Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-33886

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33885

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows. This has been fixed in 5.73.16 and 6.7.2.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33884

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16 and 6.7.2.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33883

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser. This has been fixed in 5.73.16 and 6.7.2.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33882

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, an authenticated control panel user could retrieve sensitive user data including email addresses, encrypted passkey data, and encrypted two-factor authentication codes. This has been fixed in 5.73.16 and 6.7.2.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33881

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals without escaping single quotes in the NativeTS executor. A workspace admin who sets a custom environment variable with a value containing `'` can inject arbitrary JavaScript that executes inside every NativeTS script in that workspace. This is a code injection bug in `worker.rs`, not related to the sandbo

PUBLISHED
Vendor
windmill-labs
Product
windmill
Provider severity
HIGH
Conflicts
0

CVE-2026-3388

A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
Squirrel
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33879

Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks. FLIP users are external to the organization, increasing credential reuse risk. As of time of publication, it is unclear if a patch is available.

PUBLISHED
Vendor
londonaicentre
Product
FLIP
Provider severity
LOW
Conflicts
0

CVE-2026-33877

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows unauthenticated username and email enumeration. When a user is not found, the handler returns after a fixed 2-second artificial delay, but when a valid user is found, it performs a MongoDB update and SMTP email send with no equivalent delay normalization, producing measurabl

PUBLISHED
Vendor
apostrophecms
Product
apostrophe
Provider severity
LOW
Conflicts
0

CVE-2026-33875

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

PUBLISHED
Vendor
gematik
Product
app-Authenticator
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33874

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

PUBLISHED
Vendor
gematik
Product
app-Authenticator
Provider severity
HIGH
Conflicts
0

CVE-2026-33873

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to validate generated component code, the implementation reaches dynamic execution sinks and instantiates the generated class server-side. In deployments where an attacker can access the Agentic Assistant feature and influence the model output, this can

PUBLISHED
Vendor
langflow-ai
Product
langflow
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33872

elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerability. Because the worker does not verify which request a response belongs to, it may return the next available data in the buffer to an unrelated caller. In high-throughput environments where the library

PUBLISHED
Vendor
revelrylabs
Product
elixir-nodejs
Provider severity
HIGH
Conflicts
0

CVE-2026-33871

A flaw was found in Netty. A remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of CONTINUATION frames. The server's lack of a limit on these frames, coupled with a bypass of size-based mitigations using zero-byte frames, allows an attacker to consume excessive CPU resources. This can render the server unresponsive with minimal bandwidth usage.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Serverless, Logging Subsystem for Red Hat OpenShift, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Serverless, Red Hat build of Debezium 2, Cryostat 4, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform 8, Red Hat OpenShift AI (RHOAI), streams for Apache Kafka 3, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel - HawtIO 4, OpenShift Serverless, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7, Red Hat Satellite 6, Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Streams for Apache Kafka 3.2.0, Cryostat 4 on RHEL 9, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux AI (RHEL AI) 3, Cryostat 4 on RHEL 9, Red Hat AMQ Broker 7.13.5, Red Hat AMQ Clients, netty, Red Hat Data Grid 8.6.1, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, streams for Apache Kafka 3, Red Hat OpenShift AI 2.25, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat build of Quarkus 3.27.3, Red Hat Fuse 7, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, OpenShift Serverless, Streams for Apache Kafka 2.9.4, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Serverless, Red Hat build of Quarkus, Red Hat Process Automation 7, Red Hat AMQ Broker 7.14.0, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of OptaPlanner 8, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Serverless, Red Hat OpenShift Dev Spaces 3.27, Cryostat 4 on RHEL 9, Red Hat build of OptaPlanner 8, Red Hat build of Debezium 2, Red Hat AMQ Broker 7.12.7, Red Hat OpenShift AI (RHOAI), Red Hat build of Apicurio Registry 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat build of Quarkus 3.20.6, Red Hat OpenShift Dev Spaces 3.27, Red Hat JBoss Enterprise Application Platform 7, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, OpenShift Serverless, Red Hat Single Sign-On 7, Red Hat build of Apicurio Registry 2, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift AI (RHOAI), Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Satellite 6, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform 8.1, OpenShift Serverless, Red Hat build of Debezium 3, Red Hat build of Apicurio Registry 2
Provider severity
HIGH
Conflicts
3

CVE-2026-33870

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/1.1 chunked transfer encoding extension values. Due to incorrect parsing of quoted strings, this flaw enables request smuggling attacks, potentially allowing an attacker to bypass security controls or access unauthorized information.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, netty, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
streams for Apache Kafka 3, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Red Hat build of Apache Camel - HawtIO 4, Red Hat Process Automation 7, Red Hat build of OptaPlanner 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Data Grid 8.6.1, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform 8.1, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Dev Spaces 3.27, Cryostat 4 on RHEL 9, OpenShift Serverless, Red Hat AMQ Broker 7.13.5, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Logging Subsystem for Red Hat OpenShift, Cryostat 4 on RHEL 9, Streams for Apache Kafka 2.9.4, Red Hat build of Quarkus 3.27.3, Red Hat OpenShift AI 2.25, netty, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, OpenShift Serverless, Logging Subsystem for Red Hat OpenShift, OpenShift Serverless, Streams for Apache Kafka 3.2.0, OpenShift Serverless, Red Hat Fuse 7, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat AMQ Broker 7.12.7, Red Hat OpenShift Dev Spaces 3.27, Logging Subsystem for Red Hat OpenShift, OpenShift Serverless, Cryostat 4 on RHEL 9, Red Hat build of Quarkus 3.20.6, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat build of Apicurio Registry 3, Red Hat Single Sign-On 7, Red Hat AMQ Clients, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.27, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Satellite 6, OpenShift Serverless, Red Hat AMQ Broker 7.14.0, Red Hat build of Apache Camel 4 for Quarkus 3, OpenShift Serverless, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Serverless, Red Hat JBoss Enterprise Application Platform 7, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat build of Apicurio Registry 2, Red Hat Satellite 6
Provider severity
HIGH
Conflicts
2

CVE-2026-3387

A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
wren-lang
Product
wren
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33869

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnerability has been patched in Mastodon 4.5.8 and 4.4.15. Mastodon 4.3 and earlier are not affected because they do not support quotes.

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33868

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can craft a specially encoded URL that causes the application to redirect users to an arbitrary external domain, enabling phishing attacks and potential OAuth credential theft. The issue occurs because URL-encoded slashes (`%2

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33867

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the database (via SQL injection, a database backup, or misconfigured access controls), they obtain all video passwords in cleartext. Commit f2d68d2adbf73588ea61be2b781d93120a819e36 contains a patch.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33866

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. This issue affects MLflow version through 3.10.1

PUBLISHED
Vendor
Mlflow
Product
Mlflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33865

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows actions such as session hijacking or performing operations on behalf of the victim. This issue affects MLflow version through 3.10.1

PUBLISHED
Vendor
Mlflow
Product
Mlflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33862

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter user-supplied data. This could allow an attacker to inject malicious code that can be executed by other users when they visit the affected page.

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens
Product
Teamcenter V2506, Teamcenter V2406, Teamcenter V2512, Teamcenter V2412, Teamcenter V2312
Provider severity
HIGH
Conflicts
2

CVE-2026-3386

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
wren-lang
Product
wren
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33858

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
HIGH
Conflicts
0

CVE-2026-33857

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33856

Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
HIGH
Conflicts
0

CVE-2026-33855

Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33854

Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
HIGH
Conflicts
0

CVE-2026-33853

NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33852

Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

PUBLISHED
Vendor
MolotovCherry
Product
Android-ImageMagick7
Provider severity
HIGH
Conflicts
0

CVE-2026-33851

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in joncampbell123 doslib.This issue affects doslib: before doslib-20250729.

PUBLISHED
Vendor
joncampbell123
Product
doslib
Provider severity
HIGH
Conflicts
0

CVE-2026-33850

Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.

PUBLISHED
Vendor
WujekFoliarz
Product
DualSenseY-v2
Provider severity
HIGH
Conflicts
0

CVE-2026-3385

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
wren-lang
Product
wren
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33849

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.

PUBLISHED
Vendor
linkingvision
Product
rapidvms
Provider severity
HIGH
Conflicts
0

CVE-2026-33848

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.

PUBLISHED
Vendor
linkingvision
Product
rapidvms
Provider severity
HIGH
Conflicts
0

CVE-2026-33847

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in linkingvision rapidvms.This issue affects rapidvms: before PR#96.

PUBLISHED
Vendor
linkingvision
Product
rapidvms
Provider severity
HIGH
Conflicts
0

CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Discovery 2, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Hardened Images, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat AI Inference Server 3.2, Red Hat Hardened Images, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Discovery 2, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat AI Inference Server 3.2, Red Hat Discovery 2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Discovery 2, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
1

CVE-2026-33845

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat AI Inference Server 3.2, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Discovery 2, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Discovery 2, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Update Infrastructure 5, Red Hat Hardened Images, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Hardened Images, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Discovery 2, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Update Infrastructure 5, Red Hat Discovery 2, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4, Red Hat Update Infrastructure 5, Red Hat AI Inference Server 3.2, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Update Infrastructure 5
Provider severity
HIGH
Conflicts
1

CVE-2026-33844

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Managed Instance for Apache Cassandra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33843

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Entra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33842

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 1607, Windows 10 Version 1809, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33841

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 11 Version 24H2, Windows 11 version 23H2, Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-33840

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 25H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-3384

A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_Node_Impl::eval/chaiscript::eval::Function_Push_Pop of the file include/chaiscript/language/chaiscript_eval.hpp. The manipulation leads to uncontrolled recursion. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
ChaiScript
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-33839

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 11 version 23H2, Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-33838

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows Server 2019, Windows 11 Version 25H2, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012, Windows 11 version 23H2, Windows Server 2025 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 R2, Windows 11 Version 24H2
Provider severity
HIGH
Conflicts
1

CVE-2026-33837

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1607, Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2012, Windows 11 version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-33835

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-33834

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows Server 2025, Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2016, Windows Server 2012, Windows 11 version 23H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-33833

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Machine Learning
Provider severity
HIGH
Conflicts
0