Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-24835

Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prior to version 1.25.1 allows any extension to completely circumvent permission checks and gain unauthorized access to all authentication sessions. The `isAccessAllowed()` function unconditionally returns `true`, enabling malicious extensions to impersonate any user, hijack authentication sessions, and access sensitive resources without authorization.

PUBLISHED
Vendor
podman-desktop
Product
podman-desktop
Provider severity
HIGH
Conflicts
0

CVE-2026-24834

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately achieving arbitrary code execution as root in said VM. The current understanding is this doesn’t impact the security of the Host or of other containers / VMs running on that Host (note that

PUBLISHED
Vendor
Red Hat, kata-containers, Red Hat
Product
Red Hat OpenShift Container Platform 4, kata-containers, Confidential Compute Attestation
Provider severity
CRITICAL
Conflicts
3

CVE-2026-24833

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, a module could install with richtext in its description field which could contain scripts that will run for user in the Persona Bar. Versions 9.13.10 and 10.2.0 contain a fix for the issue.

PUBLISHED
Vendor
dnnsoftware
Product
Dnn.Platform
Provider severity
HIGH
Conflicts
0

CVE-2026-24832

Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

PUBLISHED
Vendor
ixray-team
Product
ixray-1.6-stcop
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24831

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

PUBLISHED
Vendor
ixray-team
Product
ixray-1.6-stcop
Provider severity
HIGH
Conflicts
0

CVE-2026-24830

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

PUBLISHED
Vendor
Ralim
Product
IronOS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2483

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session

PUBLISHED
Vendor
IBM
Product
InfoSphere Information Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24829

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

PUBLISHED
Vendor
Is-Daouda
Product
is-Engine
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24828

Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

PUBLISHED
Vendor
Is-Daouda
Product
is-Engine
Provider severity
HIGH
Conflicts
0

CVE-2026-24827

Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge.

PUBLISHED
Vendor
gerstrong
Product
Commander-Genius
Provider severity
HIGH
Conflicts
0

CVE-2026-24826

Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability in cadaver turso3d.This issue affects .

PUBLISHED
Vendor
cadaver
Product
turso3d
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24825

Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This vulnerability is associated with program files yail_tree.C. This issue affects ydb: through 24.4.4.2.

PUBLISHED
Vendor
ydb-platform
Product
ydb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24824

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in yacy yacy_search_server (source/net/yacy/http/servlets modules). This vulnerability is associated with program files YaCyDefaultServlet.Java. This issue affects yacy_search_server.

PUBLISHED
Vendor
yacy
Product
yacy_search_server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24823

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER/App/Utils/lv_img_png/PNGdec/src modules). This vulnerability is associated with program files inflate.C. This issue affects X-TRACK: through v2.7.

PUBLISHED
Vendor
FASTSHIFT
Product
X-TRACK
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24822

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.

PUBLISHED
Vendor
ttttupup
Product
wxhelper
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24821

Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C. This issue affects WickedEngine: through 0.71.727.

PUBLISHED
Vendor
turanszkij
Product
WickedEngine
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24820

Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files ldebug.C. This issue affects WickedEngine: before 0.71.705.

PUBLISHED
Vendor
turanszkij
Product
WickedEngine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2482

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

PUBLISHED
Vendor
IBM
Product
WebSphere Application Server - Liberty
Provider severity
LOW
Conflicts
0

CVE-2026-24819

Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/foxinmy/weixin4j/util modules). This vulnerability is associated with program files CharArrayBuffer.Java, ClassUtil.Java. This issue affects weixin4j.

PUBLISHED
Vendor
foxinmy
Product
weixin4j
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24818

Out-of-bounds Read vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects UEVR: before 1.05.

PUBLISHED
Vendor
praydog
Product
UEVR
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24817

Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects UEVR: before 1.05.

PUBLISHED
Vendor
praydog
Product
UEVR
Provider severity
HIGH
Conflicts
0

CVE-2026-24816

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlangtech/tis/runtime/module/action modules). This vulnerability is associated with program files ChangeDomainAction.Java. This issue affects tis: before v4.3.0.

PUBLISHED
Vendor
datavane
Product
tis
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24815

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before v4.3.0.

PUBLISHED
Vendor
datavane
Product
tis
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24814

Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.

PUBLISHED
Vendor
swoole
Product
swoole-src
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24813

NULL Pointer Dereference vulnerability in abcz316 SKRoot-linuxKernelRoot (testRoot/jni/utils modules). This vulnerability is associated with program files cJSON.Cpp. This issue affects SKRoot-linuxKernelRoot.

PUBLISHED
Vendor
abcz316
Product
SKRoot-linuxKernelRoot
Provider severity
HIGH
Conflicts
0

CVE-2026-24812

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root: through 6.36.00-rc1.

PUBLISHED
Vendor
root-project
Product
root
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24811

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.

PUBLISHED
Vendor
root-project
Product
root
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24810

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb (src/cjson modules). This vulnerability is associated with program files cJSON.Cc. This issue affects rethinkdb: through v2.4.4.

PUBLISHED
Vendor
rethinkdb
Product
rethinkdb
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2481

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[js]' parameter in versions up to, and including, 2.10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
beaverbuilder
Product
Beaver Builder Page Builder – Drag and Drop Website Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24809

An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 leads to a heap-buffer overflow when a recursive error occurs.

PUBLISHED
Vendor
praydog
Product
REFramework
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24808

Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with program files dcraw.Cc. This issue affects RawTherapee: through 5.11.

PUBLISHED
Vendor
RawTherapee
Product
RawTherapee
Provider severity
HIGH
Conflicts
0

CVE-2026-24807

Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/util modules). This vulnerability is associated with program files SeekableOutputStream.Java. This issue affects quick-media: before v1.0.

PUBLISHED
Vendor
liuyueyi
Product
quick-media
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24806

Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java. This issue affects quick-media: before v1.0.

PUBLISHED
Vendor
liuyueyi
Product
quick-media
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24805

NULL Pointer Dereference vulnerability in visualfc liteide (liteidex/src/3rdparty/libvterm/src modules). This vulnerability is associated with program files screen.C, state.C, vterm.C. This issue affects liteide: before x38.4.

PUBLISHED
Vendor
visualfc
Product
liteide
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24804

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.

PUBLISHED
Vendor
coolsnowwolf
Product
lede
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24803

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7615d/src/mt_wifi/embedded/security modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.

PUBLISHED
Vendor
coolsnowwolf
Product
lede
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24802

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlecode/jsonrpc4j modules). This vulnerability is associated with program files NoCloseOutputStream.Java. This issue affects jsonrpc4j: through 1.6.0.

PUBLISHED
Vendor
briandilley
Product
jsonrpc4j
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24801

Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source modules). This vulnerability is associated with program files ecc_dsa.C. This issue affects IronOS: before v2.23-rc3.

PUBLISHED
Vendor
Ralim
Product
IronOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24800

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules). This vulnerability is associated with program files inflate.C.

PUBLISHED
Vendor
tildearrow
Product
furnace
Provider severity
CRITICAL
Conflicts
1

CVE-2026-2480

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and including, 7.4.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
gn_themes
Product
WP Shortcodes Plugin — Shortcodes Ultimate
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24799

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking dlib (dlib/external/zlib modules). This vulnerability is associated with program files inflate.C. This issue affects dlib: before v19.24.9.

PUBLISHED
Vendor
davisking
Product
dlib
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24798

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C. This issue affects DagorEngine: through dagor_2025_01_15.

PUBLISHED
Vendor
GaijinEntertainment
Product
DagorEngine
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24797

Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program files tjbench.C. This issue affects cupoch.

PUBLISHED
Vendor
neka-nat
Product
cupoch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24796

Out-of-bounds Read vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerability is associated with program files regparse.C. This issue affects CloverBootloader: before 5162.

PUBLISHED
Vendor
CloverHackyColor
Product
CloverBootloader
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24795

Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerability is associated with program files regcomp.C. This issue affects CloverBootloader: before 5162.

PUBLISHED
Vendor
CloverHackyColor
Product
CloverBootloader
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24794

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpowered/impl/world modules). This vulnerability is associated with program files WorldImpl.Java. This issue affects cardboard: before 1.21.4.

PUBLISHED
Vendor
CardboardPowered
Product
cardboard
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24793

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib modules). This vulnerability is associated with program files inflate.C. This issue affects azerothcore-wotlk: through v4.0.0.

PUBLISHED
Vendor
azerothcore
Product
azerothcore-wotlk
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24792

in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.

PUBLISHED
Vendor
OpenHarmony
Product
OpenHarmony
Provider severity
HIGH
Conflicts
0

CVE-2026-24790

The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.

PUBLISHED
Vendor
Welker
Product
OdorEyes EcoSystem Pulse Bypass System with XL4 Controller
Provider severity
HIGH
Conflicts
0

CVE-2026-2479

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host comparison in the `ajax_upload_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application, which can be used to query and modi

PUBLISHED
Vendor
dfactory
Product
Responsive Lightbox & Gallery
Provider severity
MEDIUM
Conflicts
0