Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25197

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

PUBLISHED
Vendor
Gardyn
Product
Cloud API
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25196

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when the configuration is processed.

PUBLISHED
Vendor
Copeland, Copeland, Copeland
Product
Copeland XWEB 500D PRO, Copeland XWEB 500B PRO, Copeland XWEB 300D PRO
Provider severity
HIGH
Conflicts
1

CVE-2026-25195

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

PUBLISHED
Vendor
Copeland, Copeland, Copeland
Product
Copeland XWEB 300D PRO, Copeland XWEB 500B PRO, Copeland XWEB 500D PRO
Provider severity
HIGH
Conflicts
1

CVE-2026-25193

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %pr

PUBLISHED
Vendor
Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher, Gallagher
Product
Entra ID Sync, Diagnostics Service, Command Centre Server, Okta Sync, Event Logger, Encoding Kiosk Application, Event Sync Utility, Active Directory Sync, Cardholder Sync Utility, SIP Integration, Middleware Framework, Elevator Service, Papercut Interface Integration, Nexudus Integration
Provider severity
HIGH
Conflicts
1

CVE-2026-25192

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption o

PUBLISHED
Vendor
CTEK
Product
Chargeportal
Provider severity
CRITICAL
Conflicts
1

CVE-2026-25191

The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privilege.

PUBLISHED
Vendor
Digital Arts Inc., Digital Arts Inc.
Product
FinalCode Ver.6 series, FinalCode Ver.5 series
Provider severity
HIGH
Conflicts
2

CVE-2026-25190

Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 R2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-2519

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it possible for unauthenticated attackers to submit a negative number to the 'tips' parameter, causing the total price to be reduced to zero.

PUBLISHED
Vendor
ladela
Product
Online Scheduling and Appointment Booking System – Bookly
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25189

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-25188

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2019, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-25187

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 version 22H3, Windows Server 2025 (Server Core installation), Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-25186

Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2016 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2016, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25185

Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2022, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2012 R2, Windows 11 version 26H1, Windows 11 version 22H3
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25184

Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 version 22H3, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-25181

Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 21H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2012, Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2012 R2
Provider severity
HIGH
Conflicts
1

CVE-2026-25180

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016, Windows 11 version 22H3, Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 11 Version 23H2, Windows 11 version 26H1, Windows 11 Version 25H2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2012 R2, Windows 10 Version 22H2, Microsoft Office for Android, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 1809
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2518

The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the PostX plugin.

PUBLISHED
Vendor
wpxpo
Product
FastX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25179

Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2016, Windows Server 2012, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows 11 version 22H3, Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows Server 2022, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-25178

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2025, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2016, Windows 11 version 22H3
Provider severity
HIGH
Conflicts
1

CVE-2026-25177

Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2022, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 1607, Windows 11 version 26H1, Windows Server 2025, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-25176

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 (Server Core installation), Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2022, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-25175

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2016, Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2022, Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2026-25174

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2025, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows 11 version 22H3, Windows Server 2012 R2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2012, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-25173

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows 10 Version 1607, Windows 11 version 22H3, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows 10 Version 1809, Windows 10 Version 21H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-25172

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 23H2, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 11 version 26H1, Windows 11 Version 25H2, Windows 11 version 22H3, Windows Server 2022, Windows Server 2016, Windows Server 2012, Windows Server 2025, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1809
Provider severity
HIGH
Conflicts
2

CVE-2026-25171

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2022, Windows Server 2012 R2, Windows 10 Version 1809, Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows Server 2012, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2019, Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-25170

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2022, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-2517

A security flaw has been discovered in Open5GS up to 2.7.6. This vulnerability affects the function ogs_gtp2_parse_tft in the library lib/gtp/v2/types.c of the component SMF. Performing a manipulation of the argument pf[0].content.length results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
Open5GS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25169

Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2016 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2025, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2012, Windows Server 2022, Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25168

Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2 (Server Core installation), Windows Server 2012 R2, Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2025, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2012
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25167

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-25166

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows ADK for Windows Server 2022, Windows ADK for Windows 10, version 2004, Windows ADK for Windows 11, version 22H2, Windows ADK for Windows 11, version 24H2, Windows ADK for Windows 11, version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-25165

Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows 10 Version 22H2, Windows 10 Version 21H2, Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2016 (Server Core installation), Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2019, Windows Server 2012, Windows 11 Version 25H2, Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-25164

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `apis/routes/_rest_routes_standard.inc.php` does not call `RestConfig::request_authorization_check()` for the document and insurance routes. Other patient routes in the same file (e.g. encounters, patients/med) call it with the appropriate ACL. As a result, any valid API bearer token can access or modify every patient's documents and insuran

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-25161

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation handlers. An authenticated attacker can bypass directory-level authorisation by injecting traversal sequences into filename components, enabling unauthorised file removal, movement and copying across user boundaries within the same storage mount. This issue has been patched in version 3.57.0.

PUBLISHED
Vendor
AlistGo
Product
alist
Provider severity
HIGH
Conflicts
0

CVE-2026-25160

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (MitM) attacks. This enables the complete decryption, theft, and manipulation of all data transmitted during storage operations, severely compromising the confidentiality and integrity of user data. This issue has been pat

PUBLISHED
Vendor
AlistGo
Product
alist
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2516

A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in the library SHFOLDER.dll. Such manipulation leads to uncontrolled search path. The attack needs to be performed locally. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading the affected component is recommended. The vendor explains: "[W]e have already addressed similar D

PUBLISHED
Vendor
Unidocs, Unidocs
Product
ezPDF DRM Reader, ezPDF Reader
Provider severity
HIGH
Conflicts
3

CVE-2026-25157

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SS

PUBLISHED
Vendor
openclaw
Product
openclaw
Provider severity
HIGH
Conflicts
0

CVE-2026-25156

HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be rendered in the user’s browser rather than downloaded. (The intended behavior was for only `text/plain`, `application/pdf`, `image/gif`, `image/jpeg`, and `image/png` to be delivered inline, though adding `save=0` to the document URL could request inline delivery for any document.) This made users who clicked a document

PUBLISHED
Vendor
kohler
Product
hotcrp
Provider severity
HIGH
Conflicts
0

CVE-2026-25155

Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.

PUBLISHED
Vendor
QwikDev
Product
qwik
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25154

LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local network without needing an internet connection. In versions up to and including 1.17.0, when a user initiates a "Share via Link" session, the LocalSend application starts a local HTTP server to host the selected files. The client-side logic for this web interface is contained in `app/assets/web/main.js`. Note that at [0], the `handleFilesDisplay` function constructs the HTML fo

PUBLISHED
Vendor
localsend
Product
localsend
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25153

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when TechDocs is configured with `runIn: local`, a malicious actor who can submit or modify a repository's `mkdocs.yml` file can execute arbitrary Python code on the TechDocs build server via MkDocs hooks configuration. @backstage/plugin-techdocs-node versions 1.13.11 an

PUBLISHED
Vendor
Red Hat, Red Hat, backstage, Red Hat
Product
Red Hat Developer Hub 1.9, Red Hat Developer Hub 1.8, backstage, Self-service automation portal 2
Provider severity
HIGH
Conflicts
2

CVE-2026-25152

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs local generator allows attackers to read arbitrary files from the host filesystem when Backstage is configured with `techdocs.generator.runIn: local`. When processing documentation from untrusted sources, symlinks within the

PUBLISHED
Vendor
backstage
Product
backstage
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25151

Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted or multi-valued Content-Type headers. This issue has been patched in version 1.19.0.

PUBLISHED
Vendor
QwikDev
Product
qwik
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25150

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create nested objects, but fails to sanitize dangerous property names like __proto__, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially l

PUBLISHED
Vendor
QwikDev
Product
qwik
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2515

The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to use the 'hostinger_reach_connection_notice_action' action to update the API key value stored in the database. This vulnerability can only be exploited whe

PUBLISHED
Vendor
hostinger
Product
Hostinger Reach – AI-Powered Email Marketing for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25149

Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs. Successful exploitation permits attackers to craft convincing phishing links that appear to originate from the trusted domain but redirect the victim to an attacker-controlled site. This issue has been patched in version 1.19.0.

PUBLISHED
Vendor
QwikDev
Product
qwik
Provider severity
LOW
Conflicts
0

CVE-2026-25148

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual attributes. Successful exploitation permits script execution in a victim's browser in the context of the affected origin. This issue has been patched in version 1.19.0.

PUBLISHED
Vendor
QwikDev
Product
qwik
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25147

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid = ($_REQUEST['hidden_patient_code'] ?? null) > 0 ? $_REQUEST['hidden_patient_code'] : $pid`) instead of being fixed to the authenticated portal user. The portal session already has a valid `$pid` for the logged-in patient. Overwriting

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
HIGH
Conflicts
0

CVE-2026-25146

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.

PUBLISHED
Vendor
openemr
Product
openemr
Provider severity
CRITICAL
Conflicts
0