Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25937

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of a user's credentials can bypass MFA and steal their account. Version 11.0.6 fixes the issue.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25936

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25935

Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanceTooltip.vue temporarily creates a div and sets the innerHtml to the description. Since there is no escaping on either the server or client side, a malicious user can share a project, create a malicious task, and cause an XSS on hover. This vulnerability is fixed in 1.1.0.

PUBLISHED
Vendor
go-vikunja
Product
vikunja
Provider severity
HIGH
Conflicts
0

CVE-2026-25934

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform inte

PUBLISHED
Vendor
go-git
Product
go-git
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25933

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from insufficient sanitization and validation of input data received from connected hardware devices, specifically in the _info.Serial and _info.Address metadata fields. The problem occurs during device information handling. When a board is connected, the application collects identifying attributes to est

PUBLISHED
Vendor
arduino
Product
arduino-app-lab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25932

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
HIGH
Conflicts
1

CVE-2026-25931

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each time settings are fetched. The code coerces any truthy value to true and forwards it to ConfigLoader.setIsTrusted , which in turn allows JavaScript/TypeScript configuration files ( .c

PUBLISHED
Vendor
streetsidesoftware
Product
vscode-spell-checker
Provider severity
HIGH
Conflicts
1

CVE-2026-25930

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not verify that the form belongs to the current user’s authorized patient/encounter. An authenticated user with LBF access can enumerate form IDs and view or print any patient’s encounter forms. Version 8.0.0 fixes the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2593

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_gspb_post_css` post meta value and the `dynamicAttributes` block attribute in all versions up to, and including, 12.8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page

PUBLISHED
Vendor
wpsoul
Product
Greenshift – animation and page builder blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25929

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verifying that the current user is authorized to access that patient. An authenticated user with document ACL can supply another patient’s ID and retrieve their photo. Version 8.0.0 fixes the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25928

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing path traversal sequences (e.g. `../`). An attacker with DICOM upload/export permission can write files outside the intended directory, potentially under the web root, leading to arbitrary file write and possibly remote code execution if PHP or other

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25927

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the document belongs to the current user’s authorized patient or encounter. An authenticated user can read or modify DICOM viewer state (e.g. annotations, view settings) for any document by enumerating document IDs. Version 8.0.0 fixes the issue.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-25926

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the context of the running application. Version 8.9.2 patches the issue.

PUBLISHED
Vendor
notepad-plus-plus
Product
notepad-plus-plus
Provider severity
HIGH
Conflicts
0

CVE-2026-25925

PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts the $type property in JSON files, allowing an attacker to instantiate arbitrary .NET objects and execute code. This vulnerability is fixed in 2.4.0.

PUBLISHED
Vendor
modery
Product
PowerDocu
Provider severity
HIGH
Conflicts
0

CVE-2026-25924

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin installation interface when the PLUGIN_INSTALLER configuration is set to false, the underlying backend endpoint fails to verify this security setting. An attacker can exploit this oversight to force the server to download and

PUBLISHED
Vendor
kanboard
Product
kanboard
Provider severity
HIGH
Conflicts
0

CVE-2026-25923

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature, trigger Phar deserialization through BBCode [img] tag processing, and exploit Smarty 4.1.0 POP chain to achieve arbitrary file deletion. This vulnerability is fixed in 20260208.1.

PUBLISHED
Vendor
My-Little-Forum
Product
mylittleforum
Provider severity
HIGH
Conflicts
1

CVE-2026-25922

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Advanced Protocol settings configured, it was possible for an attacker to inject a malicious assertion before the signed assertion that authentik would use instead. authentik 2025.8.6, 2025.10.4, and 2025

PUBLISHED
Vendor
goauthentik
Product
authentik
Provider severity
HIGH
Conflicts
1

CVE-2026-25921

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS objects are vulnerable to be maliciously overwritten by malicious attackers. This issue has been patched in version 0.14.2.

PUBLISHED
Vendor
gogs
Product
gogs
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25920

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check in AddCdicData() only validates half the range that DecodeOne() actually accesses. Opening a crafted .mobi file can read nearly (1 << codeLength) bytes beyond the CDIC dictionary buffer, leading to a crash.

PUBLISHED
Vendor
sumatrapdfreader
Product
sumatrapdf
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2592

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callback handler 'Return_from_ZarinPal_Gateway' failing to validate that the authority token provided in the callback URL belongs to the specific order being marked as paid. This makes it possible for unauthenticated attackers to potentially mark orders as paid without proper payment by reusing a valid a

PUBLISHED
Vendor
zarinpal
Product
Zarinpal Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-25918

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems. This vulnerability is fixed in 1.8.2.

PUBLISHED
Vendor
RageAgainstThePixel
Product
unity-cli
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25917

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
HIGH
Conflicts
0

CVE-2026-25916

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25908

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulnerability in the AWCC. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

PUBLISHED
Vendor
Dell
Product
Alienware Command Center (AWCC)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25907

Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25906

Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

PUBLISHED
Vendor
Dell
Product
Optimizer
Provider severity
HIGH
Conflicts
0

CVE-2026-25905

The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

PUBLISHED
Vendor
Not asserted
Product
Not asserted
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25904

The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix.

PUBLISHED
Vendor
Not asserted
Product
Not asserted
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25903

Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required to add the annotated component to the flow configuration, but framework authorization did not check restricted status when updating a component previously added. The missing authorization requires a more privileged user to add a restric

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache NiFi
Provider severity
HIGH
Conflicts
0

CVE-2026-25901

Lack of output escaping leads to a XSS vector in the multilingual associations component.

PUBLISHED
Vendor
Joomla! Project
Product
Joomla! CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25900

Lack of output escaping leads to a XSS vector in the feed modules.

PUBLISHED
Vendor
Joomla! Project
Product
Joomla! CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2590

Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing certain connection types while password saving is disabled.

PUBLISHED
Vendor
Devolutions
Product
Remote Desktop Manager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25899

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpack deserialization. No authentication is required. Every GoFiber v3 endpoint is affected regardless of whether the application uses flash messages. Version 3.1.0 fixes the issue.

PUBLISHED
Vendor
gofiber
Product
fiber
Provider severity
HIGH
Conflicts
0

CVE-2026-25898

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25897

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25896

A flaw was found in fast-xml-parser. A remote attacker can exploit this vulnerability by providing a specially crafted XML input. The system incorrectly interprets a dot in a DOCTYPE entity name as a regular expression wildcard during processing. This allows the attacker to bypass security measures and inject malicious scripts, resulting in Cross-Site Scripting (XSS) when the parsed output is displayed to users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, NaturalIntelligence, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Migration Toolkit for Applications 8, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Security 4.8, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Developer Hub 1.8, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Self-service automation portal 2, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Virtualization 4, Red Hat Satellite 6, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift GitOps, Red Hat Developer Hub 1.9, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Security 4.9, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, fast-xml-parser, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Satellite 6, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-25895

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched in FUXA version 1.2.10.

PUBLISHED
Vendor
frangoteam
Product
FUXA
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25894

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enabled, but the administrator JWT secret is not configured. This issue has been patched in FUXA version 1.2.10.

PUBLISHED
Vendor
frangoteam
Product
FUXA
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25893

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execute arbitrary code on the server. This issue has been patched in FUXA version 1.2.10.

PUBLISHED
Vendor
frangoteam
Product
FUXA
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25892

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to a

PUBLISHED
Vendor
vrana
Product
adminer
Provider severity
HIGH
Conflicts
0

CVE-2026-25891

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.

PUBLISHED
Vendor
gofiber
Product
fiber
Provider severity
HIGH
Conflicts
0

CVE-2026-25890

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/) to the path, the authorization check fails to match the rule, while the underlying filesystem resolves the path correctly, granting unauthorized access to restricted files. This vuln

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
HIGH
Conflicts
1

CVE-2026-2589

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 12.8.3 via the automated Settings Backup stored in a publicly accessible file. This makes it possible for unauthenticated attackers to extract sensitive data including the configured OpenAI, Claude, Google Maps, Gemini, DeepSeek, and Cloudflare Turnstile API keys.

PUBLISHED
Vendor
wpsoul
Product
Greenshift – animation and page builder blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25889

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a case-sensitivity flaw in the password validation logic allows any authenticated user to change their password (or an admin to change any user's password) without providing the current password. By using Title Case field name "Password" instead of lowercase "password" in the API request, the current_password verification is completel

PUBLISHED
Vendor
filebrowser
Product
filebrowser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25888

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via a vulnerable API. This issue has been patched in version 4.8.1.

PUBLISHED
Vendor
chartbrew
Product
chartbrew
Provider severity
HIGH
Conflicts
0

CVE-2026-25887

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.

PUBLISHED
Vendor
chartbrew
Product
chartbrew
Provider severity
HIGH
Conflicts
0

CVE-2026-25885

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss://polarlearn.nl/api/v1/ws can be used without logging in. An unauthenticated client can subscribe to any group chat by providing a group UUID, and can also send messages to any group. The server accepts the message and stores it in the group’s chatContent, so this is not just a visual spam issue.

PUBLISHED
Vendor
polarnl
Product
PolarLearn
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25884

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

PUBLISHED
Vendor
Exiv2
Product
exiv2
Provider severity
LOW
Conflicts
0

CVE-2026-25883

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa webhook feature allows authenticated users to configure an arbitrary URL that receives HTTP POST requests when meetings complete. The application performs no validation on the webhook URL, enabling Server-Side Request Forgery (SSRF). An authenticated attacker can set their webhook URL to target internal services (Redis, databases, admin panels), cloud metadata endpoints (AWS

PUBLISHED
Vendor
Vexa-ai
Product
vexa
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25882

Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vulnerability results from missing validation during route registration combined with an unbounded array write during request matching. Version 2.52.12 patches the issue in the v2 branch and 3.1.0 patches the issue in the v3 branch.

PUBLISHED
Vendor
gofiber
Product
fiber
Provider severity
MEDIUM
Conflicts
0