Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-24352

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not test

PUBLISHED
Vendor
PluXml
Product
PluXml CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24351

PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

PUBLISHED
Vendor
PluXml
Product
PluXml CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24350

PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the uploaded image. In version 5.9.0-rc7 clicking the link associated with the uploaded image doesn't execute malicious code but directly accessing the file will still execute the embedded payload. The vendor was notified early about this vulnerability, but didn't respond with

PUBLISHED
Vendor
PluXml
Product
PluXml CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2435

Tanium addressed a SQL injection vulnerability in Asset.

PUBLISHED
Vendor
Tanium
Product
Asset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24349

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive informati

PUBLISHED
Vendor
Siemens, Siemens, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC WinCC Unified PC Runtime V18, SIMATIC WinCC Unified PC Runtime V21, SIMATIC WinCC Unified PC Runtime V16, SIMATIC WinCC Unified PC Runtime V19, SIMATIC WinCC Unified PC Runtime V20, SIMATIC WinCC Unified PC Runtime V17
Provider severity
HIGH
Conflicts
2

CVE-2026-24348

Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execute arbitrary JavaScript code in the browser of other Admin UI users.

PUBLISHED
Vendor
EZCast
Product
EZCast Pro II
Provider severity
HIGH
Conflicts
0

CVE-2026-24347

Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /tmp directory

PUBLISHED
Vendor
EZCast
Product
EZCast Pro II
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24346

Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application

PUBLISHED
Vendor
EZCast
Product
EZCast Pro II
Provider severity
HIGH
Conflicts
0

CVE-2026-24345

Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

PUBLISHED
Vendor
EZCast
Product
EZCast Pro II
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24344

Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and potential remote code execution

PUBLISHED
Vendor
EZCast
Product
EZCast Pro II
Provider severity
HIGH
Conflicts
0

CVE-2026-24343

Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HertzBeat
Provider severity
HIGH
Conflicts
0

CVE-2026-2434

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
poporon
Product
Pz-LinkCard
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24332

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."

PUBLISHED
Vendor
Discord
Product
WebSocket API service
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2433

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, 5.0.11. This is due to the plugin's admin-shell.js registering a global message event listener without origin validation (missing event.origin check) and directly passing user-controlled URLs to window.open() without URL scheme validation. This makes it possible for unauthenticated attackers to execu

PUBLISHED
Vendor
rebelcode
Product
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24328

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
Business Server Pages Application (TAF_APPLAUNCHER)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24327

Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages), an authenticated attacker could access information that they are otherwise unauthorized to view. This leads to low impact on confidentiality and no effect on integrity or availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24326

Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP S/4HANA Defense & Security (Disconnected Operations)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24325

SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an admin user to inject malicious JavaScript into a website and the injected script gets executed when the user visits the compromised page.This vulnerability has low impact on confidentiality and integrity of the data. There is no impact on the availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP BusinessObjects Enterprise (Central Management Console)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24324

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause the Content Management Server (CMS) to crash, rendering the CMS partially or completely unavailable and resulting in the denial of service of the Content Management Server (CMS). Successful exploitation impacts system availability, while confidentiality and integrity remain unaffected.

PUBLISHED
Vendor
SAP_SE
Product
SAP BusinessObjects Business Intelligence Platform (AdminTools)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24323

The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no impact on the availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP Document Management System
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24322

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity or availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Solution Tools Plug-In (ST-PI)
Provider severity
HIGH
Conflicts
0

CVE-2026-24321

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Commerce Cloud
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24320

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver and ABAP Platform (Application Server ABAP)
Provider severity
LOW
Conflicts
0

CVE-2026-2432

The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installati

PUBLISHED
Vendor
creativemindssolutions
Product
CM Custom Reports – Flexible reporting to track what matters most
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24319

In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gaining access to this information could potentially lead to unauthorized operations within the B1 environment, including modification of company data. This issue results in a high impact on confidentiality and integrity, with no impact on availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Business One (B1 Client Memory Dump Files)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24318

Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after authentication, the attacker could assume the victim�s authenticated context. This could allow the attacker to access or modify information within the victim�s session scope, impacting confident

PUBLISHED
Vendor
SAP_SE
Product
SAP BusinessObjects Business Intelligence Platform
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24317

SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided GuiXT is enabled. This vulnerability has a low impact on confidentiality, integrity, and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP GUI for Windows with active GuiXT
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24316

SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP requests to arbitrary internal or external endpoints. The report is therefore vulnerable to Server-Side Request Forgery (SSRF). Successful exploitation could lead to interaction with potentially sensitive internal endpoints, resulting in a low impact on data confidentiality and integrity. There is no impact on availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver Application Server for ABAP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24315

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori (launchpad)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24314

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality of the application while integrity and availability are not impacted.

PUBLISHED
Vendor
SAP_SE
Product
S/4HANA (Manage Payment Media)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24313

SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Solution Tools Plug-In (ST-PI)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24312

An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative user can bypass role restrictions by leveraging permissions from a less sensitive function to execute unauthorized, high-privilege actions. This has a high impact on data integrity, with low impact on confidentiality and no impact on availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP Business Workflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24311

The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation. Such changes could affect system behaviour during startup, resulting in a high impact on the application's confidentiality and integrity, with a low impact on availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Customer Checkout 2.0
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24310

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidentiality with no effect on the integrity and availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver Application Server for ABAP
Provider severity
LOW
Conflicts
0

CVE-2026-2431

The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PUBLISHED
Vendor
creativemindssolutions
Product
CM Custom Reports – Flexible reporting to track what matters most
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24309

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced system performance or interruptions. The vulnerability has low impact on the application's integrity and availability, with no effect on confidentiality.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver Application Server for ABAP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24308

A flaw was found in Apache ZooKeeper. Improper handling of configuration values in ZKConfig allows an attacker to expose sensitive information. This occurs when sensitive client configuration values are logged at an INFO level in the client's logfile. This vulnerability can lead to information disclosure, potentially revealing critical system details to unauthorized parties.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat JBoss Enterprise Application Platform 7, Red Hat AMQ Broker 7.12.7, streams for Apache Kafka 3, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat Fuse 7, Streams for Apache Kafka 2.9.4, Apache ZooKeeper, Red Hat build of Apache Camel for Spring Boot 4, Red Hat OpenShift AI 2.25, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift AI (RHOAI), Red Hat AMQ Broker 7.13.5, Red Hat Offline Knowledge Portal, Red Hat build of Debezium 3, Red Hat build of Debezium 2, Red Hat AMQ Broker 7.14.0
Provider severity
LOW, MEDIUM
Conflicts
3

CVE-2026-24307

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Front Door
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Microsoft Entra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Resource Manager
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Partner Center
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24302

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure ARC
Provider severity
HIGH
Conflicts
0

CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Azure Front Door
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2430

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing in all versions up to, and including, 3.1.14. This is due to the use of an overly permissive regular expression in the `add_lazyload` function that replaces all occurrences of `\ssrc=` in image tags without limiting to the actual attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that

PUBLISHED
Vendor
optimizingmatters
Product
Autoptimize
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24299

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24297

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2012, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows Server 2012 R2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-24296

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2012 R2, Windows 11 version 22H3, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows 10 Version 1607, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-24295

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 22H3, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2025
Provider severity
HIGH
Conflicts
2

CVE-2026-24294

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 22H2, Windows Server 2025, Windows 11 Version 23H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2012 R2, Windows 11 version 22H3, Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2022, Windows 11 version 26H1, Windows Server 2016, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012 (Server Core installation)
Provider severity
HIGH
Conflicts
1