Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-29167

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2916

The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.1 via the `enqueue_scripts()` method in `class/dashboard/class-dashboard.php`. The plugin injects a `JkitDashboardOption` JavaScript object containing full plugin inventory (names, versions, paths, active status), system environment details (WordPress version, PHP version, site URLs, server capabilities), and potentially third-party API credentials (Mailchimp A

PUBLISHED
Vendor
jegtheme
Product
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2915

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

PUBLISHED
Vendor
HP Inc
Product
HP System Event Utility
Provider severity
MEDIUM
Conflicts
1

CVE-2026-29146

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Apache Tomcat, Red Hat JBoss Web Server 6.2.3, Red Hat JBoss Web Server 6.2 on RHEL 10, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat JBoss Web Server 7.0 on RHEL 9, Red Hat Enterprise Linux 8, Red Hat JBoss Web Server 6.2 on RHEL 8, Red Hat JBoss Web Server 5, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat JBoss Web Server 6.2 on RHEL 9, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat JBoss Web Server 7.0 on RHEL 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat JBoss Web Server 7.0 on RHEL 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat JBoss Web Server 7.0.0, Red Hat Enterprise Linux 6
Provider severity
HIGH
Conflicts
2

CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation
Product
Apache Tomcat, Apache Tomcat Native
Provider severity
CRITICAL
Conflicts
2

CVE-2026-29144

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-29143

SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-29142

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29141

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-29140

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-2914

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

PUBLISHED
Vendor
CyberArk Software, a Palo Alto Networks Company
Product
Endpoint Privilege Manager Agent
Provider severity
HIGH
Conflicts
1

CVE-2026-29139

SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-29138

SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29137

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29136

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29135

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29134

SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29133

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29132

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29131

SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2913

A vulnerability was determined in libvips up to 8.19.0. The affected element is the function vips_source_read_to_memory of the file libvips/iofuncs/source.c. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. Patch name: a56feecbe9ed66521d9647ec9fbcd2546eccd7ee. Applying a patch is the recomme

PUBLISHED
Vendor
n/a
Product
libvips
Provider severity
LOW
Conflicts
2

CVE-2026-29129

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Tomcat
Provider severity
HIGH
Conflicts
1

CVE-2026-29128

IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) contain hardcoded or otherwise insecure plaintext passwords (including “enable”/privileged-mode credentials). A remote actor is able to abuse the reuse/hardcoded nature of these credentials to further access other systems in the netw

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
1

CVE-2026-29127

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the system due to the presence of highly privileged processes and binaries residing within the affected directory.

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
CRITICAL
Conflicts
0

CVE-2026-29126

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and persistence) via modification of a root-owned, world-writable BusyBox udhcpc DHCP event script, which is executed when a DHCP lease is obtained, renewed, or lost.

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29125

IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and cause denial of service.

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29124

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from the `monitor` user to root

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29123

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlink abuse or shared object hijacking.

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29122

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root user on the local file system. This allows an actor to be able to read any root read-only files, such as the /etc/shadow file or other configuration/secrets carrier files.

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29121

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root user on the local file system and may potentially lead to other avenues for preforming privileged actions.

PUBLISHED
Vendor
International Datacasting Corporation
Product
SFX2100 Satellite Receiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29120

The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password itself is highly insecure and susceptible to offline dictionary attacks using the rockyou.txt wordlist. Because direct root SSH login is disabled, an attacker must first obtain low-privileged access to the system (e.g., via other vulnerabilities) to be able to log in as the root u

PUBLISHED
Vendor
International Datacasting Corporation
Product
IDC SFX2100 SuperFlex Satellite Receiver
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2912

A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Online Reviewer System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-29119

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.

PUBLISHED
Vendor
International Datacasting Corporation (IDC)
Product
SFX2100 Series SuperFlex SatelliteReceiver
Provider severity
HIGH
Conflicts
0

CVE-2026-29116

A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.

PUBLISHED
Vendor
Dahua
Product
IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPC
Provider severity
HIGH
Conflicts
0

CVE-2026-29115

A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.

PUBLISHED
Vendor
Dahua
Product
IPC/SD
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29114

A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain.

PUBLISHED
Vendor
Dahua
Product
IPC
Provider severity
LOW
Conflicts
0

CVE-2026-29113

Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an attacker can force a logged-in victim editor to mint a preview token chosen by the attacker. That token can then be used by the attacker (without authentication) to access previewed/unpublished content t

PUBLISHED
Vendor
craftcms
Product
cms
Provider severity
LOW
Conflicts
0

CVE-2026-29112

DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `width` and `height` attributes from the input SVG to determine the output canvas size for rasterization (PNG, JPEG, WebP, AVIF). An attacker who can supply a crafted SVG with extremely large dimensions (e.g. `width="999999999"`) could force the server to allocate excessive memory, leading to denial of service. This primarily affects server-side applic

PUBLISHED
Vendor
dicebear
Product
dicebear
Provider severity
HIGH
Conflicts
0

CVE-2026-29111

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. N

PUBLISHED
Vendor
systemd
Product
systemd
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29110

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information about the files stored inside a vault at a time, where the actual vault is closed. Not every cleartext path is logged. Only if a filesystem request fails for some reason (e.g. damaged encrypted file, not existing file), a log message is created. This issue has been patched in version 1.19.0.

PUBLISHED
Vendor
cryptomator
Product
cryptomator
Provider severity
LOW
Conflicts
0

CVE-2026-2911

A vulnerability has been found in Tenda FH451 up to 1.0.0.9. This issue affects some unknown processing of the file /goform/GstDhcpSetSer. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
FH451
Provider severity
HIGH
Conflicts
2

CVE-2026-29109

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an authenticated administrator to execute arbitrary system commands on the server. `FilterDefinitionProvider.php` calls `unserialize()` on user-controlled data from the `saved_search.contents` database column without restricting instantiable classes. V

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM-Core
Provider severity
HIGH
Conflicts
0

CVE-2026-29108

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and MFA configuration. As any authenticated user can query this endpoint, it's possible to retrieve and potentially crack the passwords of administrative users. Version 8.9.3 patches the issue.

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM-Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29107

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `<img>` tags. When a PDF is exported using this template, the content (for example, `<img src=http://{burp_collaborator_url}>` is rendered server side, and thus a request is issued from the server, resulting in Server-Side Request Forgery. Versions 7.15.1 and 8.9.3 patch the issue.

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29106

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is encapsulated in double quotation marks. Versions 7.15.1 and 8.9.3 patch the issue. Users should also use a Content Security Policy (CSP) header to completely mitigate XSS.

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
MEDIUM
Conflicts
1

CVE-2026-29105

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter is used as a redirect destination without validation, allowing attackers to redirect victims to arbitrary external websites. This vulnerability allows attackers to abuse the trusted SuiteCRM domain for phishing and social

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-29104

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can bypass intended file type restrictions when uploading PDF font files, allowing arbitrary files with attacker‑controlled filenames to be written to the server. Although the upload directory is not directly web‑accessible by d

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
LOW
Conflicts
0

CVE-2026-29103

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a direct Patch Bypass of CVE-2024-49774. Although the vendor attempted to fix the issue in version 7.14.5, the underlying flaw in ModuleScanner.php regarding PHP token parsing remains. The scanner incorrect

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
CRITICAL
Conflicts
1

CVE-2026-29102

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution (RCE) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
HIGH
Conflicts
0

CVE-2026-29101

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

PUBLISHED
Vendor
SuiteCRM
Product
SuiteCRM
Provider severity
MEDIUM
Conflicts
0