Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-27914

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2016, Windows Server 2012 R2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-27913

Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-27912

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-27911

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2019, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2025, Windows 11 version 22H3, Windows 10 Version 1607, Windows Server 2022
Provider severity
HIGH
Conflicts
2

CVE-2026-27910

Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2012 R2, Windows Server 2022, Windows Server 2025, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 11 Version 23H2, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 22H3, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-2791

Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27909

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2019, Windows Server 2022, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2025, Windows 11 version 26H1, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-27908

Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2022, Windows 10 Version 22H2, Windows 11 version 26H1, Windows 10 Version 1809, Windows Server 2019, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 Version 23H2, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-27907

Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-27906

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 11 Version 24H2, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 10 Version 22H2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27905

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path, not the symlink's target. An attacker can create a malicious bento/model tar file containing a symlink pointing outside the extraction directory, followed by a regular file that writes through the sy

PUBLISHED
Vendor
bentoml
Product
BentoML
Provider severity
HIGH
Conflicts
0

CVE-2026-27904

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe

PUBLISHED
Vendor
isaacs
Product
minimatch
Provider severity
HIGH
Conflicts
0

CVE-2026-27903

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call

PUBLISHED
Vendor
isaacs
Product
minimatch
Provider severity
HIGH
Conflicts
0

CVE-2026-27902

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.

PUBLISHED
Vendor
sveltejs
Product
svelte
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27901

Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. Version 5.53.5 fixes the issue.

PUBLISHED
Vendor
sveltejs
Product
svelte
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27900

The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when debug/provider logs are explicitly enabled (for example in local troubleshooting, CI/CD jobs, or centralized log collection). If enabled, sensitive values may be written to logs and then retained, shared, or exported beyond the ori

PUBLISHED
Vendor
linode
Product
terraform-provider-linode
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2790

Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-27899

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and back in, the session picks up admin privileges from the database. When a user updates their own profile, the server parses the full JSON body into the user model, including the `Is

PUBLISHED
Vendor
h44z
Product
wg-portal
Provider severity
HIGH
Conflicts
1

CVE-2026-27898

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint returns 200 OK and exposes cipherDetails (including name, notes, data, secureNote, etc.). This issue has been patched in version 1.35.4.

PUBLISHED
Vendor
dani-garcia
Product
vaultwarden
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27897

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the file path, the API does not validate the filename string before it is processed by the backends filesystem logic. Because the API is unauthenticated and the CORS configuration in app.

PUBLISHED
Vendor
WanderingAstronomer
Product
Vociferous
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27896

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:"method" would also match "Method", "METHOD", etc. This violated the JSON-RPC 2.0 specification, which defines exact field names. A malicious MCP peer may have been able to send protocol messages with non-standard field casing that the SDK would silently

PUBLISHED
Vendor
Red Hat, Red Hat, modelcontextprotocol, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Migration Toolkit for Virtualization, Migration Toolkit for Virtualization, go-sdk, Red Hat OpenShift AI (RHOAI), Migration Toolkit for Virtualization, OpenShift Serverless, OpenShift Serverless, Migration Toolkit for Virtualization, OpenShift Lightspeed, Migration Toolkit for Virtualization, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
3

CVE-2026-27895

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf, an attacker can achieve remote code execution as the web server user. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-ac

PUBLISHED
Vendor
LDAPAccountManager
Product
lam
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27894

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8 this allows to execute arbitrary code. Users need to login to LAM to exploit this vulnerability. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be

PUBLISHED
Vendor
LDAPAccountManager
Product
lam
Provider severity
HIGH
Conflicts
0

CVE-2026-27893

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-out. This enables remote code execution via malicious model repositories even when the user has explicitly disabled remote code trust. Version 0.18.0 patches the issue.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, vllm-project, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI 3.3, Red Hat AI Inference Server, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, vllm, Red Hat AI Inference Server, Red Hat Enterprise Linux AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux AI 3.3
Provider severity
HIGH
Conflicts
2

CVE-2026-27892

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC metadata. Any authenticated user who downloaded an image could extract the uploader's embedded metadata, which included GPS coordinates, device information, timestamps, embedded comments/notes, thumbnail previews, and other personally identifiable information (PII) preserved in the image metadata. Of all

PUBLISHED
Vendor
NeoRazorX
Product
facturascripts
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27891

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leading to Arbitrary File Write and Remote Code Execution (RCE) by overwriting sensitive .php files outside the designated plugins directory. The vulnerability is located in Plugins.php. While the testZipFi

PUBLISHED
Vendor
NeoRazorX
Product
facturascripts
Provider severity
HIGH
Conflicts
1

CVE-2026-27890

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in

PUBLISHED
Vendor
FirebirdSQL
Product
firebird
Provider severity
HIGH
Conflicts
1

CVE-2026-2789

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2026-27889

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before authentication, and so is exposed to anyone who can connect to the websockets port. Versions 2.11.14 and 2.12.5 contains a fix. A workaround is available. The vulnerability only affects deployments which use WebSockets an

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, nats-io, Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat multicluster global hub 1.6.0, Multicluster Global Hub 1.5.4, nats-server, Red Hat multicluster global hub 1.4.4
Provider severity
HIGH
Conflicts
2

CVE-2026-27888

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode`. This has been fixed in pypdf 6.7.3. As a workaround, apply the patch manually.

PUBLISHED
Vendor
py-pdf
Product
pypdf
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27887

Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to buffer the entire response before delivering it to the guest, which can lead to the host process running out of memory, panicking, and crashing. In addition, a malicious guest appli

PUBLISHED
Vendor
spinframework, spinframework, spinframework
Product
spin, SpinKube, containerd-shim-spin
Provider severity
MEDIUM
Conflicts
2

CVE-2026-27886

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` (or other admin-relation) field to perform a boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field.

PUBLISHED
Vendor
strapi
Product
strapi
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27885

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including user credentials, email addresses, and all stored content. This issue has been patched in version 16.3.0.

PUBLISHED
Vendor
Piwigo
Product
Piwigo
Provider severity
HIGH
Conflicts
0

CVE-2026-27884

NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file and folder path when saving files from SMB shares. It does not take into account that it is possible for Linux SMB shares to have path traversal characters such as `../` in them. An attacker can craft a filename in an SMB share that includes these characters, which when spider_plus crawls and downloads, can write or overwrite arbitrary files. The issue is patched in v1.5.1. As a

PUBLISHED
Vendor
Pennyw0rth
Product
NetExec
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27883

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any team, bypassing team-based authorization. The $teamId is extracted from the authentication token but never used to scope the database query. This vulnerability is fixed in 4.0.0-beta.464.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27882

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation is vulnerable to timing attacks, which could allow an attacker to gradually discover the secret token by measuring response time differences. This vulnerability is fixed in 4.0.0-beta.461.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27881

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments/{uuid}` in DeployController.php retrieves deployment details without validating that the deployment belongs to the authenticated user's team. Any authenticated API user can read deployment records from other teams by providing a valid deployment UUID. This vulnerability is fixed in 4.0.0-beta.464.

PUBLISHED
Vendor
coollabsio
Product
coolify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27880

A flaw was found in Grafana. A remote attacker can exploit the feature toggle evaluation endpoint by sending unbounded values, causing the system to read excessive data into memory. This can lead to out-of-memory crashes, resulting in a Denial of Service (DoS) for the affected service.

PUBLISHED
Vendor
Red Hat, Red Hat, Grafana, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Grafana, Red Hat Enterprise Linux 8
Provider severity
HIGH
Conflicts
3

CVE-2026-2788

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27879

A resample query can be used to trigger out-of-memory crashes in Grafana.

PUBLISHED
Vendor
Grafana
Product
Grafana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27878

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

PUBLISHED
Vendor
Grafana, Grafana
Product
Tempo, Enterprise Traces (GET)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27877

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Grafana, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Grafana, Red Hat Enterprise Linux 10
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-27876

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. Only instances in the following version ranges are affected: - 11.6.0 (inclusive) to 11.6.14 (exclusive): 11.6.14 has the fix. 11.5 and below are not

PUBLISHED
Vendor
Red Hat, Red Hat, Grafana, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Grafana, Red Hat Enterprise Linux 8
Provider severity
CRITICAL
Conflicts
3

CVE-2026-27870

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS)  payload into the 'Hostname' field of the configuration file resulting in a XSS in the path /upgrade/query.php?cmd=p+3%3Bversion. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

PUBLISHED
Vendor
Teldat
Product
Regesta Smart HD-PLC - TLDPH16D2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2787

Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2026-27869

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

PUBLISHED
Vendor
Teldat
Product
Regesta Smart HD-PLC - TLDPH16D2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27868

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information disclosure. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

PUBLISHED
Vendor
Teldat
Product
Regesta Smart HD-PLC - TLDPH16D2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27860

If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.

PUBLISHED
Vendor
Open-Xchange GmbH
Product
OX Dovecot Pro
Provider severity
LOW
Conflicts
0

CVE-2026-2786

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2026-27859

A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed version where the processing is limited. No publicly available exploits are known.

PUBLISHED
Vendor
Open-Xchange GmbH
Product
OX Dovecot Pro
Provider severity
MEDIUM
Conflicts
0