Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-33001

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.

PUBLISHED
Vendor
Jenkins Project, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Jenkins, OpenShift Developer Tools and Services 4.13, Red Hat Developer Hub, OpenShift Developer Tools and Services 4.16, OpenShift Developer Tools and Services 4.17, OpenShift Developer Tools and Services 4.15, OpenShift Developer Tools and Services 4.18, OpenShift Developer Tools and Services 4.19, OpenShift Developer Tools and Services 4.21, OpenShift Developer Tools and Services 4.14, OpenShift Developer Tools and Services 4.12, OpenShift Developer Tools and Services 4.2
Provider severity
HIGH
Conflicts
3

CVE-2026-33000

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi OS Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3300

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticate

PUBLISHED
Vendor
WPEverest
Product
Everest Forms Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32999

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.

PUBLISHED
Vendor
WebPros
Product
Comet Backup
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32998

This vulnerability in Veeam Service Provider Console allows for remote code execution.

PUBLISHED
Vendor
Veeam
Product
Service Provider Console
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32997

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

PUBLISHED
Vendor
Veeam
Product
Backup and Replication
Provider severity
HIGH
Conflicts
0

CVE-2026-32996

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

PUBLISHED
Vendor
Veeam
Product
Backup and Replication
Provider severity
HIGH
Conflicts
0

CVE-2026-32995

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying room membership. Any authenticated DDP user can read the content of any message by ID from any room (private channels, DMs, E2EE rooms) by calling this method.

PUBLISHED
Vendor
Rocket.Chat
Product
Rocket.Chat
Provider severity
HIGH
Conflicts
0

CVE-2026-32994

The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8, and <7.10.12 allows any authenticated user to retrieve the full content of any message from any room (private groups, direct messages, channels) by simply providing the target message ID. The endpoint fetches the message via Messages.findOneById(messageId) with no room access check (canAccessRoomIdAsync is never called), returning the complete IMessage object including message

PUBLISHED
Vendor
Rocket.Chat
Product
Rocket.Chat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32993

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

PUBLISHED
Vendor
WebPros, WebPros
Product
cPanel, WP Squared
Provider severity
HIGH
Conflicts
1

CVE-2026-32992

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

PUBLISHED
Vendor
WebPros, WebPros
Product
WP Squared, cPanel
Provider severity
HIGH
Conflicts
1

CVE-2026-32991

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

PUBLISHED
Vendor
WebPros, WebPros, WebPros
Product
cPanel (CloudLinux 6, CentOS 6), WP Squared, cPanel
Provider severity
HIGH
Conflicts
1

CVE-2026-32990

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Tomcat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3299

The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode in all versions up to, and including, 1.7.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
futtta
Product
WP YouTube Lyte
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32989

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint handling file uploads. Attackers can exploit this to upload executable files to web-accessible locations, leading to arbitrary code execution in the context of the web server.

PUBLISHED
Vendor
Precurio
Product
Precurio Intranet Portal
Provider severity
HIGH
Conflicts
2

CVE-2026-32988

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32987

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
CRITICAL
Conflicts
1

CVE-2026-32986

Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters such as category that are reflected into Atom fields like and , which execute as JavaScript when feed readers or CMS aggregators consume the feed and insert content into the DOM using unsafe methods.

PUBLISHED
Vendor
Textpattern
Product
Textpattern CMS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32985

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing malicious PHP payloads. Attackers can bypass authentication checks in the import.php file to upload a template archive with PHP code in the media directory, which gets extracted to a web-accessible path where the malicious PHP can be directly accessed

PUBLISHED
Vendor
Xerte
Product
Xerte Online Toolkits
Provider severity
CRITICAL
Conflicts
2

CVE-2026-32984

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low impact on the availability of the authentication daemon.

PUBLISHED
Vendor
Wazuh
Product
Wazuh
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-32983

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.

PUBLISHED
Vendor
Wazuh
Product
wazuh-manager
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32982

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32981

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, ray-project, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Ray, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server 3.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server 3.2, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux AI (RHEL AI) 3
Provider severity
HIGH
Conflicts
3

CVE-2026-32980

OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing unauthenticated attackers to exhaust server resources. Attackers can send POST requests to the webhook endpoint to force memory consumption, socket time, and JSON parsing work before authentication validation occurs.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-3298

The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

PUBLISHED
Vendor
Python Software Foundation
Product
CPython
Provider severity
HIGH
Conflicts
0

CVE-2026-32979

OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local code by modifying scripts between approval and execution when exact file binding cannot occur. Remote attackers can change approved local scripts before execution to achieve unintended code execution as the OpenClaw runtime user.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32978

OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain script runners like tsx and jiti. Attackers can obtain approval for benign script commands, rewrite referenced scripts on disk, and execute modified code under the approved run context.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-32977

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32976

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32975

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages from unintended groups to the agent.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-32974

OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without encryptKey, allowing acceptance of forged events. Unauthenticated network attackers can inject forged Feishu events and trigger downstream tool execution by reaching the webhook endpoint.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32973

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard matching across path segments to execute commands or paths not intended by operators.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-32972

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only operator.write permission to access admin-only browser profile management routes through browser.request. Attackers can create or modify browser profiles and persist attacker-controlled remote CDP endpoints to disk without holding operator.admin privileges.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32971

OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
HIGH
Conflicts
1

CVE-2026-32970

OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit misconfigured local auth references to cause CLI and helper paths to select incorrect credential sources, potentially bypassing intended local authentication boundaries.

PUBLISHED
Vendor
OpenClaw
Product
OpenClaw
Provider severity
LOW
Conflicts
1

CVE-2026-3297

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
softaculous
Product
Page Builder: Pagelayer – Drag and Drop website builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32969

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
MB connect line, Helmholz, MB connect line, Helmholz
Product
MB connect line mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, myREX24V2
Provider severity
HIGH
Conflicts
1

CVE-2026-32968

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

PUBLISHED
Vendor
Helmholz, MB connect line, MB connect line, Helmholz
Product
myREX24V2.virtual, mymbCONNECT24, MB connect line mbCONNECT24, myREX24V2
Provider severity
CRITICAL
Conflicts
1

CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Provider severity
HIGH
Conflicts
0

CVE-2026-32965

Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
AMC Manager, SD-330AC
Provider severity
HIGH
Conflicts
2

CVE-2026-32964

SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
AMC Manager, SD-330AC
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32963

SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
SD-330AC, AMC Manager
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32962

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
AMC Manager, SD-330AC
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32961

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
SD-330AC, AMC Manager
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32960

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
SD-330AC, AMC Manager
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-3296

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The pay

PUBLISHED
Vendor
wpeverest
Product
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32959

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
SD-330AC, AMC Manager
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-32958

SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
AMC Manager, SD-330AC
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32957

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication.

PUBLISHED
Vendor
silex technology, Inc., silex technology, Inc.
Product
AMC Manager, SD-330AC
Provider severity
MEDIUM
Conflicts
2