Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-33940

A flaw was found in Handlebars.js. A remote attacker can exploit this vulnerability by providing a specially crafted object within the template context. This crafted object, when processed by a dynamic partial lookup, can bypass security checks and be interpreted as malicious code. This allows the attacker to execute arbitrary commands on the server where Handlebars.js is running.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, handlebars-lang, Red Hat
Product
Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat Data Grid 8, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Dev Spaces 3.27, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Cryostat 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Process Automation 7, Red Hat Enterprise Linux 7, Cluster Observability Operator 1.5.0, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, handlebars.js, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
2

CVE-2026-3394

A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Performing a manipulation results in memory corruption. The attack must be initiated from a local position. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
jarikomppa
Product
soloud
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-33939

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled template calls `lookupProperty(decorators, "n")`, which returns `undefined`. The runtime then immediately invokes the result as a function, causing an unhandled `TypeError: ... is not a function` that crashes the Node.js process. Any application that compiles user-su

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, handlebars-lang, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Data Grid 8, Red Hat Enterprise Linux 8, Red Hat Process Automation 7, Red Hat Enterprise Linux 7, Cluster Observability Operator 1.5.0, Cluster Observability Operator 1.5.0, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, handlebars.js, Cluster Observability Operator 1.5.0, Cryostat 4, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.27, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
2

CVE-2026-33938

A flaw was found in Handlebars. A remote attacker can exploit this vulnerability by manipulating the `@partial-block` special variable within the template data context. By overwriting `@partial-block` with a specially crafted Abstract Syntax Tree (AST) through a helper, a subsequent invocation of `{{> @partial-block}}` will compile and execute the malicious AST. This enables arbitrary JavaScript execution on the server, leading to potential compromise of the system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, handlebars-lang, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift Dev Spaces 3.27, Red Hat Enterprise Linux 10, Cluster Observability Operator 1.5.0, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), handlebars.js, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Logging Subsystem for Red Hat OpenShift, Red Hat Process Automation 7, Red Hat Enterprise Linux 8, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 7, Cluster Observability Operator 1.5.0, Cryostat 4, Red Hat Data Grid 8, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
2

CVE-2026-33937

A flaw was found in Handlebars. An attacker can exploit this by supplying a crafted Abstract Syntax Tree (AST) object to the `Handlebars.compile()` function. This allows the injection and execution of arbitrary JavaScript code due to improper sanitization of the `value` field in `NumberLiteral` AST nodes. This vulnerability can lead to Remote Code Execution (RCE) on the server.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, handlebars-lang, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Logging Subsystem for Red Hat OpenShift, Cluster Observability Operator 1.5.0, Red Hat Process Automation 7, Logging Subsystem for Red Hat OpenShift, handlebars.js, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Cluster Observability Operator 1.5.0, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10, Cryostat 4, Red Hat Data Grid 8, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 7, Red Hat OpenShift Dev Spaces 3.27, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9
Provider severity
CRITICAL
Conflicts
2

CVE-2026-33936

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing functions can cause unexpected exceptions to be raised from the public API functions. `ecdsa.der.remove_octet_string()` accepts truncated DER where the encoded length exceeds the ava

PUBLISHED
Vendor
tlsfuzzer
Product
python-ecdsa
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33935

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from password-based authentication by triggering failed login attempts. The application exposes three password verification endpoints, all of which are publicly accessible. All three endpoints share a single file-backed login attempt state stored in `login-attempts.json`. When any endpoint records a failed authentication att

PUBLISHED
Vendor
franklioxygen
Product
MyTube
Provider severity
HIGH
Conflicts
0

CVE-2026-33934

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of any staff member by supplying an arbitrary `user` value in the POST body. The companion write endpoint (`save-signature.php`) was already hardened against this same issue, but the read endpoint was not u

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33933

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript in an authenticated staff member's browser session by sending them a crafted URL. The attacker does not need an OpenEMR account. Version 8.0.0.3 patches the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33932

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a clinician's browser session when the document is previewed. The XSL stylesheet sanitizes attributes for all other narrative elements but not for `linkHtml`, allowing `href="javascript:..."` and event h

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-33931

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment records — including invoice/billing data (PHI) and payment card metadata — by manipulating the `recid` query parameter in `portal/portal_payment.php`. Version 8.0.0.3 patches the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33930

Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Traffic Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-3393

A security vulnerability has been detected in jarikomppa soloud up to 20200207. The impacted element is the function SoLoud::Wav::loadflac of the file src/audiosource/wav/soloud_wav.cpp of the component Audio File Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
jarikomppa
Product
soloud
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33929

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version 2.0.37 or 3.0.8 once available. Until then, they should apply the fix provided in GitHub PR 427. The ExtractEmbeddedFiles example contained a path traversal vulnerability (CWE-22) mentioned in CVE-2026-2390

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache PDFBox Examples
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3392

A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
FascinatedBox
Product
lily
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33918

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL permissions. This allows any authenticated OpenEMR user — regardless of whether they have billing privileges — to download and permanently delete electronic claim batch files containing protected health

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-33917

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the ajax_save page in the CAMOS form. Version 8.0.0.3 patches the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-33916

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflec

PUBLISHED
Vendor
handlebars-lang
Product
handlebars.js
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33915

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every other data-modifying route in the standard API uses. This allows any authenticated API user to create and modify insurance company records even if their OpenEMR user account does not have administrative ACL permissions. Version 8.0.0.3 patches the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33914

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function. The `dels` POST parameter is read via `pnVarCleanFromInput()`, which only strips HTML tags and performs no SQL escaping. The value is then interpolated directly into a raw SQL `DELETE` statement that is executed unsanitized via Doctrine DBAL's `exec

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-33913

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include href="file:///etc/passwd" parse="text"/>` to read arbitrary files from the server. Version 8.0.0.3 patches the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-33912

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser session. Version 8.0.0.3 patches the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33911

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html` Content-Type, the browser interprets injected HTML/script tags rather than treating the output as JSON. An authenticated attacker can craft a request that executes arbitrary JavaScript in a victim's session. Version 8.0.0.3 con

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33910

OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the patient selection feature. Version 8.0.0.3 contains a patch.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-3391

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
FascinatedBox
Product
lily
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33909

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without parameterization or type casting, enabling SQL injection. Version 8.0.0.3 contains a patch.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33908

A flaw was found in ImageMagick, a free and open-source software for editing and manipulating digital images. When ImageMagick processes an XML file with deeply nested structures, the `DestroyXMLTree()` function, which frees memory, is executed recursively without a depth limit. This can lead to the exhaustion of stack memory, allowing a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted XML file.

PUBLISHED
Vendor
Red Hat, ImageMagick, Red Hat
Product
Red Hat Enterprise Linux 7, ImageMagick, Red Hat Enterprise Linux 6
Provider severity
HIGH
Conflicts
2

CVE-2026-33907

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.7.0 added IE presence verification to NAS message handling.

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33906

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered copy to escalate to Admin, gaining access to user management, audit logs, debug endpoints, and operator identity configuration that the role was explicitly denied. In version 1.7.0, backup and restore

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
HIGH
Conflicts
0

CVE-2026-33905

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33904

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface can cause Ella Core to hang, resulting in a denial of service for all subscribers. Version 1.7.0 adds deferred Radio cleanup in serveConn SCTP server so that every connection exit path removes the radio. Remove the stale-entry scan from SCTP Notificati

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33903

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. Version 1.7.0 adds guards in NGAP Location Report handler.

PUBLISHED
Vendor
ellanetworks
Product
core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33902

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33901

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

PUBLISHED
Vendor
ImageMagick, Red Hat, Red Hat
Product
ImageMagick, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6
Provider severity
HIGH
Conflicts
2

CVE-2026-33900

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3390

A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
FascinatedBox
Product
lily
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33899

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33898

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authentication token. When accessed with that token, Incus creates a cookie persisting that token without needing to include it in subsequent HTTP request

PUBLISHED
Vendor
lxc
Product
incus
Provider severity
HIGH
Conflicts
0

CVE-2026-33897

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of the instance. This particular implementation of pongo2 within Incus allowed for file read/write but with the expectation that the pongo2 chroot feature would isolate all such acces

PUBLISHED
Vendor
lxc
Product
incus
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33896

A flaw was found in Forge (also known as node-forge), a JavaScript implementation of Transport Layer Security (TLS). The `pki.verifyCertificateChain()` function does not properly enforce certificate validation rules. This oversight allows an intermediate certificate that lacks specific security extensions to enable any leaf certificate to function as a Certificate Authority (CA) and sign other certificates. Consequently, node-forge could accept these unauthorized certificates as valid, potential

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, digitalbazaar, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat Data Grid 8, Red Hat build of Apicurio Registry 2, Red Hat Enterprise Linux 8, Red Hat build of Apache Camel - HawtIO 4, Red Hat Enterprise Linux 9, Red Hat Quay 3, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Red Hat Fuse 7, Red Hat Fuse 7, Logging Subsystem for Red Hat OpenShift, Red Hat Developer Hub 1.9, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Cryostat 4, Cluster Observability Operator 1.5.0, Red Hat Developer Hub 1.8, forge, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Build of Podman Desktop, Red Hat Process Automation 7
Provider severity
HIGH
Conflicts
2

CVE-2026-33895

A flaw was found in Forge (also called `node-forge`), a JavaScript library used for Transport Layer Security (TLS). The library's Ed25519 signature verification process does not correctly validate cryptographic signatures, allowing forged non-canonical signatures to be accepted. A remote attacker could exploit this signature malleability to bypass authentication and authorization logic. This vulnerability can also circumvent security checks in applications that rely on the uniqueness of cryptogr

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, digitalbazaar, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Cluster Observability Operator 1.5.0, Red Hat build of Apicurio Registry 2, Red Hat Enterprise Linux 8, Red Hat Developer Hub 1.8, Red Hat Enterprise Linux 10, Red Hat Process Automation 7, Red Hat Data Grid 8, Red Hat Quay 3, Red Hat Fuse 7, Red Hat build of Apache Camel - HawtIO 4, forge, Logging Subsystem for Red Hat OpenShift, Cryostat 4, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Red Hat Developer Hub 1.9, Logging Subsystem for Red Hat OpenShift, Red Hat Fuse 7, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
2

CVE-2026-33894

A flaw was found in Forge (also called `node-forge`), a JavaScript implementation of Transport Layer Security. A remote attacker could exploit weaknesses in the RSASSA PKCS#1 v1.5 signature verification process. By crafting malicious signatures that include extra data within the ASN structure and do not meet padding requirements, an attacker can bypass signature validation. This allows for the creation of forged signatures that appear legitimate, potentially compromising the integrity and authen

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, digitalbazaar, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Cluster Observability Operator 1.5.0, Red Hat Data Grid 8, Red Hat Quay 3.14, Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Quay 3.15, Red Hat Process Automation 7, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.9, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Quay 3.16, Red Hat Developer Hub 1.8, Logging Subsystem for Red Hat OpenShift, forge, Logging Subsystem for Red Hat OpenShift, Red Hat build of Apache Camel - HawtIO 4, Red Hat Quay 3.12, Red Hat Quay 3.1, Red Hat Fuse 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Quay 3.17, Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux 9, Red Hat build of Apicurio Registry 2, Red Hat Ansible Automation Platform 2, Red Hat Fuse 7, Cryostat 4, Red Hat Quay 3.9, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
2

CVE-2026-33893

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contains hardcoded key which is used for obfuscation stored directly into the application. This could allow an attacker to obtain these keys and misuse them to gain unauthorized access.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens
Product
Teamcenter V2412, Teamcenter V2406, Teamcenter V2312, Teamcenter V2506, Teamcenter V2512
Provider severity
HIGH
Conflicts
2

CVE-2026-33892

A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user authentication on remote connections to devices. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitatio

PUBLISHED
Vendor
Siemens, Siemens, Siemens
Product
Industrial Edge Management Pro V1, Industrial Edge Management Pro V2, Industrial Edge Management Virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-33891

A flaw was found in the node-forge library, a JavaScript implementation of Transport Layer Security. This vulnerability, inherited from the bundled jsbn library, allows a remote attacker to cause a Denial of Service (DoS). When the BigInteger.modInverse() function is called with a zero value, it enters an infinite loop, causing the process to hang indefinitely and consume 100% of the CPU resources.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, digitalbazaar, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Developer Hub 1.8, Red Hat Quay 3, Cryostat 4, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Cluster Observability Operator 1.5.0, Logging Subsystem for Red Hat OpenShift, Red Hat build of Apicurio Registry 2, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Fuse 7, Red Hat Ansible Automation Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Logging Subsystem for Red Hat OpenShift, Red Hat Developer Hub 1.9, Logging Subsystem for Red Hat OpenShift, Red Hat Build of Podman Desktop, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Process Automation 7, Red Hat build of Apache Camel - HawtIO 4, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, forge, Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
2

CVE-2026-33890

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requiring prior authentication. Any successfully authenticated passkey is automatically granted an administrator token, allowing full administrative access to the application. This enables a complete comprom

PUBLISHED
Vendor
franklioxygen
Product
MyTube
Provider severity
HIGH
Conflicts
0

CVE-2026-3389

A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
Squirrel
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33889

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color values prefixed with -- bypass TinyColor validation intended for CSS custom properties, and the launder.string() call performs only type coercion without stripping HTML metacharacters. These unsanitized values are then concatenated directly into <style> tags both in per-widget style elements rendered

PUBLISHED
Vendor
apostrophecms
Product
apostrophe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33888

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, where the method checks whether a MongoDB projection has already been set before applying the admin-configured publicApiProjection. An unauthenticated attacker can supply a project query parameter in the REST API request, which is processed by applyBuildersSafely before the permission check,

PUBLISHED
Vendor
apostrophecms
Product
apostrophe
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33887

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the authorization checks that the main entry controllers enforce, exposing entry field values and blueprint data. Users could also create entry revisions without edit permission, though this only snapshots

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
0