Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-28353

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users using the affected artifact are advised to immediately remove it and rotate environment secrets. The malicious artifact has been removed from the marketplace. No other affected artifact

PUBLISHED
Vendor
aquasecurity
Product
trivy-vscode-extension
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28352

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check, allowing unauthenticated/unauthorized access to this endpoint. The impact of this is limited to getting the metadata (title, category chain, start/end date) for events in an existing series, deleting an existing event series, and modifying an existing event series. This vulnerability

PUBLISHED
Vendor
indico
Product
indico
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28351

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode filter. This has been fixed in pypdf 6.7.4. As a workaround, consider applying the changes from PR #3664.

PUBLISHED
Vendor
py-pdf
Product
pypdf
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28350

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject it and hijack relative links on the page. This issue has been patched in version 0.4.4.

PUBLISHED
Vendor
fedora-python
Product
lxml_html_clean
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2835

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attackers to send HTTP/1.0 requests in a way that would desync Pingora’s request framing from backend servers’. Impact This vulnerability primarily affects standalone Pingora deployments in front of certain b

PUBLISHED
Vendor
Cloudflare
Product
https://github.com/cloudflare/pingora
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28348

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing external CSS loading or XSS in older browsers. This issue has been patched in version 0.4.4.

PUBLISHED
Vendor
fedora-python
Product
lxml_html_clean
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28343

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to version 47.6.0, a cross-site scripting (XSS) vulnerability has been discovered in the General HTML Support feature. This vulnerability could be triggered by inserting specially crafted markup, leading to unauthorized JavaScript code execution, if the editor instance used an unsafe General HTML Support configuration. This issue has been patched in version 47.6.0.

PUBLISHED
Vendor
ckeditor
Product
ckeditor5
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28342

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By issuing multiple parallel requests, an attacker can exhaust available container memory, leading to service degradation or complete denial of service (DoS). The issue occurs because the endpoint performs computationally and memory-intensive hashing o

PUBLISHED
Vendor
OliveTin
Product
OliveTin
Provider severity
HIGH
Conflicts
1

CVE-2026-2834

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ parameter in all versions up to, and including, 3.32.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
tokenoftrust
Product
Age Verification & Identity Verification by Token of Trust
Provider severity
HIGH
Conflicts
0

CVE-2026-28338

PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report formats insert rule violation messages into HTML output without escaping. When PMD analyzes untrusted source code containing crafted string literals, the generated HTML report contains executable JavaScript that runs when opened in a browser. Practical impact is limited because `vbhtml` and `yahtml` are legacy formats rarely used in practice. The default `html` format is properly

PUBLISHED
Vendor
pmd
Product
pmd
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2833

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the rest of the bytes on the connection to a backend before the backend has accepted the upgrade. An attacker can thus directly forward a malicious payload after a request with an Upgrade header to that backend in a way that may be interpreted as a subsequent request

PUBLISHED
Vendor
Cloudflare
Product
https://github.com/cloudflare/pingora
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

PUBLISHED
Vendor
SolarWinds
Product
Web Help Desk
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28322

SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

PUBLISHED
Vendor
SolarWinds
Product
Database Performance Analyzer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28321

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-2832

Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization.

PUBLISHED
Vendor
HP Inc, HP Inc, HP Inc, HP Inc
Product
SL-K4255RX, SL-K4305LX, SL-K4355LX, Samsung MultiXpress SL-X7600LXR, SL-X7500LXR, SL-X7400LXR, SL-X4225RX, SL-X4255LX, SL-X4305LX, Samsung MultiXpress SL-K7400LXR, SL-K7500LXR, SL-K7600LXR
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28318

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

PUBLISHEDCISA KEV
Vendor
SolarWinds
Product
Serv-U
Provider severity
HIGH
Conflicts
0

CVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28315

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-2831

The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
pierrelannoy
Product
MailArchiver
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28307

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28306

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28305

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28304

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28302

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

PUBLISHED
Vendor
SolarWinds
Product
Serv-U
Provider severity
CRITICAL, MEDIUM
Conflicts
1

CVE-2026-28301

A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.

PUBLISHED
Vendor
SolarWinds
Product
Observability Self-Hosted
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2830

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PUBLISHED
Vendor
wpallimport
Product
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28299

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

PUBLISHED
Vendor
SolarWinds
Product
Web Help Desk
Provider severity
HIGH
Conflicts
0

CVE-2026-28298

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

PUBLISHED
Vendor
SolarWinds
Product
SolarWinds Observability Self-Hosted
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28297

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

PUBLISHED
Vendor
SolarWinds
Product
SolarWinds Observability Self-Hosted
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28296

A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28295

A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28292

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, steveukx, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform Expansion Pack, simple-git, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 8, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Process Automation 7
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-28291

simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as Git's flexible option parsing allows numerous character combinations (e.g., -vu, -4u, -nu) to circumvent the regular-expression-based blocklist in the unsafe operations plugin. Due to

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, steveukx, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Build of Keycloak, Red Hat Process Automation 7, git-js, Red Hat JBoss Enterprise Application Platform 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
2

CVE-2026-28289

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contain

PUBLISHED
Vendor
freescout-help-desk
Product
freescout
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28288

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

PUBLISHED
Vendor
langgenius
Product
dify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28287

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5.

PUBLISHED
Vendor
FreePBX
Product
security-reporting
Provider severity
HIGH
Conflicts
0

CVE-2026-28286

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting directly with the API, the restrictions are bypass-able. By sending a crafted request targeting paths like /etc, /usr, or other sensitive system directories, the API successfully creates files or directories in locations where n

PUBLISHED
Vendor
IceWhaleTech
Product
ZimaOS
Provider severity
HIGH
Conflicts
0

CVE-2026-28284

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5.

PUBLISHED
Vendor
FreePBX
Product
security-reporting
Provider severity
HIGH
Conflicts
0

CVE-2026-28282

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any private/restricted groups. Once membership to a private/restricted group has been obtained, the user will be able to read private topics that only the group has access to. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workarou

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
LOW
Conflicts
0

CVE-2026-28281

InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability is fixed in 2.18.1.

PUBLISHED
Vendor
instantsoft
Product
icms2
Provider severity
HIGH
Conflicts
0

CVE-2026-28280

osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exists in the `osctrl-admin` on-demand query list. A user with query-level permissions can inject arbitrary JavaScript via the query parameter when running an on-demand query. The payload is stored and executes in the browser of any user (including administrators) who visits the query list page. This can be chained with CSRF token extraction to escalate privileges and take actions

PUBLISHED
Vendor
jmpsec
Product
osctrl
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28279

osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell commands via the hostname parameter when creating or editing environments. These commands are embedded into enrollment one-liner scripts generated using Go's `text/template` package (which does not perform shell escaping) and execute on every endpoint that enrolls using the comprom

PUBLISHED
Vendor
jmpsec
Product
osctrl
Provider severity
HIGH
Conflicts
0

CVE-2026-28277

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that tri

PUBLISHED
Vendor
langchain-ai
Product
langgraph
Provider severity
MEDIUM
Conflicts
0