Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-32178

A flaw was found in the .NET runtime (System.Net.Mail) in how email address data is parsed. Improper neutralization of special characters, specifically carriage return and line feed (CR/LF) sequences, may allow specially crafted email address input to be interpreted incorrectly. An attacker could exploit this issue to perform email spoofing by injecting additional headers or altering how the email address is processed during SMTP operations

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Microsoft, Microsoft, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, .NET 9.0, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support, Microsoft Visual Studio 2022 version 17.12, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, .NET 8.0, Microsoft Visual Studio 2022 version 17.14, .NET 10.0, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Hardened Images, Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 10, .NET 8.0, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support
Provider severity
HIGH
Conflicts
3

CVE-2026-32177

A flaw was found in dotnet. A heap-based buffer overflow in .NET allows an unauthenticated attacker to elevate privileges locally.

PUBLISHED
Vendor
Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Microsoft, Red Hat, Microsoft, Microsoft, Microsoft, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Microsoft, Microsoft, Red Hat, Microsoft, Microsoft, Red Hat
Product
Red Hat Hardened Images, Microsoft .NET Framework 3.5 AND 4.7.2, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Microsoft .NET Framework 3.5 AND 4.8.1, .NET 10.0, Red Hat Enterprise Linux 10, .NET 9.0, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 4.8, Red Hat Enterprise Linux 10, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Hardened Images, Microsoft Visual Studio 2022 version 17.14, Red Hat Enterprise Linux 9, Microsoft Visual Studio 2022 version 17.12, Microsoft Visual Studio 2026 version 18.5, Red Hat Enterprise Linux 9, Microsoft .NET Framework 3.5, .NET 8.0, Red Hat Hardened Images
Provider severity
HIGH
Conflicts
3

CVE-2026-32176

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft SQL Server 2017 (GDR), Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2025 (CU 3), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 24)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32175

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories. To exploit the vulnerability, an attacker must send a specially crafted file to a vulnerable system. The security update fixes the vulnerability by ensuring .NET

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
.NET 9.0, Microsoft Visual Studio 2022 version 17.12, .NET 10.0, Microsoft Visual Studio 2022 version 17.14, .NET 8.0, Microsoft Visual Studio 2026 version 18.5
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32174

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure AI Bot Service
Provider severity
HIGH
Conflicts
0

CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure SRE Agent Gateway - SignalR Hub
Provider severity
HIGH
Conflicts
0

CVE-2026-32172

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Power Apps
Provider severity
HIGH
Conflicts
0

CVE-2026-32171

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Logic Apps
Provider severity
HIGH
Conflicts
0

CVE-2026-32170

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows 11 version 23H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1607, Windows Server 2019, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3217

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - Service Provider allows Cross-Site Scripting (XSS).This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.3.

PUBLISHED
Vendor
Drupal
Product
SAML SSO - Service Provider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32169

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Cloud Shell
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32168

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Monitor
Provider severity
HIGH
Conflicts
0

CVE-2026-32167

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft SQL Server 2022 for x64-based Systems (CU 24), Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2017 (GDR), Microsoft SQL Server 2025 (CU 3), Microsoft SQL Server 2022 (GDR)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32165

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2022, Windows 10 Version 1809, Windows Server 2025, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
2

CVE-2026-32164

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 1809, Windows 11 version 22H3, Windows 11 version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-32163

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2022, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
2

CVE-2026-32162

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 11 version 22H3, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2019, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-32161

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2012, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 25H2, Windows Server 2022
Provider severity
HIGH
Conflicts
2

CVE-2026-32160

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1, Windows Server 2019, Windows 11 Version 24H2, Windows Server 2022, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 22H3, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-3216

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1.

PUBLISHED
Vendor
Drupal
Product
Drupal Canvas
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32159

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2025, Windows 11 Version 24H2, Windows Server 2022, Windows 11 version 26H1, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
2

CVE-2026-32158

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2019, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
2

CVE-2026-32157

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2022, Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2012, Windows 10 Version 1607, Windows 11 version 22H3, Remote Desktop client for Windows Desktop, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2019, Windows App Client for Windows Desktop
Provider severity
HIGH
Conflicts
1

CVE-2026-32156

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows Server 2022, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 11 version 22H3, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2026-32155

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 version 22H3, Windows Server 2022, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-32154

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows Server 2016, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2025, Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-32153

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 11 Version 25H2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-32152

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-32151

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows 11 version 22H3, Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2012, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32150

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows 11 version 22H3, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 11 version 26H1, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-3215

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora allows Cross-Site Scripting (XSS).This issue affects Islandora: from 0.0.0 before 2.17.5.

PUBLISHED
Vendor
Drupal
Product
Islandora
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32149

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 1809, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 10 Version 1607, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
2

CVE-2026-32148

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked builds. However, Hex.RemoteConverger.verify_resolved/2 never executes checksum verification because the lock data returned by Hex.Utils.lock/1 uses string-based dependency names, while the verification logic compares again

PUBLISHED
Vendor
hexpm, hexpm
Product
hex, hex
Provider severity
HIGH
Conflicts
2

CVE-2026-32147

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to modify file attributes outside the configured chroot directory. The SFTP daemon (ssh_sftpd) stores the raw, user-supplied path in file handles instead of the chroot-resolved path. When SSH_FXP_FSETSTAT is issued on such a handle, file attributes (permissions, ownership, timestamps) are modified on the real filesystem path, bypassi

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32146

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory. When resolving git

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Gleam, Gleam, Red Hat, Gleam
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Gleam, Gleam, Red Hat Enterprise Linux 8, Gleam
Provider severity
HIGH
Conflicts
3

CVE-2026-32145

Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. The multipart_body function bypasses configured max_body_size and max_files_size limits. When a multipart boundary is not present in a chunk, the parser takes the MoreRequiredForBody path, which appends the chunk to the output but passes the quota unchanged to the recursive call. Only the final chunk containing the boundary is counted via decrement_qu

PUBLISHED
Vendor
gleam-wisp, gleam-wisp
Product
wisp, wisp
Provider severity
HIGH
Conflicts
1

CVE-2026-32144

A flaw was found in Erlang OTP public_key. This improper certificate validation vulnerability allows a remote attacker to bypass Online Certificate Status Protocol (OCSP) designated-responder authorization. The vulnerability stems from missing signature verification during OCSP response validation, enabling an attacker to forge responses that mark revoked certificates as valid. Consequently, clients may accept connections to compromised servers, potentially leading to the transmission of sensiti

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Erlang, Erlang, Erlang
Product
Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, OTP, OTP, OTP
Provider severity
HIGH
Conflicts
3

CVE-2026-32143

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive operational data intended only for admins. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32142

Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

PUBLISHED
Vendor
shopware
Product
commercial
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32141

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process. This vulnerability is fixed in 3.4.0.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, WebReflection, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Edge Manager 1.0, Red Hat Process Automation 7, Red Hat 3scale API Management Platform 2, Red Hat Edge Manager 1.1, Red Hat Process Automation 7, Red Hat Directory Server 11, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat AMQ Broker 7, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.9, Red Hat build of Apicurio Registry 2, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat Edge Manager 1.1, Red Hat Enterprise Linux 8, Logging Subsystem for Red Hat OpenShift, Red Hat Developer Hub 1.8, Red Hat 3scale API Management Platform 2, Red Hat Single Sign-On 7, Red Hat Directory Server 12, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Logging Subsystem for Red Hat OpenShift, Red Hat Edge Manager 1.1, streams for Apache Kafka 2, Red Hat Enterprise Linux 8, flatted, Red Hat 3scale API Management Platform 2, Red Hat Fuse 7, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 8, Red Hat Edge Manager 1.0, Red Hat OpenShift Container Platform 4, Red Hat 3scale API Management Platform 2, Red Hat Data Grid 8, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Dev Spaces 3.28, Red Hat 3scale API Management Platform 2, Cryostat 4, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, streams for Apache Kafka 3, Red Hat Edge Manager 1.1, Red Hat build of OptaPlanner 8, Red Hat 3scale API Management Platform 2, Red Hat Directory Server 13, Logging Subsystem for Red Hat OpenShift, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.16, Red Hat OpenShift Container Platform 4, Cluster Observability Operator 1.5.0, Cluster Observability Operator 1.5.0, Red Hat Quay 3
Provider severity
HIGH
Conflicts
2

CVE-2026-32140

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to remote code execution. The Redshift JDBC driver execution flow reaches a method named getJdbcIniFile. The getJdbcIniFile method implements an aggressive automatic configuration file discovery mechanism. If not explicitly

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3214

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.This issue affects CAPTCHA: from 0.0.0 before 1.17.0, from 2.0.0 before 2.0.10.

PUBLISHED
Vendor
Drupal
Product
CAPTCHA
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32139

Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads. However, backend validation only checks whether the XML is parseable and whether the root node is svg. It does not sanitize active content such as onload/onerror event handlers or script-capable attributes. As a result, an attacker can upload a malicious SVG and then trigger script execution in a browser by visiting the exposed static resource URL

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32138

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker could use these keys to interact with backend services without authentication, potentially leading to unauthorized access to application resources and user data. This vulnerability is fixed in 2.0.0.

PUBLISHED
Vendor
Stalin-143
Product
website
Provider severity
HIGH
Conflicts
1

CVE-2026-32137

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string, attackers can inject malicious SQL statements by constructing malicious table names. This vulnerability is fixed in 2.10.20.

PUBLISHED
Vendor
dataease
Product
dataease
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32136

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTTP/2 connection is handled by the inner mux, which has no authentication middleware attached. All subsequent HTTP/2 requests on that connection are processed as fully authenticated, regardless of wheth

PUBLISHED
Vendor
AdguardTeam
Product
AdGuardHome
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32135

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggerable heap buffer overflow in the `uri_param_parse` function of NanoMQ's REST API. The vulnerability occurs due to an off-by-one error when allocating memory for query parameter keys and values, allowing an attacker to write a null byte beyond the allocated buffer. This can be triggered via a crafted HTTP request. Version 0.24.11 patches the issue.

PUBLISHED
Vendor
nanomq
Product
nanomq
Provider severity
HIGH
Conflicts
0

CVE-2026-32134

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the broker can crash due to a NULL pointer dereference during MQTT session resumption for clean_start=0 clients. The transport's p_peer callback (tcptran_pipe_peer()) iterates cpipe->subinfol while copying session metadata from the cached old pipe to the new reconnecting pipe, without checking whether the

PUBLISHED
Vendor
nanomq, nanomq
Product
NanoNNG, nanomq
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32133

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability exists in 2FAuth that allows authenticated users to make arbitrary HTTP requests from the server to internal networks and cloud metadata endpoints. The image parameter in OTP URL is not properly validated for internal / private IP addresses before making HTTP requests. While the previous fix added response validation to ensure only valid images are

PUBLISHED
Vendor
Bubka
Product
2FAuth
Provider severity
HIGH
Conflicts
0

CVE-2026-32132

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the code, could allow an attacker to potentially register their own passkey and gain access to the victim's account. This vulnerability is fixed in 3.4.8 and 4.12.2.

PUBLISHED
Vendor
zitadel
Product
zitadel
Provider severity
HIGH
Conflicts
0