Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-23699

AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exploited, arbitrary commands may be executed on the devices.

PUBLISHED
Vendor
Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd., Ruijie Networks Co., Ltd.
Product
AP180-PE V2.xx, AP180-AC V1.xx, AP180-AC V2.xx, AP180(JA) V1.xx, AP180(JP) V1.xx, AP180-PE V3.xx, AP180-AC V3.xx, AP180-PE V1.xx, AP180(JA) V2.xx
Provider severity
HIGH
Conflicts
2

CVE-2026-23698

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the modules/ directory under the web root without validating file types beyond the manifest.xml descriptor. Attackers can place executable PHP files in the modules/ directory that become di

PUBLISHED
Vendor
Vtiger
Product
Vtiger CRM
Provider severity
HIGH
Conflicts
1

CVE-2026-23697

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apach

PUBLISHED
Vendor
Vtiger
Product
Vtiger CRM
Provider severity
HIGH
Conflicts
1

CVE-2026-23696

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints.

PUBLISHED
Vendor
Windmill Labs, Windmill Labs
Product
Windmill EE (Enterprise Edition), Windmill CE (Community Edition)
Provider severity
CRITICAL
Conflicts
2

CVE-2026-23695

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive without sanitization. An attacker with content/:models/manage permission can inject arbitrary JavaScript into the Display template, which executes in the browser of any user viewing the collection items lis

PUBLISHED
Vendor
Cockpit-HQ
Product
Cockpit
Provider severity
MEDIUM
Conflicts
1

CVE-2026-23694

Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affecting multiple administrative AJAX actions. The handlers for ahsc_reset_options, ahsc_debug_status, and ahsc_enable_purge perform authentication and capability checks but do not verify a WordPress nonce for state-changing requests. An attacker can induce a logged-in administrator to visit a malicious webpage that submits forged requests to admin-ajax.ph

PUBLISHED
Vendor
Aruba.it
Product
Aruba HiSpeed Cache
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23693

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open prox

PUBLISHED
Vendor
Roxnor
Product
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
Provider severity
CRITICAL
Conflicts
1

CVE-2026-2369

A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-23689

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality a

PUBLISHED
Vendor
SAP_SE
Product
SAP Supply Chain Management
Provider severity
HIGH
Conflicts
0

CVE-2026-23688

SAP Fiori App Manage Service Entry Sheets does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on integrity, confidentiality and availability are not impacted.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori App (Manage Service Entry Sheets - Lean Services)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23687

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver AS ABAP and ABAP Platform
Provider severity
HIGH
Conflicts
0

CVE-2026-23686

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configuration, allowing manipulation of application-controlled settings. Successful exploitation leads to a low impact on integrity, while confidentiality and availability remain unaffected.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver Application Server Java
Provider severity
LOW
Conflicts
0

CVE-2026-23685

Due to a Deserialization vulnerability in SAP NetWeaver (JMS service), an attacker authenticated as an administrator with local access could submit specially crafted content to the server. If processed by the application, this content could trigger unintended behavior during internal logic execution, potentially causing a denial of service. Successful exploitation results in a high impact on availability, while confidentiality and integrity remain unaffected.

PUBLISHED
Vendor
SAP_SE
Product
SAP NetWeaver (JMS service)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23684

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact on data integrity, with no impact on data confidentiality or availability of the application.

PUBLISHED
Vendor
SAP_SE
Product
SAP Commerce Cloud
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23683

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.

PUBLISHED
Vendor
SAP_SE
Product
SAP Fiori App (Intercompany Balance Reconciliation)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23681

Due to missing authorization check in a function module in SAP Support Tools Plug-In, an authenticated attacker could invoke specific function modules to retrieve information about the system and its configuration. This disclosure of the system information could assist the attacker to plan subsequent attacks. This vulnerability has a low impact on the confidentiality of the application, with no effect on its integrity or availability.

PUBLISHED
Vendor
SAP_SE
Product
SAP Support Tools Plug-In
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2368

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.

PUBLISHED
Vendor
Lenovo, Lenovo
Product
FileZ, FileZ
Provider severity
HIGH
Conflicts
2

CVE-2026-23679

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_ge

PUBLISHED
Vendor
libusb
Product
libusb
Provider severity
MEDIUM
Conflicts
1

CVE-2026-23678

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an authenticated attacker with access to the web interface can execute arbitrary CLI commands on the device.

PUBLISHED
Vendor
Binardat Ltd.
Product
10G08-0800GSM Network Switch
Provider severity
HIGH
Conflicts
1

CVE-2026-23674

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012, Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2022, Windows Server 2025, Windows Server 2012 R2, Windows Server 2016, Windows 11 version 26H1, Windows 11 version 22H3
Provider severity
HIGH
Conflicts
1

CVE-2026-23673

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 (Server Core installation), Windows Server 2019 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 10 Version 1607, Windows Server 2019, Windows Server 2012, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-23672

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows 11 Version 25H2, Windows 10 Version 1607, Windows Server 2012 R2, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2012
Provider severity
HIGH
Conflicts
1

CVE-2026-23671

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2016, Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows 10 Version 21H2, Windows Server 2025, Windows 10 Version 1809, Windows 10 Version 1607, Windows Server 2025 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 25H2, Windows Server 2022
Provider severity
HIGH
Conflicts
2

CVE-2026-23670

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows Server 2016, Windows 10 Version 22H2, Windows Server 2022, Windows 10 Version 1809, Windows 11 Version 23H2, Windows 11 version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2019, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1607
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2367

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
ays-pro
Product
Secure Copy Content Protection and Content Locking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23669

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2012 R2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2025, Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows 10 Version 21H2, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2022, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-23668

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 (Server Core installation), Windows 10 Version 22H2, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows Server 2012 R2, Windows Server 2012, Windows 10 Version 1809, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-23667

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 11 version 26H1, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2026-23666

A flaw was found in .NET Framework. An unauthorized attacker can exploit a race condition, which is a concurrent execution using shared resources with improper synchronization, to deny service over a network. This vulnerability can lead to a Denial of Service (DoS) for affected systems.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Red Hat, Red Hat, Microsoft, Red Hat, Microsoft, Microsoft, Red Hat, Microsoft, Red Hat, Microsoft, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Microsoft .NET Framework 4.8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Microsoft .NET Framework 3.5 AND 4.8, Red Hat Hardened Images, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Red Hat Hardened Images, Microsoft .NET Framework 3.5 AND 4.7.2, Red Hat Enterprise Linux 8, Microsoft .NET Framework 3.5 AND 4.8.1, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
3

CVE-2026-23665

Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Linux Virtual Machines with Azure Diagnostics extension
Provider severity
HIGH
Conflicts
0

CVE-2026-23664

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure IoT Explorer
Provider severity
HIGH
Conflicts
0

CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Global Secure Access (GSA)
Provider severity
HIGH
Conflicts
0

CVE-2026-23662

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure IoT Explorer
Provider severity
HIGH
Conflicts
1

CVE-2026-23661

Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure IoT Explorer
Provider severity
HIGH
Conflicts
0

CVE-2026-23660

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center in Azure Portal
Provider severity
HIGH
Conflicts
0

CVE-2026-2366

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim's unique identifier (UUID) and the Organizations feature is enabled.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.11, Red Hat build of Keycloak 26.4
Provider severity
LOW
Conflicts
1

CVE-2026-23659

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Data Factory
Provider severity
HIGH
Conflicts
0

CVE-2026-23658

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure DevOps: msazure
Provider severity
HIGH
Conflicts
0

CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft
Product
Microsoft Office LTSC 2024, Microsoft 365 Apps for Enterprise
Provider severity
HIGH
Conflicts
1

CVE-2026-23656

Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows App Client for Windows Desktop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23655

Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft ACI Confidential Containers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23654

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
GitHub Repo: Zero Shot scFoundation
Provider severity
HIGH
Conflicts
0

CVE-2026-23653

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Visual Studio Code CoPilot Chat Extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Power Pages
Provider severity
CRITICAL
Conflicts
0

CVE-2026-23651

Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft ACI Confidential Containers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2365

The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_save_data` AJAX action in all versions up to, and including, 6.1.17. This is due to the draft form submission endpoint being publicly accessible without authentication or nonce verification, combined with insufficient input sanitization and output escaping of form field data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex

PUBLISHED
Vendor
techjewel
Product
Fluent Forms Pro Add On Pack
Provider severity
HIGH
Conflicts
0

CVE-2026-23648

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can replace or modify these binaries to execute arbitrary commands with root privileges, enabling local privilege escalation.

PUBLISHED
Vendor
Glory Global Solutions
Product
RBG-100
Provider severity
HIGH
Conflicts
1

CVE-2026-23647

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using these credentials and gain unauthorized access to the system. Successful exploitation allows remote acces

PUBLISHED
Vendor
Glory Global Solutions
Product
RBG-100
Provider severity
CRITICAL
Conflicts
1

CVE-2026-23646

OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not properly checked if the session belongs to the user. As the ID that is used to identify these session objects use incremental integers, users could iterate requests using `DELETE /my/sessions/:id` and thus unauthenticate other users. Users did not h

PUBLISHED
Vendor
opf
Product
openproject
Provider severity
MEDIUM
Conflicts
0

CVE-2026-23645

SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views a malicious SVG file (e.g., imported from an untrusted source), arbitrary JavaScript code is executed in the context of their authenticated session. This vulnerability is fixed in 3.5.4-dev2.

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
MEDIUM
Conflicts
0