Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-32617

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, On default installations where no password or API key has been configured, all HTTP endpoints and the agent WebSocket lack authentication, and the server's CORS policy accepts any origin. AnythingLLM Desktop binds to 127.0.0.1 (loopback) by default. Modern browsers (Chrome, Edge, Firefox) implement Private Network Access (PNA). This explicitly blocks

PUBLISHED
Vendor
Mintplex-Labs
Product
anything-llm
Provider severity
HIGH
Conflicts
1

CVE-2026-32616

Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in the HTTP request, causing the verification link sent to the user's email to point to an attacker-controlled domain. This can lead to account takeover by stealing the email verification token. This vulnerability is fixed in 1.0.201.

PUBLISHED
Vendor
kasuganosoras
Product
Pigeon
Provider severity
HIGH
Conflicts
0

CVE-2026-32615

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside private categories they did not have read access to. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32614

Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/SM3/SM4/SM9/ZUC. Prior to 0.41.1, the current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root cause is that, during decryption, the elliptic-curve point C1 in the ciphertext is only deserialized and checked to be on the curve, but the implementation does not explicitly reject the point at infinity

PUBLISHED
Vendor
emmansun
Product
gmsm
Provider severity
HIGH
Conflicts
0

CVE-2026-32613

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enabled a user to use arbitrary java classes which allow deep access to the system. This enabled the ability to invo

PUBLISHED
Vendor
spinnaker
Product
spinnaker
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32612

Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account. This has been fixed in 6.6.2.

PUBLISHED
Vendor
statamic
Product
cms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32611

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export module by converting all SQL operations to use parameterized queries and `psycopg.sql` composable objects. However, the DuckDB export module (`glances/exports/glances_duckdb/__init__.py`) was not included in this fix and contains the same class of vulnerability: table names and column names derived from monitoring statistics are directly interpolat

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
0

CVE-2026-32610

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with `allow_credentials=True`. When both of these options are enabled together, Starlette's `CORSMiddleware` reflects the requesting `Origin` header value in the `Access-Control-Allow-Origin` response header instead of returning the literal `*` wildcard. This effectively grants any website the abi

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
0

CVE-2026-3261

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
School Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-32609

Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenticated configuration secrets exposure on the `/api/v4/config` endpoints by introducing `as_dict_secure()` redaction. However, the `/api/v4/args` and `/api/v4/args/{item}` endpoints were not addressed by this fix. These endpoints return the complete command-line arguments namespace via `vars(self.args)`, which includes the password hash (salt + pbkdf2_hmac), SNMP community string

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
0

CVE-2026-32608

Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support Mustache template variables (e.g., `{{name}}`, `{{key}}`) that are populated with runtime monitoring data. The `secure_popen()` function, which executes these commands, implements its own pipe, redirect, and chain operator handling by splitting the command string before passing eac

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
0

CVE-2026-32607

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escaping in several assignment-related UI paths. This allows users with assign permission to inject arbitrary HTML/JavaScript that executes in the

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
LOW
Conflicts
0

CVE-2026-32606

IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any interaction by the system's owner or any tampering of Secure Boot state or kernel (UKI) boot image. That's because in this configuration, the LUKS key is made available by the TPM so long as the system has the expected PCR7

PUBLISHED
Vendor
lxc
Product
incus-os
Provider severity
HIGH
Conflicts
0

CVE-2026-32605

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could crash a validator by publishing a signed tendermint proposal message where signer == validators.num_validators(). ProposalSender::send uses > instead of >= for the signer bounds check, so the equality case passes and reaches validators.get_validator_by_slot_band(signer), which panics with an out-of-bounds index before an

PUBLISHED
Vendor
nimiq
Product
core-rs-albatross
Provider severity
HIGH
Conflicts
1

CVE-2026-32604

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily. Versions 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2 contain a patch. As a workaround, disable the gitrepo artifact types.

PUBLISHED
Vendor
spinnaker
Product
spinnaker
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32603

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \Device\SandboxieDriverApi driver, triggering an immediate kernel crash (BSOD). The vulnerability affects the Standard Sandbox configuration both with and without dropped administrator privileges, but does not affect the Se

PUBLISHED
Vendor
sandboxie-plus
Product
Sandboxie
Provider severity
HIGH
Conflicts
0

CVE-2026-32602

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operations without a transaction: CHECK, CREATE, and DELETE. Because these operations are not atomic, concurrent requests can all pass the validation step (1) before any of them reaches the deletion step (3). T

PUBLISHED
Vendor
homarr-labs
Product
homarr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32600

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 2.3.1 and 1.13.9.

PUBLISHED
Vendor
simplesamlphp
Product
xml-security
Provider severity
HIGH
Conflicts
0

CVE-2026-32598

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to application logs (log aggregation, Docker logs, Kubernetes pod logs) can intercept reset tokens and perform account takeover on any user. This vulnerability is fixed in 10.0.24.

PUBLISHED
Vendor
OneUptime
Product
oneuptime
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32597

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, jpadilla, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server 3.3, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat Quay 3.9, Red Hat OpenShift AI 2.25, Red Hat Quay 3.15, Red Hat Ansible Automation Platform 2.5 for RHEL 9, pyjwt, OpenShift Lightspeed, Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI 3.3, Red Hat Trusted Artifact Signer 1.4, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.12, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Enterprise Linux AI 3.3, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat Satellite 6.18, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux AI 3.3, Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 2.25, OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.1, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Quay 3.16, Red Hat Ansible Automation Platform 2.6, Red Hat Trusted Artifact Signer, Red Hat Enterprise Linux 8, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2
Provider severity
HIGH
Conflicts
2

CVE-2026-32596

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (passwords, API keys, tokens) to any network client. Version 4.5.2 fixes the issue.

PUBLISHED
Vendor
nicolargo
Product
glances
Provider severity
HIGH
Conflicts
0

CVE-2026-32595

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middleware performs a bcrypt password comparison taking ~166ms. When the username does not exist, the response returns immediately in ~0.6ms. This ~298x timing difference is observable over the network and allows an unauthenticated attacker to reliably dis

PUBLISHED
Vendor
traefik
Product
traefik
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32594

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection control, and query complexity limits. An attacker can connect to the WebSocket endpoint and execute GraphQL operations without providing a valid application or API key, access the GraphQL schema via introspe

PUBLISHED
Vendor
parse-community
Product
parse-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32591

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Quay 3.12, Red Hat Quay 3.16, Red Hat Quay 3.15, Red Hat Quay 3.18, Red Hat Quay 3.9, mirror registry for Red Hat OpenShift, Red Hat Quay 3.15, mirror registry for Red Hat OpenShift 2, Red Hat Quay 3.1, Red Hat Quay 3.12, mirror registry for Red Hat OpenShift 2, Red Hat Quay 3.17, Red Hat Quay 3.9, Red Hat Quay 3.1, Red Hat Quay 3.16, mirror registry for Red Hat OpenShift, Red Hat Quay 3.17, Red Hat Quay 3.18, Red Hat Quay 3.12
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Quay 3.1, Red Hat Quay 3.17, mirror registry for Red Hat OpenShift, Red Hat Quay 3.9, Red Hat Quay 3.15, Red Hat Quay 3.17, Red Hat Quay 3.12, mirror registry for Red Hat OpenShift 2.0, Red Hat Quay 3.18, Red Hat Quay 3.14, Red Hat Quay 3.16
Provider severity
HIGH
Conflicts
1

CVE-2026-3259

A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism in Google BigQuery on Google Cloud Platform allows an authenticated user to potentially disclose sensitive data using a crafted materialized view that triggers a runtime error during the refresh process. This vulnerability was patched on 29 January 2026, and no customer action is needed.

PUBLISHED
Vendor
Google Cloud
Product
BigQuery
Provider severity
HIGH
Conflicts
0

CVE-2026-32589

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Quay 3.12, Red Hat Quay 3.16, Red Hat Quay 3.15, Red Hat Quay 3.12, Red Hat Quay 3.1, mirror registry for Red Hat OpenShift 2.0, Red Hat Quay 3.17, Red Hat Quay 3.9, Red Hat Quay 3.17, Red Hat Quay 3.14, Red Hat Quay 3.14, Red Hat Quay 3.16, mirror registry for Red Hat OpenShift 2.0, Red Hat Quay 3.15, Red Hat Quay 3.1, mirror registry for Red Hat OpenShift, Red Hat Quay 3.9, mirror registry for Red Hat OpenShift
Provider severity
HIGH
Conflicts
1

CVE-2026-32588

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Cassandra
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32587

Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.

PUBLISHED
Vendor
Saad Iqbal
Product
WP EasyPay
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32586

Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booster for WooCommerce: from n/a through < 7.11.3.

PUBLISHED
Vendor
Pluggabl
Product
Booster for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32583

Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modern Events Calendar: from n/a through 7.29.0.

PUBLISHED
Vendor
Webnus Inc.
Product
Modern Events Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32573

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.7.

PUBLISHED
Vendor
Nelio Software
Product
Nelio AB Testing
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3257

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.

PUBLISHED
Vendor
TOKUHIROM
Product
UnQLite
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32567

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in icopydoc YML for Yandex Market yml-for-yandex-market allows Path Traversal.This issue affects YML for Yandex Market: from n/a through < 5.3.0.

PUBLISHED
Vendor
icopydoc
Product
YML for Yandex Market
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32565

Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contextual Related Posts: from n/a through < 4.2.2.

PUBLISHED
Vendor
Ajay
Product
Contextual Related Posts
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32562

Missing Authorization vulnerability in WP Folio Team PPWP password-protect-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPWP: from n/a through <= 1.9.15.

PUBLISHED
Vendor
WP Folio Team
Product
PPWP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3256

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. The distribution includ

PUBLISHED
Vendor
KTAT
Product
HTTP::Session
Provider severity
CRITICAL
Conflicts
1

CVE-2026-3255

HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand() function is unsuitable for cryptographic usage. HTTP::Session2 after version 1.02 will attempt to use the /d

PUBLISHED
Vendor
TOKUHIROM
Product
HTTP::Session2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32546

Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/a through <= 3.2.22.

PUBLISHED
Vendor
StellarWP
Product
Restrict Content
Provider severity
HIGH
Conflicts
1

CVE-2026-32545

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Taboola Taboola Pixel taboola-pixel allows Reflected XSS.This issue affects Taboola Pixel: from n/a through <= 1.1.4.

PUBLISHED
Vendor
Taboola
Product
Taboola Pixel
Provider severity
HIGH
Conflicts
0

CVE-2026-32544

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OOPSpam Team OOPSpam Anti-Spam oopspam-anti-spam allows Stored XSS.This issue affects OOPSpam Anti-Spam: from n/a through <= 1.2.62.

PUBLISHED
Vendor
OOPSpam Team
Product
OOPSpam Anti-Spam
Provider severity
HIGH
Conflicts
0

CVE-2026-32543

Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Blocks: from n/a through <= 2.2.0.

PUBLISHED
Vendor
CyberChimps
Product
Responsive Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32542

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder fusion-builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through < 3.15.0.

PUBLISHED
Vendor
ThemeFusion
Product
Fusion Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-32541

Missing Authorization vulnerability in Premmerce Premmerce Redirect Manager premmerce-redirect-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce Redirect Manager: from n/a through <= 1.0.12.

PUBLISHED
Vendor
Premmerce
Product
Premmerce Redirect Manager
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32540

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a through <= 26.7.

PUBLISHED
Vendor
Bookly
Product
Bookly
Provider severity
HIGH
Conflicts
0

CVE-2026-3254

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
LOW
Conflicts
0

CVE-2026-32539

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects PublishPress Revisions: from n/a through <= 3.7.23.

PUBLISHED
Vendor
PublishPress
Product
PublishPress Revisions
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32538

Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Embedded Sensitive Data.This issue affects SMTP Mailer: from n/a through <= 1.1.24.

PUBLISHED
Vendor
Noor Alam
Product
SMTP Mailer
Provider severity
HIGH
Conflicts
0

CVE-2026-32537

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Visual Portfolio, Photo Gallery & Post Grid visual-portfolio allows PHP Local File Inclusion.This issue affects Visual Portfolio, Photo Gallery & Post Grid: from n/a through <= 3.5.1.

PUBLISHED
Vendor
nK
Product
Visual Portfolio, Photo Gallery & Post Grid
Provider severity
HIGH
Conflicts
0

CVE-2026-32536

Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a through <= 2.08.

PUBLISHED
Vendor
halfdata
Product
Green Downloads
Provider severity
CRITICAL
Conflicts
0