Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-32683

Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature.

PUBLISHED
Vendor
EZVIZ
Product
EZVIZ APP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32682

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef filters. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
NGINX Gateway Fabric
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32680

The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to execute an arbitrary code with SYSTEM privilege.

PUBLISHED
Vendor
RATOC Systems, Inc.
Product
RATOC RAID Monitoring Manager for Windows
Provider severity
HIGH
Conflicts
1

CVE-2026-3268

A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttributeController.java of the component Session Attribute Handler. Performing a manipulation results in improper access controls. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
psi-probe
Product
PSI Probe
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32679

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory, the affected installer may load that DLL and execute its code with the privilege of the user invoking the installer.

PUBLISHED
Vendor
Japan Media Systems Corporation, Japan Media Systems Corporation, Japan Media Systems Corporation, Japan Media Systems Corporation
Product
Downloader5Installer.exe, Downloader5InstallerForAdmin.exe, CanonNWCamPlugin.exe, CanonNWCamPluginForAdmin.exe
Provider severity
HIGH
Conflicts
2

CVE-2026-32678

Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.

PUBLISHED
Vendor
BUFFALO INC.
Product
BUFFALO Wi-Fi router products
Provider severity
HIGH
Conflicts
1

CVE-2026-32673

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-32669

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.

PUBLISHED
Vendor
BUFFALO INC.
Product
BUFFALO Wi-Fi router products
Provider severity
HIGH
Conflicts
1

CVE-2026-32666

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers. Spoofed packets may be processed as legitimate.

PUBLISHED
Vendor
Automated Logic
Product
WebCTRL Premium Server
Provider severity
HIGH
Conflicts
1

CVE-2026-32665

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Unbound exceed the configured 'quic-size' limit with low-cost input. Using only one connection and two

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
HIGH
Conflicts
0

CVE-2026-32663

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicio

PUBLISHED
Vendor
IGL-Technologies
Product
eParking.fi
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-32662

Development and test API endpoints are present that mirror production functionality.

PUBLISHED
Vendor
Gardyn
Product
Cloud API
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32661

Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user privilege.

PUBLISHED
Vendor
Canon Marketing Japan Inc., Canon Marketing Japan Inc.
Product
GUARDIANWALL Mail Security Cloud (SaaS version), GUARDIANWALL MailSuite (On-premises version)
Provider severity
CRITICAL
Conflicts
2

CVE-2026-3266

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

PUBLISHED
Vendor
OpenText™
Product
Filr
Provider severity
HIGH
Conflicts
0

CVE-2026-32658

Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

PUBLISHED
Vendor
Dell
Product
Automation Platform
Provider severity
HIGH
Conflicts
0

CVE-2026-32655

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

PUBLISHED
Vendor
Dell
Product
Alienware Command Center (AWCC)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32652

Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded (either manually or automatically) to version 1.18.3 or later are not impacted, even if they were originally installed on an earlier version.

PUBLISHED
Vendor
Dell
Product
AIOps
Provider severity
HIGH
Conflicts
0

CVE-2026-32650

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling unauthorized database access.

PUBLISHED
Vendor
Anviz
Product
Anviz CrossChex Standard
Provider severity
HIGH
Conflicts
0

CVE-2026-3265

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Security API. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specifie

PUBLISHED
Vendor
go2ismail
Product
Free-CRM
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32649

A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.

PUBLISHED
Vendor
Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight
Product
TS2966-X12TPE, MS-CQxx68-xxxG1, TS4466-X4RVPE, MS-Cxx61-xxxPE, MS-Cxx66-xxxxGOPC, TS8266-RFIVPG1, MS-Cxx74-PA, MS-Cxx72-xxxPE, TS4466-X4RIPG1, MS-Cxx83-xPD, TS2841-X36TPC, MS-C5366-X12LVPC, MS-Nxxxx-xxE, TS5366-X12VPE, MS-CQxx31-xxxG1, TS4466-X4RIWG1, TS2866-X4TGPC, MS-Cxx66-RFIPKG1, MS-Cxx62-xxxPE, TS5366-X12PE, MS-Cxx66-FIPKG1, TS4441-X36RPE, TS5510-GH, TS8266-X4WE, MS-Cxx52-xxxPE, TS2866-X4TVPC, MS-C8477-HPG1, MS-C2966-X12RLVPC, TS2866-X4TPC, MS-C2972-RFLPC, MS-Cxx65-PE, MS-Cxx75-xxPD, MS-Cxx71-xxxPE, MS-CQxx72-xxxG1, MS-C5366-X12LPC, MS-Cxx41-xxxPE, MS-Cxx76-PE, MS-Nxxxx-NxE, MS-Cxx66-xxxPE, PMC8266-FPE, TS2961-X12TPC, MS-Cxx67-xxxPE, MS-Cxx63-PD, TS2841-X36TPC/W, MS-Cxx66-xxxG1, MS-Cxx62-xxxG1, TS8266-X4PE, MS-C5321-FPE, TS8266-X4RIWG1, MS-C2966-RFLWPC, TS4466-RFIVPG1, MS-C5361-X12LPC, MS-Nxxxx-xxH, MS-C2964-RFLPC, TS4441-X36RE, MS-Nxxxx-xxC, MS-Cxx64-xPD, MS-Nxxxx-xxT, MS-C8477-PC, MS-Nxxxx-xxG, TS2867-X5TPC, MS-Cxx73-xPD, TS5366-X12RIPG1, TS2966-X12TVPE, TS8266-X4RIPG1, MS-C2966-X12RLPC, MS-Cxx72-FIPKG1, TS8266-FPC/P, MS-Cxx66-xxxGPE, TS5510-GVH, SP111, PM3322-E, TS8266-X4RIVPG1, MS-Cxx72-xxxG1, SC211, TS4466-X4RWE, TS8266-X4VPE, MS-Cxx72-RFIPKG1, TS4466-X4RIVPG1, PMC8266-FGPE, TS4466-X4RPE, TS5511-GVH
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-32648

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device.

PUBLISHED
Vendor
Anviz, Anviz
Product
Anviz CX7 Firmware, Anviz CX2 Lite Firmware
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32647

A flaw was found in NGINX's ngx_http_mp4_module. This Out-of-Bounds Read/Write vulnerability occurs due to improper handling of specially crafted MP4 files. A local authenticated attacker, by supplying a malicious MP4 file, can trigger a buffer over-read or overwrite in worker memory. This can lead to process termination, potentially causing a denial-of-service or, under certain conditions, achieving code execution.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, F5, F5, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Lightspeed proxy 1, NGINX Open Source, NGINX Plus, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Update Infrastructure 5, Red Hat Update Infrastructure 5, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
3

CVE-2026-32646

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

PUBLISHED
Vendor
Gardyn
Product
Cloud API
Provider severity
HIGH
Conflicts
1

CVE-2026-32644

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

PUBLISHED
Vendor
Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight
Product
MS-Cxx41-xxxPE, MS-Cxx66-xxxG1, MS-Cxx64-xPD, TS4466-X4RIWG1, MS-Cxx72-xxxG1, MS-C5361-X12LPC, MS-Nxxxx-xxE, MS-C2966-X12RLVPC, TS2866-X4TPC, MS-Cxx62-xxxPE, MS-Cxx75-xxPD, MS-C2972-RFLPC, MS-Nxxxx-xxH, MS-Cxx66-FIPKG1, TS5510-GH, MS-Cxx62-xxxG1, TS8266-X4VPE, MS-C8477-PC, TS8266-X4RIPG1, TS2966-X12TPE, MS-Nxxxx-xxC, MS-Nxxxx-xxG, MS-C5366-X12LVPC, TS8266-X4RIVPG1, MS-CQxx68-xxxG1, MS-Cxx66-xxxGPE, TS4466-RFIVPG1, TS5510-GVH, MS-Cxx67-xxxPE, TS2841-X36TPC, MS-Cxx72-xxxPE, TS5511-GVH, TS4466-X4RIPG1, MS-Cxx74-PA, TS4466-X4RPE, TS4441-X36RE, PM3322-E, SP111, MS-Cxx66-xxxPE, TS2841-X36TPC/W, MS-C2966-X12RLPC, MS-Cxx66-xxxxGOPC, TS8266-X4PE, TS8266-X4RIWG1, MS-C5321-FPE, TS4466-X4RVPE, TS4466-X4RWE, TS2866-X4TVPC, PMC8266-FGPE, MS-Nxxxx-xxT, MS-Cxx73-xPD, MS-Cxx72-FIPKG1, MS-Cxx63-PD, TS8266-RFIVPG1, MS-C2964-RFLPC, PMC8266-FPE, SC211, MS-CQxx31-xxxG1, MS-CQxx72-xxxG1, TS8266-X4WE, MS-Nxxxx-NxE, TS5366-X12RIPG1, TS8266-FPC/P, MS-Cxx66-RFIPKG1, MS-Cxx65-PE, TS5366-X12PE, TS2866-X4TGPC, TS2966-X12TVPE, MS-Cxx83-xPD, TS4466-X4RIVPG1, MS-Cxx71-xxxPE, MS-Cxx52-xxxPE, MS-C5366-X12LPC, TS2961-X12TPC, MS-C2966-RFLWPC, MS-Cxx76-PE, TS5366-X12VPE, MS-Cxx61-xxxPE, MS-C8477-HPG1, TS4441-X36RPE, TS2867-X5TPC, MS-Cxx72-RFIPKG1
Provider severity
CRITICAL
Conflicts
2

CVE-2026-32643

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
BIG-IP, BIG-IQ
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-32642

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation
Product
Apache ActiveMQ Artemis, Apache Artemis
Provider severity
LOW
Conflicts
1

CVE-2026-32640

SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects you've passed in as names to SimpleEval have modules or other disallowed / dangerous objects available as attrs. Additionally, dangerous functions or modules could be accessed by passing them as callbacks to other safe functions to call. The latest version 1.0.5 has this issue fixed. Thi

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, danthedeckie, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, simpleeval, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
3

CVE-2026-3264

A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administrative Interface. Executing a manipulation can lead to execution after redirect. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailabl

PUBLISHED
Vendor
go2ismail
Product
Free-CRM
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32638

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `rank` query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request `rank=owner` and receive owner account records, including IDs, usernames, display names, and email addresses, even though the adjacent `getUser` endpoint correctly blocks admins from vie

PUBLISHED
Vendor
withstudiocms
Product
studiocms
Provider severity
LOW
Conflicts
0

CVE-2026-32636

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32635

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulnerability has been identified in the Angular runtime and compiler. It occurs when the application uses a security-sensitive attribute (for example href on an anchor tag) together with Angular's ability to internationalize attributes. Enabling internationalization for the sensitive

PUBLISHED
Vendor
@angular, @angular
Product
compiler, core
Provider severity
HIGH
Conflicts
1

CVE-2026-32634

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of the discovered IP. When a dynamic server reports itself as protected, Glances also uses that same untrusted name as the lookup key for saved passwords and the global `[passwords] default` credential.

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
1

CVE-2026-32633

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList.get_servers_list()`. Those objects are mutated in-place during background polling and can contain a `uri` field with embedded HTTP Basic credentials for downstream Glances servers, using the reusable pbkdf2-derived Glances authentication secret. If the front Glances Browser/API instance is started w

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
CRITICAL
Conflicts
1

CVE-2026-32632

Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the MCP endpoint, but prior to version 4.5.2, the main REST/WebUI FastAPI application still accepts arbitrary `Host` headers and does not apply `TrustedHostMiddleware` or an equivalent host allowlist. As a result, the REST API, WebUI, and token endpoint remain reachable through attacker-controlled domains in classic DNS rebinding scenarios. Once the victim browser has rebound the

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32631

Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This i

PUBLISHED
Vendor
git-for-windows
Product
git
Provider severity
HIGH
Conflicts
0

CVE-2026-32630

file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for stream-based detection, but not for known-size inputs. As a result, a small compressed ZIP can cause file-type to inflate and process a much larger payload while probing ZIP-based formats such as OOXML. Thi

PUBLISHED
Vendor
sindresorhus
Product
file-type
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3263

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
go2ismail
Product
Asp.Net-Core-Inventory-Order-Management-System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32629

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example "<script>alert(1)</script>"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts this email as valid. The email is stored in the database without HTML sanitization and later rendered in the admin FAQ editor template using Twig's |raw filter, which bypasses auto-esc

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32628

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any user who can invoke the agent to execute arbitrary SQL commands on connected databases. The getTableSchemaSql() method in all three database connectors (MySQL, PostgreSQL, MSSQL) constructs SQL queries using direct string concatenation of the table_name parameter without sanitiz

PUBLISHED
Vendor
Mintplex-Labs
Product
anything-llm
Provider severity
HIGH
Conflicts
0

CVE-2026-32627

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostname verification silently disabled on the new connection. The client will accept any certificate presented by the redirect target — expired, self-signed, or forged — without raising an error or notifying the application. A network attacker in a positio

PUBLISHED
Vendor
yhirose
Product
cpp-httplib
Provider severity
HIGH
Conflicts
0

CVE-2026-32626

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS due to insecure Electron configuration. This works with default settings and requires no user interaction beyond normal chat usage. The custom markdown-it image renderer in frontend/src/utils/chat/markd

PUBLISHED
Vendor
Mintplex-Labs
Product
anything-llm
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32625

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-controlled domain containing environment variable references, causing the LibreChat server to connect

PUBLISHED
Vendor
danny-avila
Product
LibreChat
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32624

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated remote attacker can send a crafted, excessively long username and domain name to overflow the internal buffer. This can corrupt adjacent memory regions, potentially leading to a Denial of Service (DoS) or unexpected behavior. The domain_name_separator directive is commented

PUBLISHED
Vendor
neutrinolabs
Product
xrdp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32623

xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from xrdp to another server, the module fails to properly validate the size of reassembled fragmented virtual channel data against its allocated memory buffer. A malicious downstream RDP server (or an attacker capable of performing a Man-in-the-Middle attack) could exploit this flaw to cause memory corruption, potentially leading to a

PUBLISHED
Vendor
neutrinolabs
Product
xrdp
Provider severity
HIGH
Conflicts
0

CVE-2026-32622

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, unsanitized storage of terminology descriptions containing dangerous payloads, and a lack of semantic fencing when injecting terminology into the LLM's system prompt. Together, these flaws allow an atta

PUBLISHED
Vendor
dataease
Product
SQLBot
Provider severity
HIGH
Conflicts
1

CVE-2026-32621

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were

PUBLISHED
Vendor
@apollo, @apollo, @apollo
Product
query-planner, gateway, federation-internals
Provider severity
CRITICAL
Conflicts
1

CVE-2026-32620

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only metadata about who read the post and when. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3262

A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
go2ismail
Product
Asp.Net-Core-Inventory-Order-Management-System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-32619

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, users who lost access to a topic (e.g., removed from a private category group) could still interact with polls in that topic, including voting and toggling poll status. No content was exposed, but users could modify poll state in topics they should no longer have access to. This issue has been patched in versions 2026.1.3,

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32618

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0