Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-28764

MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability

PUBLISHED
Vendor
MediaArea
Product
MediaInfoLib
Provider severity
HIGH
Conflicts
0

CVE-2026-28761

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.

PUBLISHED
Vendor
Fujitsu Japan Limited
Product
Musetheque V4 Information Disclosure for IPKNOWLEDGE
Provider severity
HIGH
Conflicts
1

CVE-2026-28760

The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a crafted DLL with the installer, an arbitrary code may be executed with the administrator privilege.

PUBLISHED
Vendor
RATOC Systems, Inc.
Product
RATOC RAID Monitoring Manager for Windows
Provider severity
HIGH
Conflicts
1

CVE-2026-2876

A vulnerability was determined in Tenda A18 15.13.07.13. This affects the function parse_macfilter_rule of the file /goform/setBlackRule. This manipulation of the argument deviceList causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
A18
Provider severity
HIGH
Conflicts
2

CVE-2026-28759

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28758

When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28756

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
Provider severity
HIGH
Conflicts
0

CVE-2026-28755

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
NGINX Plus, NGINX Open Source
Provider severity
MEDIUM
Conflicts
2

CVE-2026-28754

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
Provider severity
HIGH
Conflicts
0

CVE-2026-28753

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5, F5
Product
NGINX Open Source, NGINX Plus
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-28751

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

PUBLISHED
Vendor
OpenHarmony
Product
OpenHarmony
Provider severity
LOW
Conflicts
0

CVE-2026-28747

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

PUBLISHED
Vendor
Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight, Milesight
Product
MS-Cxx71-xxxPE, MS-C2964-RFLPC, MS-Cxx61-xxxPE, MS-Cxx67-xxxPE, TS5511-GVH, MS-C5366-X12LVPC, TS2867-X5TPC, TS5366-X12PE, TS2866-X4TVPC, TS4441-X36RPE, MS-C5321-FPE, MS-Nxxxx-xxH, PMC8266-FGPE, TS5366-X12RIPG1, TS4466-X4RPE, MS-Cxx62-xxxG1, TS8266-X4VPE, SP111, TS8266-RFIVPG1, MS-C2966-X12RLPC, MS-Nxxxx-NxE, MS-CQxx72-xxxG1, MS-Cxx66-RFIPKG1, TS4441-X36RE, MS-Nxxxx-xxG, MS-C2966-X12RLVPC, TS8266-FPC/P, SC211, MS-C2972-RFLPC, MS-Cxx72-xxxPE, TS8266-X4RIVPG1, MS-CQxx68-xxxG1, TS8266-X4RIWG1, TS2961-X12TPC, TS5510-GVH, MS-C5361-X12LPC, TS2866-X4TGPC, MS-Cxx72-FIPKG1, TS4466-X4RIWG1, MS-Cxx63-PD, MS-Nxxxx-xxT, MS-C8477-HPG1, MS-C5366-X12LPC, PMC8266-FPE, MS-Cxx72-RFIPKG1, TS8266-X4PE, MS-Cxx83-xPD, MS-C2966-RFLWPC, MS-Cxx66-xxxG1, MS-Nxxxx-xxE, PM3322-E, MS-Cxx66-FIPKG1, MS-Cxx73-xPD, TS4466-X4RIVPG1, MS-Cxx66-xxxPE, TS4466-RFIVPG1, MS-Cxx66-xxxGPE, TS5366-X12VPE, TS5510-GH, MS-C8477-PC, TS4466-X4RIPG1, TS4466-X4RWE, MS-Cxx41-xxxPE, MS-Cxx64-xPD, MS-Cxx74-PA, TS2841-X36TPC/W, TS4466-X4RVPE, TS2966-X12TVPE, TS2841-X36TPC, MS-Cxx62-xxxPE, MS-Cxx52-xxxPE, MS-Cxx76-PE, TS8266-X4RIPG1, MS-Nxxxx-xxC, TS2866-X4TPC, MS-Cxx65-PE, TS8266-X4WE, MS-Cxx66-xxxxGOPC, MS-Cxx75-xxPD, MS-CQxx31-xxxG1, TS2966-X12TPE, MS-Cxx72-xxxG1
Provider severity
HIGH
Conflicts
2

CVE-2026-28744

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
HIGH
Conflicts
0

CVE-2026-28742

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate valid signatures for arbitrary device or account operations due to the absence of per-device keys, server-side nonce tracking, or replay protections. Combined with the system’s use of plain HTTP for control-plane traffic, the construction enables broad request forgery and impersonation across the pla

PUBLISHED
Vendor
Naxclow, Naxclow, Naxclow, Naxclow
Product
ix cam, V720, Smart Doorbell X3, X Smart Home
Provider severity
CRITICAL
Conflicts
2

CVE-2026-28741

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious page. Mattermost Advisory ID: MMSA-2026-00625

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28740

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
HIGH
Conflicts
1

CVE-2026-2874

A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipulation of the argument ssid can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Tenda
Product
A21
Provider severity
HIGH
Conflicts
2

CVE-2026-28737

Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
HIGH
Conflicts
0

CVE-2026-28736

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. This allows an authenticated attacker who knows a victim's fileID to read the content of the file. NOTE: Focalboard as a standalone product is not maintained and no fix will be issued.

PUBLISHED
Vendor
Mattermost
Product
Focalboard
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28735

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28733

in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.

PUBLISHED
Vendor
OpenHarmony
Product
OpenHarmony
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28732

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2873

A vulnerability was detected in Tenda A21 1.0.0.0. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Tenda
Product
A21
Provider severity
HIGH
Conflicts
2

CVE-2026-28728

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

PUBLISHED
Vendor
Acronis
Product
Acronis True Image
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28727

Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.

PUBLISHED
Vendor
Acronis, Acronis, Acronis
Product
Acronis Cyber Protect 17, Acronis Cyber Protect Cloud Agent, Acronis True Image
Provider severity
HIGH
Conflicts
1

CVE-2026-28726

Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28725

Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28724

Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28723

Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28722

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
HIGH
Conflicts
0

CVE-2026-28721

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
HIGH
Conflicts
0

CVE-2026-28720

Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2872

A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. Such manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
Tenda
Product
A21
Provider severity
HIGH
Conflicts
2

CVE-2026-28719

Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28718

Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28717

Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28716

Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28715

Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28714

Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28713

Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.

PUBLISHED
Vendor
Acronis, Acronis
Product
Acronis Cyber Protect Cloud Agent, Acronis Cyber Protect 17
Provider severity
HIGH
Conflicts
1

CVE-2026-28712

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28711

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28710

Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
HIGH
Conflicts
0

CVE-2026-2871

A weakness has been identified in Tenda A21 1.0.0.0. This affects the function fromSetIpMacBind of the file /goform/SetIpMacBind. This manipulation of the argument list causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Tenda
Product
A21
Provider severity
HIGH
Conflicts
2

CVE-2026-28709

Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

PUBLISHED
Vendor
Acronis
Product
Acronis Cyber Protect 17
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28705

Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release assets, allowing specially crafted names to affect dump output paths.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28704

Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with the privilege of the user invoking EmoCheck.

PUBLISHED
Vendor
Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)
Product
Emocheck
Provider severity
HIGH
Conflicts
1

CVE-2026-28703

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
Provider severity
HIGH
Conflicts
0

CVE-2026-28701

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

PUBLISHED
Vendor
Daktronics, Daktronics, Daktronics
Product
DMP-8000, DMP-5000, VFC-DMP-5000
Provider severity
CRITICAL
Conflicts
2

CVE-2026-2870

A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Tenda
Product
A21
Provider severity
HIGH
Conflicts
2