Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-24674

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Reflected Cross-Site Scripting (XSS) vulnerability allows remote attackers to execute arbitrary JavaScript in the context of authenticated users by crafting malicious URLs and tricking victims into visiting them. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24673

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited extensions by embedding them inside ZIP archives and extracting them using the application’s built-in decompression functionality. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24672

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated students to inject malicious JavaScript into user profile fields, which is executed when users with viewing privileges access affected application pages. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
HIGH
Conflicts
0

CVE-2026-24671

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated high-privileged users (teachers or administrators) to inject malicious JavaScript into multiple user-controllable input fields across the application, which is executed when other users access affected pages. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24670

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to create new course units, an action normally restricted to higher-privileged roles. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2467

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.0.0 before 5.2.*.

PUBLISHED
Vendor
RTI
Product
Connext Professional
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-24669

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token after it has already been used, enabling unauthorized password changes and potential account takeover. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
HIGH
Conflicts
0

CVE-2026-24668

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to add content to existing course units, an action normally restricted to higher-privileged roles. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24667

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, potentially enabling unauthorized continued access to user accounts. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24666

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multiple teacher-restricted endpoints allows attackers to induce authenticated teachers to perform unintended actions, such as modifying assignment grades, via crafted requests. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24665

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated students to inject malicious JavaScript into uploaded assignment files, which is executed when instructors view the submission. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
HIGH
Conflicts
0

CVE-2026-24664

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a username enumeration vulnerability allows unauthenticated attackers to identify valid user accounts by analyzing differences in the login response behavior. This issue has been patched in version 4.2.

PUBLISHED
Vendor
gunet
Product
openeclass
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24663

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.

PUBLISHED
Vendor
Copeland, Copeland, Copeland
Product
Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Provider severity
CRITICAL
Conflicts
1

CVE-2026-24662

Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file.

PUBLISHED
Vendor
Fujitsu Japan Limited
Product
Musetheque V4 Information Disclosure for IPKNOWLEDGE
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24661

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
LOW
Conflicts
0

CVE-2026-24660

A flaw was found in LibRaw. A remote attacker could exploit a heap-based buffer overflow vulnerability in the x3f_load_huffman functionality by providing a specially crafted malicious file. This can lead to memory corruption, potentially allowing the attacker to execute arbitrary code or cause a denial of service.

PUBLISHED
Vendor
Red Hat, LibRaw, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, LibRaw, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Provider severity
HIGH
Conflicts
3

CVE-2026-2466

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PUBLISHED
Vendor
Unknown
Product
DukaPress
Provider severity
HIGH
Conflicts
1

CVE-2026-24656

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to deserialization of untrusted data, eventually causing DoS. NB: Decanter log socket collector is not installed by default. Users who have not installed Decanter log socket are not impacted by this is

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Karaf
Provider severity
LOW
Conflicts
0

CVE-2026-2465

Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026.

PUBLISHED
Vendor
E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co.
Product
Turboard FOR-S
Provider severity
HIGH
Conflicts
0

CVE-2026-24641

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requests.

PUBLISHED
Vendor
Fortinet
Product
FortiWeb
Provider severity
LOW
Conflicts
0

CVE-2026-24640

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

PUBLISHED
Vendor
Fortinet
Product
FortiWeb
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2464

Path traversal vulnerability in the AMR Printer Management 1.01 Beta web service, which allows remote attackers to read arbitrary files from the underlying Windows system by using specially crafted path traversal sequences in requests directed to the web management service. The service is accessible without authentication and runs with elevated privileges, amplifying the impact of the vulnerability. An attacker can exploit this condition to access sensitive and privileged files on the system usi

PUBLISHED
Vendor
AMR
Product
AMR Printer Management Beta web service
Provider severity
HIGH
Conflicts
0

CVE-2026-24639

Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

PUBLISHED
Vendor
Ronald Huereca
Product
Photo Block
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24638

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

PUBLISHED
Vendor
Webful Creations
Product
RepairBuddy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24637

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

PUBLISHED
Vendor
Blubrry Podcasting
Product
PowerPress Podcasting
Provider severity
HIGH
Conflicts
0

CVE-2026-24636

Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sugar Calendar (Lite): from n/a through <= 3.9.1.

PUBLISHED
Vendor
Syed Balkhi
Product
Sugar Calendar (Lite)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24635

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edublink-core allows PHP Local File Inclusion.This issue affects EduBlink Core: from n/a through <= 2.0.7.

PUBLISHED
Vendor
DevsBlink
Product
EduBlink Core
Provider severity
HIGH
Conflicts
0

CVE-2026-24634

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16.

PUBLISHED
Vendor
Rustaurius
Product
Ultimate Reviews
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24633

Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Expires Headers & Optimized Minify: from n/a through <= 3.2.0.

PUBLISHED
Vendor
Passionate Brains
Product
Add Expires Headers & Optimized Minify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24632

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jagdish1o1 Delay Redirects delay-redirects allows DOM-Based XSS.This issue affects Delay Redirects: from n/a through <= 1.0.0.

PUBLISHED
Vendor
jagdish1o1
Product
Delay Redirects
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24631

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rosebud: from n/a through <= 1.4.

PUBLISHED
Vendor
Mikado-Themes
Product
Rosebud
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24630

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Design Stylish Cost Calculator stylish-cost-calculator allows Stored XSS.This issue affects Stylish Cost Calculator: from n/a through <= 8.2.9.

PUBLISHED
Vendor
Design
Product
Stylish Cost Calculator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2463

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24629

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Stored XSS.This issue affects Web Accessibility with Max Access: from n/a through <= 2.1.0.

PUBLISHED
Vendor
Ability, Inc
Product
Web Accessibility with Max Access
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24628

Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.

PUBLISHED
Vendor
Supsystic
Product
Photo Gallery by Supsystic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24627

Missing Authorization vulnerability in Trusona Trusona for WordPress trusona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trusona for WordPress: from n/a through <= 2.0.0.

PUBLISHED
Vendor
Trusona
Product
Trusona for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24626

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Logo Slider logo-slider-wp allows Stored XSS.This issue affects Logo Slider: from n/a through <= 5.1.1.

PUBLISHED
Vendor
LogicHunt
Product
Logo Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24625

Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3.

PUBLISHED
Vendor
Imaginate Solutions
Product
File Uploads Addon for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24624

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL Injection.This issue affects Neoforum: from n/a through <= 1.0.

PUBLISHED
Vendor
saeros1984
Product
Neoforum
Provider severity
HIGH
Conflicts
0

CVE-2026-24623

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saeros1984 Neoforum neoforum allows Reflected XSS.This issue affects Neoforum: from n/a through <= 1.0.

PUBLISHED
Vendor
saeros1984
Product
Neoforum
Provider severity
HIGH
Conflicts
0

CVE-2026-24622

Missing Authorization vulnerability in Sergiy Dzysyak Suggestion Toolkit suggestion-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Suggestion Toolkit: from n/a through <= 5.0.

PUBLISHED
Vendor
Sergiy Dzysyak
Product
Suggestion Toolkit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24621

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Statsenko Terms descriptions terms-descriptions allows DOM-Based XSS.This issue affects Terms descriptions: from n/a through <= 3.4.9.

PUBLISHED
Vendor
Vladimir Statsenko
Product
Terms descriptions
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue affects Landing Page Builder: from n/a through <= 1.5.3.4.

PUBLISHED
Vendor
PluginOps
Product
Landing Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2462

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24619

Missing Authorization vulnerability in PopCash PopCash.Net Code Integration Tool popcashnet-code-integration-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PopCash.Net Code Integration Tool: from n/a through <= 1.8.

PUBLISHED
Vendor
PopCash
Product
PopCash.Net Code Integration Tool
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24618

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.

PUBLISHED
Vendor
HashThemes
Product
Hash Elements
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24617

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Easy Modal easy-modal allows Stored XSS.This issue affects Easy Modal: from n/a through <= 2.1.0.

PUBLISHED
Vendor
Daniel Iser
Product
Easy Modal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24616

Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Popups: from n/a through <= 2.2.0.5.

PUBLISHED
Vendor
Damian
Product
WP Popups
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24615

Missing Authorization vulnerability in themebeez Cream Magazine cream-magazine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cream Magazine: from n/a through <= 2.1.10.

PUBLISHED
Vendor
themebeez
Product
Cream Magazine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24614

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.10.

PUBLISHED
Vendor
Devsbrain
Product
Flex QR Code Generator
Provider severity
MEDIUM
Conflicts
0