Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-22910

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

PUBLISHED
Vendor
SICK AG
Product
TDC-X401GL
Provider severity
HIGH
Conflicts
0

CVE-2026-2291

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.

PUBLISHED
Vendor
dnsmasq
Product
dnsmasq
Provider severity
HIGH
Conflicts
0

CVE-2026-22909

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

PUBLISHED
Vendor
SICK AG
Product
TDC-X401GL
Provider severity
HIGH
Conflicts
0

CVE-2026-22908

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

PUBLISHED
Vendor
SICK AG
Product
TDC-X401GL
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22907

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

PUBLISHED
Vendor
SICK AG
Product
TDC-X401GL
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22906

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.

PUBLISHED
Vendor
WAGO, WAGO, WAGO, WAGO
Product
0852-1328, 0852-1322, 0852-1322, 0852-1328
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22905

An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/../cgi-bin/post.cgi), gaining unauthorized access to protected CGI endpoints and configuration downloads.

PUBLISHED
Vendor
WAGO, WAGO, WAGO, WAGO
Product
0852-1322, 0852-1328, 0852-1328, 0852-1322
Provider severity
HIGH
Conflicts
1

CVE-2026-22904

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

PUBLISHED
Vendor
WAGO, WAGO, WAGO, WAGO
Product
0852-1322, 0852-1328, 0852-1322, 0852-1328
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22903

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

PUBLISHED
Vendor
WAGO, WAGO, WAGO, WAGO
Product
0852-1322, 0852-1328, 0852-1328, 0852-1322
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22902

A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuNetSwitch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22901

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuNetSwitch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22900

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuNetSwitch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2290

The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.28.0. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to initiate arbitrary outbound requests from the application and read the returned response content. Successful exploitation was confirmed by receiving and observing response data from an external Collaborator endpoint.

PUBLISHED
Vendor
jurajsim
Product
Post Affiliate Pro
Provider severity
LOW
Conflicts
0

CVE-2026-22899

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
File Station 5
Provider severity
LOW
Conflicts
0

CVE-2026-22898

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QVR Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22897

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuNetSwitch
Provider severity
HIGH
Conflicts
0

CVE-2026-22895

A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuFTP Service 1.4.3 and later QuFTP Service 1.5.2 and later QuFTP Service 1.6.2 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuFTP Service
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22894

A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
File Station 5
Provider severity
LOW
Conflicts
0

CVE-2026-22893

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

PUBLISHED
Vendor
QNAP Systems Inc., QNAP Systems Inc.
Product
QTS, QuTS hero
Provider severity
HIGH
Conflicts
1

CVE-2026-22892

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22891

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

PUBLISHED
Vendor
The Biosig Project
Product
libbiosig
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22890

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

PUBLISHED
Vendor
EV2GO
Product
ev2go.io
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2289

The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been d

PUBLISHED
Vendor
taskbuilder
Product
Taskbuilder – Project Management & Task Management Tool With Kanban Board
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22888

Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.

PUBLISHED
Vendor
Cybozu, Inc.
Product
Cybozu Garoon
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22886

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to accept the default password indefinitely without warning or enforcement. In real-world deployments, this service is often left enabled without changing the default credentials. As a result, a remot

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse OpenMQ
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22885

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.

PUBLISHED
Vendor
EnOcean Edge Inc
Product
SmartServer IoT
Provider severity
LOW
Conflicts
0

CVE-2026-22882

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

PUBLISHED
Vendor
Canva
Product
Affinity
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22881

Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.

PUBLISHED
Vendor
Cybozu, Inc.
Product
Cybozu Garoon
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22880

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2288

The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has b

PUBLISHED
Vendor
silvercover
Product
myLinksDump
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22879

vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

PUBLISHED
Vendor
vtk
Product
vtk
Provider severity
HIGH
Conflicts
0

CVE-2026-22878

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

PUBLISHED
Vendor
Mobility46
Product
mobility46.se
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22877

An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.

PUBLISHED
Vendor
Copeland, Copeland, Copeland
Product
Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Provider severity
LOW
Conflicts
1

CVE-2026-22876

Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vulnerability is exploited, arbitrary files on the affected product may be retrieved by a logged-in user with the low("monitoring user") or higher privilege.

PUBLISHED
Vendor
TOA Corporation
Product
Multiple Network Cameras TRIFORA 3 series
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-22875

Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

PUBLISHED
Vendor
Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd.
Product
Movable Type Premium (Advanced Edition) (Software Edition), Movable Type Premium (Cloud Edition), Movable Type Advanced (Software Edition), Movable Type (Software Edition), Movable Type (Cloud Edition), Movable Type Premium (Software Edition)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22874

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22872

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for cluster-scoped resources. Prior to version 0.13.0, tenant administrators can leverage the Controller's elevated privileges to create cluster-scoped resources (such as ClusterRole and ValidatingWebhookConfiguration) that they cannot create directly, achieving cross

PUBLISHED
Vendor
projectcapsule
Product
capsule
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22871

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract() function that allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Overwrite and Remote Code Execution on systems running GuardDog. This vulnerability is fixed in 2.7.1.

PUBLISHED
Vendor
DataDog
Product
guarddog
Provider severity
HIGH
Conflicts
0

CVE-2026-22870

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space from a few megabytes of compressed data. This vulnerability is fixed in 2.7.1.

PUBLISHED
Vendor
DataDog
Product
guarddog
Provider severity
HIGH
Conflicts
0

CVE-2026-2287

CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

PUBLISHED
Vendor
CrewAI
Product
CrewAI
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22869

Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted PR code. An attacker can exploit this to steal credentials, post comments, push code, or create releases.

PUBLISHED
Vendor
eigent-ai
Product
eigent
Provider severity
HIGH
Conflicts
0

CVE-2026-22868

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.

PUBLISHED
Vendor
ethereum
Product
go-ethereum
Provider severity
HIGH
Conflicts
0

CVE-2026-22867

LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacker with document editing privileges can inject a malicious javascript: URL that executes arbitrary code when other users click on the link. This vulnerability is fixed in 4.4.0.

PUBLISHED
Vendor
suitenumerique
Product
docs
Provider severity
HIGH
Conflicts
0

CVE-2026-22866

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only check if the last 32 (or 20) bytes of the decrypted signature match the expected hash. This enables Bleichenbacher's 2006 signature forgery attack against DNS zones using RSA keys with low public expon

PUBLISHED
Vendor
ensdomains
Product
ens-contracts
Provider severity
LOW
Conflicts
0

CVE-2026-22865

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would continue to the next repository in the list and potentially resolve dependencies from a different repository. An exception like NoHttpResponseException can indicate transient errors.

PUBLISHED
Vendor
gradle
Product
gradle
Provider severity
HIGH
Conflicts
1

CVE-2026-22864

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, .Bat, etc.). This vulnerability is fixed in 2.5.6.

PUBLISHED
Vendor
denoland
Product
deno
Provider severity
HIGH
Conflicts
0

CVE-2026-22863

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secrets. This vulnerability is fixed in 2.6.0.

PUBLISHED
Vendor
denoland
Product
deno
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22862

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.

PUBLISHED
Vendor
ethereum
Product
go-ethereum
Provider severity
HIGH
Conflicts
0

CVE-2026-22861

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Prior to 2.3.1.2, There is a heap-based buffer overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. The vulnerability is fixed in 2.3.1.2.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, rack, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, rack, Red Hat Enterprise Linux 8, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2
Provider severity
HIGH
Conflicts
2