Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-2563

A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the component jdcapp_rpc. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
JingDong
Product
JD Cloud Box AX6600
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25628

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.

PUBLISHED
Vendor
qdrant
Product
qdrant
Provider severity
HIGH
Conflicts
0

CVE-2026-25627

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while providing a much shorter actual payload. The code path copies Remaining Length bytes without verifying that the current receive buffer contains that many bytes, resulting in an out-of-bounds read (ASAN reports OOB / crash). This is remotely triggerable ove

PUBLISHED
Vendor
nanomq
Product
nanomq
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25624

An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.

PUBLISHED
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25623

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this exposure to obtain underlying terminal script code processing execution permissions.

PUBLISHED
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-25622

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.

PUBLISHED
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-25621

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

PUBLISHED
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-25620

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

PUBLISHED
Vendor
Arista Networks
Product
Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-2562

A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jdcweb_rpc. Executing a manipulation of the argument File can lead to Remote Privilege Escalation. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
JingDong
Product
JD Cloud Box AX6600
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25616

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

PUBLISHED
Vendor
Blesta
Product
Blesta
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25615

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.

PUBLISHED
Vendor
Blesta
Product
Blesta
Provider severity
HIGH
Conflicts
0

CVE-2026-25614

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

PUBLISHED
Vendor
Blesta
Product
Blesta
Provider severity
HIGH
Conflicts
0

CVE-2026-25613

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-25612

The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-25611

A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH
Conflicts
1

CVE-2026-25610

An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-2561

A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation results in Remote Privilege Escalation. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
JingDong
Product
JD Cloud Box AX6600
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25609

Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.

PUBLISHED
Vendor
MongoDB Inc
Product
MongoDB Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25608

STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.

PUBLISHED
Vendor
Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy
Product
STER
Provider severity
LOW
Conflicts
0

CVE-2026-25607

Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5.

PUBLISHED
Vendor
Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy
Product
STER
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25606

A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access This issue was fixed in version 9.5.

PUBLISHED
Vendor
Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy
Product
STER
Provider severity
HIGH
Conflicts
0

CVE-2026-25605

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.

PUBLISHED
Vendor
Siemens
Product
SICAM SIAPP SDK
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25604

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow Providers Amazon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25603

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

PUBLISHED
Vendor
Linksys, Linksys
Product
MX4200, MR9600
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25602

Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email address. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

PUBLISHED
Vendor
Mesalvo, Mesalvo
Product
Meona Server Component, Meona Client Launcher Component
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25601

A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic key within the Mx.Web.ComponentModel.dll component. When the option to store domain passwords was enabled, this key was used to encrypt user passwords before storing them in the application’s database. An attacker with sufficient privileges to access the database could extract the encrypted passwords, decrypt them using the embedded key, and gain u

PUBLISHED
Vendor
Metronik d.o.o.
Product
MEPIS RM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25600

The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the function responsible for decrypting credentials stored in the product’s configuration file. Because the secret is constant across installations, any attacker with sufficient local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored password and authenticate as th

PUBLISHED
Vendor
Trac d.o.o.
Product
PDBM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2560

A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
kalcaddle
Product
kodbox
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25599

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an unencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an attacker to impersonate a legitimate device and inject malicious payloads

PUBLISHED
Vendor
Orca Energy, Orca Energy
Product
Orca user portal, Orca heat pump
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25598

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto, sendmsg, and sendmmsg socket system calls can bypass detection and logging when using egress-policy: audit. This vulnerability is fixed in 2.14.2.

PUBLISHED
Vendor
step-security
Product
harden-runner
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25597

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. This vulnerability is fixed in 8.2.4 and 9.0.3.

PUBLISHED
Vendor
PrestaShop
Product
PrestaShop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25596

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Product Unit Name fields. An authenticated administrator can inject malicious JavaScript that executes when any administrator views an invoice containing a product with the malicious unit. Version 1.7.1 patches the issue.

PUBLISHED
Vendor
InvoicePlane
Product
InvoicePlane
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25595

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Invoice Number field. An authenticated administrator can inject malicious JavaScript that executes when any administrator views the affected invoice or visits the dashboard. Version 1.7.1 patches the issue.

PUBLISHED
Vendor
InvoicePlane
Product
InvoicePlane
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25594

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability exists in InvoicePlane 1.7.0 via the Family Name field. The `family_name` value is rendered without HTML encoding inside the family dropdown on the product form. When an administrator creates a family with a malicious name, the payload executes in the browser of any administrator who visits the product form. Version 1.7.1 patches the issue.

PUBLISHED
Vendor
InvoicePlane
Product
InvoicePlane
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25593

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability is fixed in 2026.1.20.

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH
Conflicts
1

CVE-2026-25592

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem has been fixed in Microsoft.SemanticKernel.Core version 1.71.0. As a mitigation, users can create a Function Invocation Filter which checks the arguments being passed to any calls to DownloadFileAsync  or UploadFileAsync and e

PUBLISHED
Vendor
microsoft
Product
semantic-kernel
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25591

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting malicious search patterns. The token search endpoint accepts user-supplied `keyword` and `token` parameters that are directly concatenated into SQL LIKE clauses without escaping wildcard

PUBLISHED
Vendor
QuantumNous
Product
new-api
Provider severity
HIGH
Conflicts
0

CVE-2026-25590

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.

PUBLISHED
Vendor
glpi-project
Product
glpi-inventory-plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2559

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the site's Office 365 OAuth mail configuration (access toke

PUBLISHED
Vendor
saadiqbal
Product
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25589

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL r

PUBLISHED
Vendor
RedisBloom
Product
RedisBloom
Provider severity
HIGH
Conflicts
0

CVE-2026-25588

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rul

PUBLISHED
Vendor
RedisTimeSeries
Product
RedisTimeSeries
Provider severity
HIGH
Conflicts
0

CVE-2026-25587

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the sandbox can be escaped. This vulnerability is fixed in 0.8.29.

PUBLISHED
Vendor
nyariv
Product
SandboxJS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25586

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement in the property-access path. This permits direct access to __proto__ and other blocked prototype properties, enabling host Object.prototype pollution and persistent cross-sandbox impact. This vulnerability is fixed in 0.8.29.

PUBLISHED
Vendor
nyariv
Product
SandboxJS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25585

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a vulnerability IccCmm.cpp:5793 when reading through index during ICC profile processing. The malformed ICC profile triggers improper array bounds validation in the color management module, resulting in an out-of-bounds read that can lead to memory disclosure or segmentation fault from accessing memory beyond the array bou

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-25584

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). This is triggered when processing a malformed ICC profile. The vulnerability allows an out-of-bounds write on the stack, potentially leading to memory corruption, information disclosure, or code execution when processing specially crafted ICC files. T

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-25583

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow vulnerability in CIccFileIO::Read8() when processing malformed ICC profile files via unchecked fread operation. This issue has been patched in version 2.3.1.3.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-25582

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow (read) vulnerability in CIccIO::WriteUInt16Float() when converting malformed XML to ICC profiles via iccFromXml tool. This issue has been patched in version 2.3.1.3.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-25581

SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration options. This vulnerability is fixed in 3.2.1.

PUBLISHED
Vendor
samclarke
Product
SCEditor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25580

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include malicious URLs that cause the server to make HTTP requests to internal network resources, potentially accessing internal services or cloud credentials. This vulnerability only affec

PUBLISHED
Vendor
Red Hat, pydantic, Red Hat
Product
Red Hat Enterprise Linux AI (RHEL AI) 3, pydantic-ai, Red Hat Enterprise Linux AI (RHEL AI) 3
Provider severity
HIGH
Conflicts
2

CVE-2026-2558

A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_handler.go. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
GeekAI
Provider severity
MEDIUM
Conflicts
1