Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-27458

LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authenticated user can inject a CDATA-breaking payload into a list description that escapes the XML CDATA section, injects a native SVG element into the Atom XML document, and executes arbitrary JavaScript directly in the browser when the feed URL is visited. No RSS reader or additional rendering context is

PUBLISHED
Vendor
Kovah
Product
LinkAce
Provider severity
HIGH
Conflicts
0

CVE-2026-27457

Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user (or anonymous users if `REQUIRE_LOGIN` is not set) to list and retrieve ALL addons across all projects and components via `GET /api/addons/` and `GET /api/addons/{id}/`. Version 5.16.1 fixes the issue.

PUBLISHED
Vendor
WeblateOrg
Product
weblate
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27456

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither

PUBLISHED
Vendor
util-linux
Product
util-linux
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27454

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_to directly without verifying whether the revision was hidden or if the user had permission to view edit history. This meant hidden revisions (intentionally concealed by staff) could be read by any user by simply enumerating version numbers. Starting in version

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27452

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.

PUBLISHED
Vendor
JonathanWilbur
Product
asn1-ts
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2745

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts due to inconsistent input validation in the authentication process.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27449

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the network without requiring a valid session or user credentials. By supplying a user-controlled identifier parameter (e.g., ?id=), an attacker can retrieve sensitive data associated with arbitrary records.

PUBLISHED
Vendor
umbraco
Product
Umbraco.Engage.Forms
Provider severity
HIGH
Conflicts
1

CVE-2026-27448

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

PUBLISHED
Vendor
pyca
Product
pyopenssl
Provider severity
LOW
Conflicts
0

CVE-2026-27447

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly a

PUBLISHED
Vendor
OpenPrinting
Product
cups
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27446

A flaw was found in Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can exploit a missing authentication for critical function vulnerability by using the Core protocol. This allows the attacker to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. The primary consequence is the potential for message injection into any queue and/or message exfiltration from any queue via the rogue broker.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Siemens, Red Hat, Red Hat, Apache Software Foundation, Red Hat
Product
Red Hat AMQ Clients, Red Hat build of OptaPlanner 8, Red Hat Single Sign-On 7, Red Hat AMQ Broker 7.12.6, Red Hat OpenShift Dev Spaces, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat AMQ Broker 7.13.4, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat OpenShift Dev Spaces, Apache Artemis, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Fuse 7, Opcenter RDnL, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Apache ActiveMQ Artemis, Red Hat JBoss Enterprise Application Platform Expansion Pack
Provider severity
CRITICAL
Conflicts
3

CVE-2026-27445

SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signature spoofing.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27444

SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing an interpretation conflict with other mail infrastructure that allows an attacker to fake the source of the email or decrypt it.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-27443

SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME entities, allowing an attacker to control trusted headers.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-27442

The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenames in GINA-encrypted emails, allowing an attacker to access files on the gateway.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27441

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

PUBLISHED
Vendor
SEPPmail
Product
Secure Email Gateway
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27440

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.7.6.

PUBLISHED
Vendor
Saad Iqbal
Product
myCred
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27439

Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <= 1.5.

PUBLISHED
Vendor
ThemeREX
Product
Dentario
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27438

Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7.

PUBLISHED
Vendor
ThemeREX
Product
Kingler
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27437

Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through <= 1.2.3.

PUBLISHED
Vendor
ThemeREX
Product
Tennis Club
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27436

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.

PUBLISHED
Vendor
Rustaurius
Product
Five Star Business Profile and Schema
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27435

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

PUBLISHED
Vendor
WofficeIO
Product
Woffice
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27433

Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.

PUBLISHED
Vendor
StylemixThemes
Product
Motors
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27430

Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.

PUBLISHED
Vendor
tranmautritam
Product
TheFox
Provider severity
HIGH
Conflicts
0

CVE-2026-2743

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

PUBLISHED
Vendor
SeppMail
Product
SeppMail
Provider severity
CRITICAL
Conflicts
1

CVE-2026-27429

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

PUBLISHED
Vendor
BoldThemes
Product
Nifty
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27428

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle Booking eagle-booking allows SQL Injection.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.

PUBLISHED
Vendor
Eagle-Themes
Product
Eagle Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-27427

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from n/a through 1.13.18.

PUBLISHED
Vendor
Dylan Kuhn
Product
Geo Mashup
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27426

Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.

PUBLISHED
Vendor
Themesuite
Product
Automotive Car Dealership Business
Provider severity
HIGH
Conflicts
0

CVE-2026-27425

Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.

PUBLISHED
Vendor
Themesuite
Product
Automotive Listings
Provider severity
HIGH
Conflicts
0

CVE-2026-27424

Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.

PUBLISHED
Vendor
WP Chill
Product
Image Photo Gallery Final Tiles Grid
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27423

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

PUBLISHED
Vendor
Roland Barker
Product
Participants Database
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27422

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

PUBLISHED
Vendor
bPlugins
Product
YT Player
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27421

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS. This issue affects Royal Elementor Addons: from n/a before 1.7.1053.

PUBLISHED
Vendor
WProyal
Product
Royal Elementor Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2742

An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24.9.7 and 25.0.0 through 25.0.1, applications using Spring Security due to inconsistent path pattern matching of reserved framework paths. Accessing the /VAADIN endpoint without a trailing slash bypasses security filters, and allowing unauthenticated users to trigger framework initialization and create sessions without proper authorization. Users of affected versions using Spr

PUBLISHED
Vendor
vaadin, vaadin
Product
vaadin, flow
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27419

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.

PUBLISHED
Vendor
Zozothemes
Product
Zegen
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27418

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

PUBLISHED
Vendor
Epsiloncool
Product
WP Fast Total Search
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27417

Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1.

PUBLISHED
Vendor
SeventhQueen
Product
Sweet Date
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27416

Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF Poster: from n/a through 2.4.1.

PUBLISHED
Vendor
bPlugins
Product
PDF Poster
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27415

Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affects BEAR: from n/a through 1.1.5.

PUBLISHED
Vendor
PluginUs.Net
Product
BEAR
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27414

Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

PUBLISHED
Vendor
Fuelthemes
Product
Werkstatt
Provider severity
HIGH
Conflicts
0

CVE-2026-27413

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0.

PUBLISHED
Vendor
Cozmoslabs
Product
Profile Builder Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27412

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

PUBLISHED
Vendor
StylemixThemes
Product
Pearl - Corporate Business
Provider severity
HIGH
Conflicts
0

CVE-2026-27411

Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affects SiteGuard WP Plugin: from n/a through <= 1.7.9.

PUBLISHED
Vendor
jp-secure
Product
SiteGuard WP Plugin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27410

Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.

PUBLISHED
Vendor
VeronaLabs
Product
Slimstat Analytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2741

Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 through 24.9.8, and 25.0.0 through 25.0.2. Vaadin’s build process can automatically download and extract Node.js if it is not installed locally. If an attacker can intercept or control this download via DNS hijacking, a MITM attack, a compromised mirror, or a supply chain attack, they can serve a malicious archive con

PUBLISHED
Vendor
vaadin, vaadin, vaadin
Product
flow, vaadin, flow
Provider severity
LOW
Conflicts
1

CVE-2026-27409

Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.

PUBLISHED
Vendor
Webba Plugins
Product
Webba Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27408

Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.

PUBLISHED
Vendor
imithemes
Product
NativeChurch
Provider severity
HIGH
Conflicts
0

CVE-2026-27407

Editor Privilege Escalation in AI Engine <= 3.4.9 versions.

PUBLISHED
Vendor
Meow Apps
Product
AI Engine
Provider severity
HIGH
Conflicts
0

CVE-2026-27406

Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embedded Sensitive Data.This issue affects My Tickets: from n/a through <= 2.1.0.

PUBLISHED
Vendor
Joe Dolson
Product
My Tickets
Provider severity
HIGH
Conflicts
0

CVE-2026-27405

Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9.

PUBLISHED
Vendor
Magepeople inc.
Product
WpBookingly
Provider severity
MEDIUM
Conflicts
0