Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-28208

Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often lead to remote code execution (e.g., overwriting shell profiles, source code, cron jobs, etc). Version 7.5.8 has a fix for the issue.

PUBLISHED
Vendor
junrar
Product
junrar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28207

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shell commands by providing a specially crafted output filename via the `-o` command-line argument. The vulnerability existed in the `main` application logic (specifically in `src/main.c`), where the compiler constructed a shell command string to invoke the backend C compiler. This c

PUBLISHED
Vendor
z-libs
Product
Zen-C
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28205

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.

PUBLISHED
Vendor
OpenPLC_V3
Product
OpenPLC_V3
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28204

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

PUBLISHED
Vendor
CTEK
Product
Chargeportal
Provider severity
MEDIUM
Conflicts
1

CVE-2026-28201

An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.

PUBLISHED
Vendor
Open Notebook
Product
Open Notebook
Provider severity
HIGH
Conflicts
1

CVE-2026-2820

A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects some unknown processing of the file /Module/CRXT/Controller/XAccessPermissionPlus.ashx. The manipulation of the argument DeviceIDS results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Fujian
Product
Smart Integrated Management Platform System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-28196

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

PUBLISHED
Vendor
JetBrains
Product
TeamCity
Provider severity
LOW
Conflicts
0

CVE-2026-28195

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

PUBLISHED
Vendor
JetBrains
Product
TeamCity
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28194

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

PUBLISHED
Vendor
JetBrains
Product
TeamCity
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28193

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

PUBLISHED
Vendor
JetBrains
Product
YouTrack
Provider severity
HIGH
Conflicts
0

CVE-2026-2819

A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Dromara
Product
RuoYi-Vue-Plus
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2818

A flaw was found in Spring Data Geode. This zip-slip path traversal vulnerability in the import snapshot functionality allows attackers to write files outside the intended extraction directory. This can lead to unauthorized modification of system files or the introduction of malicious content. This vulnerability primarily affects systems running on Windows operating systems.

PUBLISHED
Vendor
Red Hat, VMware, VMware
Product
Red Hat Fuse 7, Spring Data Gemfire, Spring Data Geode
Provider severity
HIGH
Conflicts
3

CVE-2026-2817

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

PUBLISHED
Vendor
VMware, VMware
Product
Spring Data Geode, Spring Data Gemfire
Provider severity
MEDIUM
Conflicts
3

CVE-2026-2815

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

PUBLISHED
Vendor
Silicon Labs
Product
SiSDK
Provider severity
HIGH
Conflicts
0

CVE-2026-28147

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.

PUBLISHED
Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28145

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

PUBLISHED
Vendor
StylemixThemes
Product
MasterStudy LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28144

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.

PUBLISHED
Vendor
Flipper Code
Product
WP Maps
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28138

Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.

PUBLISHED
Vendor
Stylemix
Product
uListing
Provider severity
HIGH
Conflicts
0

CVE-2026-28137

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Reflected XSS.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 14.9.

PUBLISHED
Vendor
QuanticaLabs
Product
MediCenter - Health Medical Clinic
Provider severity
HIGH
Conflicts
0

CVE-2026-28136

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.This issue affects WP SMS: from n/a through <= 6.9.12.

PUBLISHED
Vendor
VeronaLabs
Product
WP SMS
Provider severity
HIGH
Conflicts
0

CVE-2026-28135

Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1052.

PUBLISHED
Vendor
WP Royal
Product
Royal Elementor Addons
Provider severity
HIGH
Conflicts
1

CVE-2026-28134

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2.

PUBLISHED
Vendor
Crocoblock
Product
JetEngine
Provider severity
HIGH
Conflicts
0

CVE-2026-28133

Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.

PUBLISHED
Vendor
WP Chill
Product
Filr
Provider severity
HIGH
Conflicts
0

CVE-2026-28132

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews allows Code Injection.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.4.4.

PUBLISHED
Vendor
villatheme
Product
WooCommerce Photo Reviews
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28131

Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4.

PUBLISHED
Vendor
WPVibes
Product
Elementor Addon Elements
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28130

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign u-design allows Reflected XSS.This issue affects UDesign: from n/a through <= 4.14.0.

PUBLISHED
Vendor
AndonDesign
Product
UDesign
Provider severity
HIGH
Conflicts
0

CVE-2026-2813

ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could exploit this issue by sending a specially crafted request, Successful exploitation may result in the application redirecting the browser to an unintended, untrusted site, resulting in a limited confidentiality impact under specific user interaction conditions. The vulnerability affects only the client side navigation logic during authentication and remains confined to the same s

PUBLISHED
Vendor
Esri
Product
ArcGIS Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28129

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-birdies allows PHP Local File Inclusion.This issue affects Little Birdies: from n/a through <= 1.3.16.

PUBLISHED
Vendor
axiomthemes
Product
Little Birdies
Provider severity
HIGH
Conflicts
0

CVE-2026-28128

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through <= 1.7.0.

PUBLISHED
Vendor
ThemeREX
Product
Verse
Provider severity
HIGH
Conflicts
0

CVE-2026-28127

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Directory: from n/a through <= 1.3.2.

PUBLISHED
Vendor
e-plugins
Product
Lawyer Directory
Provider severity
HIGH
Conflicts
0

CVE-2026-28126

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam RH Frontend Publishing Pro rh-frontend allows Reflected XSS.This issue affects RH Frontend Publishing Pro: from n/a through < 4.3.4.

PUBLISHED
Vendor
sizam
Product
RH Frontend Publishing Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-28125

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Midi midi allows PHP Local File Inclusion.This issue affects Midi: from n/a through <= 1.14.

PUBLISHED
Vendor
AncoraThemes
Product
Midi
Provider severity
HIGH
Conflicts
0

CVE-2026-28124

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Notarius notarius allows PHP Local File Inclusion.This issue affects Notarius: from n/a through <= 1.9.

PUBLISHED
Vendor
AncoraThemes
Product
Notarius
Provider severity
HIGH
Conflicts
0

CVE-2026-28123

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allows PHP Local File Inclusion.This issue affects Veil: from n/a through <= 1.9.

PUBLISHED
Vendor
AncoraThemes
Product
Veil
Provider severity
HIGH
Conflicts
0

CVE-2026-28122

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: from n/a through <= 2.9.8.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
HIGH
Conflicts
0

CVE-2026-28121

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Anderson andersonclinic allows PHP Local File Inclusion.This issue affects Anderson: from n/a through <= 1.4.2.

PUBLISHED
Vendor
AncoraThemes
Product
Anderson
Provider severity
HIGH
Conflicts
0

CVE-2026-28120

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dr.Patterson dr-patterson allows PHP Local File Inclusion.This issue affects Dr.Patterson: from n/a through <= 1.3.2.

PUBLISHED
Vendor
ThemeREX
Product
Dr.Patterson
Provider severity
HIGH
Conflicts
0

CVE-2026-2812

ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthenticated attacker could exploit this issue by sending a crafted request to the endpoint. Successful exploitation may result in disruption of the web-based browsing interface. This issue affects ArcGIS Server 12.0 and earlier.

PUBLISHED
Vendor
Esri
Product
ArcGIS Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28119

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Nirvana nir-vana allows PHP Local File Inclusion.This issue affects Nirvana: from n/a through <= 2.6.

PUBLISHED
Vendor
axiomthemes
Product
Nirvana
Provider severity
HIGH
Conflicts
0

CVE-2026-28118

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Welldone welldone allows PHP Local File Inclusion.This issue affects Welldone: from n/a through <= 2.4.

PUBLISHED
Vendor
axiomthemes
Product
Welldone
Provider severity
HIGH
Conflicts
0

CVE-2026-28117

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.9.

PUBLISHED
Vendor
axiomthemes
Product
smart SEO
Provider severity
HIGH
Conflicts
0

CVE-2026-28116

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0.

PUBLISHED
Vendor
Emilia Projects
Product
Progress Planner
Provider severity
MEDIUM
Conflicts
0

CVE-2026-28115

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations: from n/a through <= 1.25.

PUBLISHED
Vendor
loopus
Product
WP Attractive Donations System - Easy Stripe & Paypal donations
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28114

Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.

PUBLISHED
Vendor
firassaidi
Product
WooCommerce License Manager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-28113

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Reflected XSS.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.1.

PUBLISHED
Vendor
azzaroco
Product
Ultimate Learning Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-28112

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup AllInOne - Banner Rotator all-in-one-bannerRotator allows Reflected XSS.This issue affects AllInOne - Banner Rotator: from n/a through <= 3.8.

PUBLISHED
Vendor
LambertGroup
Product
AllInOne - Banner Rotator
Provider severity
HIGH
Conflicts
0

CVE-2026-28110

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist all-in-one-bannerWithPlaylist allows Reflected XSS.This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a through <= 3.8.

PUBLISHED
Vendor
LambertGroup
Product
LambertGroup - AllInOne - Banner with Playlist
Provider severity
HIGH
Conflicts
0

CVE-2026-28109

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Reflected XSS.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8.

PUBLISHED
Vendor
LambertGroup
Product
LambertGroup - AllInOne - Content Slider
Provider severity
HIGH
Conflicts
0

CVE-2026-28108

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbnails all-in-one-thumbnailsBanner allows Reflected XSS.This issue affects LambertGroup - AllInOne - Banner with Thumbnails: from n/a through <= 3.8.

PUBLISHED
Vendor
LambertGroup
Product
LambertGroup - AllInOne - Banner with Thumbnails
Provider severity
HIGH
Conflicts
0

CVE-2026-28107

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Muzicon muzicon allows PHP Local File Inclusion.This issue affects Muzicon: from n/a through <= 1.9.0.

PUBLISHED
Vendor
ThemeREX
Product
Muzicon
Provider severity
HIGH
Conflicts
0