
dtale
Provider severity
MEDIUM
Conflicts
0

CVE-2026-35051

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This authentication bypass vulnerability exists in Traefik's ForwardAuth middleware when the `trustForwardHeader` setting is configured as `false` and Traefik is deployed behind a trusted upstream proxy. A remote attacker could exploit this to bypass authentication, potentially gaining unauthorized access to protected resources.

PUBLISHED
Vendor
traefik, Red Hat
Product
traefik, Red Hat OpenShift Dev Spaces 3.28
Provider severity
HIGH
Conflicts
3

CVE-2026-35050

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in "py" format and in the app root directory. This allows to overwrite python files, for instance the "download-model.py" file could be overwritten. Then, this python file can be triggered to get executed from "Model" menu when requesting to download a new model. This vulnerability is fixed in 4.1.1.

PUBLISHED
Vendor
oobabooga
Product
text-generation-webui
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3505

A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA bcpg. A specially crafted PGP AEAD (Authenticated Encryption with Associated Data) message with an unbounded chunk size can lead to an excessive consumption of memory. This issue allows an unauthenticated remote attacker to cause memory exhaustion in a JVM, resulting in a denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Legion of the Bouncy Castle Inc., Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
streams for Apache Kafka 2, Red Hat Data Grid 8, Red Hat Process Automation 7, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat Fuse 7, Red Hat Single Sign-On 7, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat JBoss Enterprise Application Platform 7, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, BC-JAVA, OpenShift Developer Tools and Services, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Satellite 6, Red Hat Data Grid 8, Red Hat Satellite 6, Red Hat AMQ Clients, streams for Apache Kafka 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Enterprise Linux 9, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 7, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27
Provider severity
HIGH
Conflicts
3

CVE-2026-35049

wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the local state is wiped. This issue has been f

PUBLISHED
Vendor
wireapp
Product
wire-ios
Provider severity
MEDIUM
Conflicts
1