Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-6649

A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Qibo
Product
CMS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-66489

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66488

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

PUBLISHED
Vendor
balbooa.com
Product
Gridbox extension for Joomla
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6648

A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Qibo
Product
CMS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-66477

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

PUBLISHED
Vendor
Shufflehound
Product
Gillion
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66476

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

PUBLISHED
Vendor
Syed Balkhi
Product
Easy Digital Downloads
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66475

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

PUBLISHED
Vendor
acowebs
Product
Checkout Field Editor for WooCommerce &#8211; Checkout Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66474

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

PUBLISHED
Vendor
HT Plugins
Product
Insert Headers and Footers Code – HT Script
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66473

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

PUBLISHED
Vendor
Xendit
Product
Xendit Payment
Provider severity
HIGH
Conflicts
0

CVE-2026-6646

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitization and output escaping on the 'title' component of the 'link' shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
Dream-Theme
Product
The7 — Website and eCommerce Builder for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6645

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executabl

PUBLISHED
Vendor
PaperCut
Product
Print Deploy
Provider severity
HIGH
Conflicts
0

CVE-2026-66448

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

PUBLISHED
Vendor
WP Chill
Product
Gallery PhotoBlocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66445

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

PUBLISHED
Vendor
100plugins
Product
Open User Map
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66442

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

PUBLISHED
Vendor
YayCommerce
Product
YayPricing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6644

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the restricted web environment and execute arbitrary code on the underlying operating system. This occurs due to insufficient validation of user-supplied input before it is passed to a system shell. Successful exploitation allows an attacker to achieve Remote Code Execution (RCE) and fully compromise the system. Affected products and versions include: fr

PUBLISHED
Vendor
ASUSTOR Inc.
Product
ADM
Provider severity
CRITICAL
Conflicts
0

CVE-2026-66438

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

PUBLISHED
Vendor
Tim Strifler
Product
Exclusive Addons Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66437

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

PUBLISHED
Vendor
Themeisle
Product
Feedzy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66434

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

PUBLISHED
Vendor
Sayontan Sinha
Product
Photonic Gallery & Lightbox for Flickr, SmugMug & Others
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66433

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

PUBLISHED
Vendor
ShapedPlugin LLC
Product
Location Weather
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6643

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing user-controlled data directly to printf(). Due to the lack of PIE and Stack Canary protections, an authenticated remote attacker can exploit these to execute arbitrary code as the web server user. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RR42 as well as from ADM 5.0.0 through ADM 5.1.2.REO1.

PUBLISHED
Vendor
ASUSTOR Inc.
Product
ADM
Provider severity
HIGH
Conflicts
0

CVE-2026-66428

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

PUBLISHED
Vendor
jgwhite33
Product
WP Google Review Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-66427

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.

PUBLISHED
Vendor
jgwhite33
Product
WP Google Review Slider
Provider severity
HIGH
Conflicts
0

CVE-2026-66421

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute within the 60-character rendering budget, which is stored in the session transcript and interpolated uns

PUBLISHED
Vendor
tugcantopaloglu
Product
openclaw-dashboard
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-66420

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used

PUBLISHED
Vendor
Ylianst
Product
MeshCentral
Provider severity
HIGH
Conflicts
1

CVE-2026-66418

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to exe

PUBLISHED
Vendor
tugcantopaloglu
Product
openclaw-dashboard
Provider severity
CRITICAL
Conflicts
1

CVE-2026-66416

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, PUT, and DELETE requests that create or delete projects, modify settings, and change permissions as a

PUBLISHED
Vendor
Leantime
Product
Leantime
Provider severity
HIGH
Conflicts
1

CVE-2026-66415

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC API endpoint to access cloud metadata services or read arbitrary files from the server filesystem.

PUBLISHED
Vendor
Leantime
Product
Leantime
Provider severity
HIGH
Conflicts
1

CVE-2026-66414

Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to redirect authenticated users to arbitrary external sites by manipulating the redirectUrl POST parameter. Attackers can craft a malicious login URL with a tampered redirectUrl value that bypasses FILTER_SANITIZE_URL validation to redirect victims to attacker-controlled sites for phishing or credential theft.

PUBLISHED
Vendor
Leantime
Product
Leantime
Provider severity
MEDIUM
Conflicts
1

CVE-2026-66412

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMilestone JSON-RPC endpoint. Attackers can enumerate integer milestone IDs through the JSON-RPC API to access project planning information, milestone titles, descriptions, and timelines across all projects on the instance regardless of project membership.

PUBLISHED
Vendor
Leantime
Product
Leantime
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-66402

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. 'victim.example\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
CRITICAL
Conflicts
1

CVE-2026-66401

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
LOW
Conflicts
1

CVE-2026-66400

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.

PUBLISHED
Vendor
getgrav
Product
grav
Provider severity
MEDIUM
Conflicts
1

CVE-2026-66399

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to pre-existing groups holding user-management rights and immediately inherit those permissions to modify or delete user accounts.

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-66398

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a malicious ZIP file as an attachment, point the updater configuration to its stored path, and extract it into the application root to achieve code execution as the web server user.

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
CRITICAL
Conflicts
0

CVE-2026-66397

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
HIGH
Conflicts
0

CVE-2026-66396

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-66395

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
CRITICAL
Conflicts
1

CVE-2026-66394

SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, enabling script execution in the application origin.

PUBLISHED
Vendor
siyuan-note
Product
siyuan
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-66391

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Wicket
Provider severity
MEDIUM
Conflicts
1

CVE-2026-66390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Wicket
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

PUBLISHED
Vendor
n/a
Product
PostgreSQL
Provider severity
LOW
Conflicts
0

CVE-2026-66374

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

PUBLISHED
Vendor
nic
Product
Knot Resolver
Provider severity
HIGH
Conflicts
0

CVE-2026-66373

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

PUBLISHED
Vendor
Redis
Product
Redis
Provider severity
HIGH
Conflicts
0

CVE-2026-6637

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Vers

PUBLISHED
Vendor
n/a
Product
PostgreSQL
Provider severity
HIGH
Conflicts
1

CVE-2026-66369

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly, resulting in a heap out-of-bounds read. On affected platforms, this condition reliably terminates the subscriber process and causes a denial-of-service.

PUBLISHED
Vendor
MZ Automation GmbH
Product
libiec61850
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-66364

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte. This out-of-bounds read reliably terminates the subscriber process, resulting in a denial-of-service condition.

PUBLISHED
Vendor
MZ Automation GmbH
Product
libiec61850
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-66360

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap over read. This condition occurs before MMS session establishment, a crafted TCP/102 connection attempt can trigger the issue. The resulting over read causes the process to terminate, leading to a denial of service con

PUBLISHED
Vendor
MZ Automation GmbH
Product
libiec61850
Provider severity
HIGH
Conflicts
1

CVE-2026-6636

A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the component API. Performing a manipulation of the argument pathname results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The

PUBLISHED
Vendor
p2r3
Product
convert
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6635

A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the component tools_webhook. Such manipulation of the argument X-Tools-JWE leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
rowboatlabs
Product
rowboat
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-66349

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing bounds check. This results in a one byte heap out-of-bounds read and causes the MMS service process to terminate, leading to a denial-of-service condition.

PUBLISHED
Vendor
MZ Automation GmbH
Product
libiec61850
Provider severity
MEDIUM
Conflicts
1