Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-3487

A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.php. Performing a manipulation of the argument course_code results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
College Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-34867

Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34866

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34865

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-34864

Boundary-unlimited vulnerability in the application read module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34863

Out-of-bounds write vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34862

Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34861

Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34860

Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3486

A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /admin/student-fee.php. Such manipulation of the argument roll_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
College Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-34859

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
EMUI, HarmonyOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34858

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34857

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34856

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0

CVE-2026-34855

Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
HarmonyOS, EMUI
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34854

UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
EMUI, HarmonyOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34853

Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei, Huawei
Product
EMUI, HarmonyOS
Provider severity
HIGH
Conflicts
1

CVE-2026-34852

Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34851

Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
LOW
Conflicts
0

CVE-2026-34850

Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
LOW
Conflicts
0

CVE-2026-3485

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-868L
Provider severity
CRITICAL
Conflicts
2

CVE-2026-34849

UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
LOW
Conflicts
0

CVE-2026-34848

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0.

PUBLISHED
Vendor
hoppscotch
Product
hoppscotch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34847

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper validation. This issue has been patched in version 2026.3.0.

PUBLISHED
Vendor
hoppscotch
Product
hoppscotch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34841

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran npm install between 00:21 UTC and ~03:30 UTC on March 31, 2026 may have been impacted. Upgrade to 3.2.1

PUBLISHED
Vendor
usebruno
Product
bruno
Provider severity
CRITICAL
Conflicts
1

CVE-2026-34840

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSignatureValid() verifies the first <Signature> element in the XML DOM using xml-crypto, while getEmail() always reads from assertion[0] via xml2js. An attacker can prepend an unsigned assertion containing an arbitrary identity before a legitimately signed assertion,

PUBLISHED
Vendor
OneUptime
Product
oneuptime
Provider severity
HIGH
Conflicts
0

CVE-2026-3484

A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identi

PUBLISHED
Vendor
PhialsBasement
Product
nmap-mcp-server
Provider severity
MEDIUM
Conflicts
2

CVE-2026-34839

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *`). This allows a malicious website to read sensitive system information from a running Glances instance in the victim’s browser, leading to cross-origin data exfiltration. While a previous advisory ex

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
1

CVE-2026-34838

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0

PUBLISHED
Vendor
Intermesh
Product
groupoffice
Provider severity
CRITICAL
Conflicts
0

CVE-2026-34837

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the AI prompt were not checked if they are accessible for the current user. This leads to having data present in the AI prompt that were not authorized before being used. A user needs to have ticket.agent permission to be able to use the provided context

PUBLISHED
Vendor
zammad
Product
zammad
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34835

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed. This can lead to host header poisoning in applications that use req.host, req.url,

PUBLISHED
Vendor
rack
Product
rack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34834

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings endpoint by providing arbitrary headers. This issue has been patched in version 1.4.10.

PUBLISHED
Vendor
bulwarkmail
Product
webmail
Provider severity
HIGH
Conflicts
0

CVE-2026-34833

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in version 1.4.10.

PUBLISHED
Vendor
bulwarkmail
Product
webmail
Provider severity
HIGH
Conflicts
0

CVE-2026-34832

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The handler enforces authentication but does not enforce object ownership (or moderator/admin authorization) before deletion. In verification, a second non-privileged account successfully deleted a victim

PUBLISHED
Vendor
Erudika
Product
scoold
Provider severity
MEDIUM
Conflicts
0

CVE-2026-34831

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains multibyte UTF-8 characters, the declared Content-Length is smaller than the number of bytes actually sent on the wire. Because Rack::Files reflects the requested path in 404 responses, an attacker can trigger this mismatch by requesting a non-existent path containing percent

PUBLISHED
Vendor
rack
Product
rack
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34830

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path interpolates the value of the X-Accel-Mapping request header directly into a regular expression when rewriting file paths for X-Accel-Redirect. Because the header value is not escaped, an attacker who can supply X-Accel-Mapping to the backend can inject regex metacharacters and control the generated X-Accel-Redirect response header. In deployments using Rack::Sendfile with x-ac

PUBLISHED
Vendor
rack
Product
rack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3483

An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

PUBLISHED
Vendor
Ivanti
Product
Desktop and Server Management
Provider severity
HIGH
Conflicts
0

CVE-2026-34829

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is sent without a Content-Length header, such as with HTTP chunked transfer encoding, multipart parsing continues until end-of-stream with no total size limit. For file parts, the uploaded body is written directly to a temporary file on disk rather than being constrained by t

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, rack, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 8, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 7, rack, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2
Provider severity
HIGH
Conflicts
2

CVE-2026-34828

listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, a session management vulnerability allows previously issued authenticated sessions to remain valid after sensitive account security changes, specifically password reset and password change. As a result, an attacker who has already obtained a valid session cookie can retain access to the account even after the victim changes or resets their password. This weakens account recover

PUBLISHED
Vendor
knadh
Product
listmonk
Provider severity
HIGH
Conflicts
0

CVE-2026-34827

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using repeated String#index searches combined with String#slice! prefix deletion. For escape-heavy quoted values, this causes super-linear processing. An unauthenticated attacker can send a crafted multipart/form-data request containing many parts with long

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, rack, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, rack, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 7, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2
Provider severity
HIGH
Conflicts
2

CVE-2026-34826

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header without limiting the number of individual byte ranges. Although the existing fix for CVE-2024-26141 rejects ranges whose total byte coverage exceeds the file size, it does not restrict the count of ranges. An attacker can supply many small overlapping ranges such as 0-0,0-0,0-0,... to trigger disproportionate CPU, memory, I/O, and bandwidth consumptio

PUBLISHED
Vendor
rack
Product
rack
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34825

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who triggers a workflow containing a SQL node with template variables from user-controlled data can inject arbitrary SQL. This issue has been patched in version 2.0.30.

PUBLISHED
Vendor
nocobase
Product
nocobase
Provider severity
HIGH
Conflicts
0

CVE-2026-34824

Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (Do

PUBLISHED
Vendor
mesop-dev
Product
mesop
Provider severity
HIGH
Conflicts
0

CVE-2026-34823

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

PUBLISHED
Vendor
Endian
Product
Endian Firewall
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34822

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

PUBLISHED
Vendor
Endian
Product
Endian Firewall
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34821

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

PUBLISHED
Vendor
Endian
Product
Endian Firewall
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34820

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

PUBLISHED
Vendor
Endian
Product
Endian Firewall
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3482

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP request.

PUBLISHED
Vendor
IBM, IBM
Product
Sterling B2B Integrator, Sterling File Gateway
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34819

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

PUBLISHED
Vendor
Endian
Product
Endian Firewall
Provider severity
MEDIUM
Conflicts
1

CVE-2026-34818

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

PUBLISHED
Vendor
Endian
Product
Endian Firewall
Provider severity
MEDIUM
Conflicts
1