Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-2286

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

PUBLISHED
Vendor
CrewAI
Product
CrewAI
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22859

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, FreeRDP, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8, FreeRDP, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-22858

A global buffer overflow flaw has been discovered in FreeRDP. This global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, FreeRDP, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 10, FreeRDP, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-22857

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22856

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22855

A heap based buffer overflow has been discovered in FreeRDP. This heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, FreeRDP, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, FreeRDP, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-22854

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memory. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22853

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, FreeRDP, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, FreeRDP, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-22852

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, causing memory corruption and a crash. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22851

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is fixed in 3.20.1.

PUBLISHED
Vendor
FreeRDP
Product
FreeRDP
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22850

Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped analytics export/import and permissive admin SQL import. Unauthenticated visitors can submit arbitrary path (`pa`) and referrer (`r`) values to the public tracking endpoint in src/Resources/functions/collect.php, which stores those strings verbatim in the analytics tables. The admin export logic in src/Admin/Data_Export.php writes these stored value

PUBLISHED
Vendor
ibericode
Product
koko-analytics
Provider severity
HIGH
Conflicts
0

CVE-2026-2285

CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.

PUBLISHED
Vendor
CrewAI
Product
CrewAI
Provider severity
HIGH
Conflicts
0

CVE-2026-22849

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors to perform stored XSS attacks on dashboards and storefronts. Malicious staff members could craft script injections to target other staff members, possibly stealing their access and/or refresh tokens. This issue has been patched in versions 3.22.27, 3

PUBLISHED
Vendor
saleor
Product
saleor
Provider severity
HIGH
Conflicts
0

CVE-2026-22844

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

PUBLISHED
Vendor
Zoom Communications Inc.
Product
Zoom Node
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2284

The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.8. This is due to a missing capability check and nonce verification on the 'ne_clean_data' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to truncate 8 core WordPress database tables (posts, comments, terms, term_relationships, term_taxonomy, postmeta, commentmeta, termmeta) and delete the entire W

PUBLISHED
Vendor
webangon
Product
News Element Elementor Blog Magazine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22828

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation

PUBLISHED
Vendor
Fortinet, Fortinet
Product
FortiManager Cloud, FortiAnalyzer Cloud
Provider severity
HIGH
Conflicts
1

CVE-2026-22822

A flaw was found in the External Secrets Operator. A user with appropriate permissions could exploit a vulnerability in the `getSecretKey` template function. This function allowed secrets, which are sensitive pieces of information like passwords or API keys, to be retrieved from other isolated environments (known as namespaces) within OpenShift Container Platform, bypassing security mechanisms. This could lead to unauthorized access and disclosure of sensitive data.

PUBLISHED
Vendor
Red Hat, external-secrets, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
external secrets operator for Red Hat OpenShift - Tech Preview, external-secrets, external secrets operator for Red Hat OpenShift - Tech Preview, External Secrets Operator for Red Hat OpenShift, external secrets operator for Red Hat OpenShift - Tech Preview, External Secrets Operator for Red Hat OpenShift, External Secrets Operator for Red Hat OpenShift, external secrets operator for Red Hat OpenShift - Tech Preview, External Secrets Operator for Red Hat OpenShift
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-22821

mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.

PUBLISHED
Vendor
pluginsGLPI
Product
mreporting
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22820

Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.

PUBLISHED
Vendor
akinloluwami
Product
outray
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2282

The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been dis

PUBLISHED
Vendor
hollandben
Product
Slidorion
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22819

Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts. This vulnerability is fixed in 0.1.5.

PUBLISHED
Vendor
akinloluwami
Product
outray
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22818

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. The JWK/JWKS JWT verification middleware has been updated to require an expl

PUBLISHED
Vendor
honojs
Product
hono
Provider severity
HIGH
Conflicts
0

CVE-2026-22817

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. As part of this fix, the JWT middleware now requires the alg option to be explicitly speci

PUBLISHED
Vendor
honojs
Product
hono
Provider severity
HIGH
Conflicts
0

CVE-2026-22816

Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered one of these exceptions, Gradle would continue to the next repository in the list and potentially resolve dependencies from a different repository. If a Gradle build used an unresolvable host name, Gradle would continue t

PUBLISHED
Vendor
gradle
Product
gradle
Provider severity
HIGH
Conflicts
1

CVE-2026-22815

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.

PUBLISHED
Vendor
aio-libs
Product
aiohttp
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-22814

@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic bypasses and unauthorized record modification within a table or model. This affects @adonisjs/lucid through version 21.8.1 and 22.x pre-release versions prior to 22.0.0-next.6. Thi

PUBLISHED
Vendor
adonisjs
Product
lucid
Provider severity
HIGH
Conflicts
0

CVE-2026-22813

OpenCode is an open source AI coding agent. The markdown renderer used for LLM responses will insert arbitrary HTML into the DOM. There is no sanitization with DOMPurify or even a CSP on the web interface to prevent JavaScript execution via HTML injection. This means controlling the LLM response for a chat session gets JavaScript execution on the http://localhost:4096 origin. This vulnerability is fixed in 1.1.10.

PUBLISHED
Vendor
anomalyco
Product
opencode
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22812

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

PUBLISHED
Vendor
anomalyco
Product
opencode
Provider severity
HIGH
Conflicts
1

CVE-2026-22810

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target p

PUBLISHED
Vendor
laurent22
Product
joplin
Provider severity
HIGH
Conflicts
0

CVE-2026-2281

The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in all versions up to, and including, 0.0.4. This is due to insufficient input sanitization and output escaping on the plugin's label text option. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installation

PUBLISHED
Vendor
edersonpeka
Product
Private Comment
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22809

tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (ReDoS) vulnerability was identified in tarteaucitron.js in the handling of the issuu_id parameter. This vulnerability is fixed in 1.29.0.

PUBLISHED
Vendor
AmauriC
Product
tarteaucitron.js
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22808

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorage. This could allow unauthorized access to Fleet, including administrative access, visibility into device data, and modification of configuration. Versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 fi

PUBLISHED
Vendor
fleetdm
Product
fleet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22807

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_code`, allowing attacker-controlled Python code in a model repo/path to execute at server startup. An attacker who can influence the model repo/path (local directory or remote Hugging Face repo) can achieve arbitrary code execution on the vLLM host during model l

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, vllm-project, Red Hat, Red Hat
Product
Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server 3.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat AI Inference Server 3.2, Red Hat OpenShift AI 2.25, Red Hat AI Inference Server 3.3, Red Hat OpenShift AI 3.4, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, vllm, Red Hat AI Inference Server, Red Hat OpenShift AI 2.25
Provider severity
HIGH
Conflicts
2

CVE-2026-22806

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be bypassed to access resources outside of it. However, the user still cannot access resources beyond what is accessible to the owner of the access key. Versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10 fix the vulnerability. Some other mitigations are available. Users can li

PUBLISHED
Vendor
loft-sh
Product
loft
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22805

Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in 55.13, 56.3, and 57.1.

PUBLISHED
Vendor
metabase
Product
metabase
Provider severity
LOW
Conflicts
0

CVE-2026-22804

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 to 1.9.0, Stored Cross-Site Scripting (XSS) vulnerability exists in the Termix File Manager component. The application fails to sanitize SVG file content before rendering it. This allows an attacker who has compromised a managed SSH server to plant a malicious file, which, when previewed by the Termix user, executes arbitrary JavaScript in the context of the application. The v

PUBLISHED
Vendor
Termix-SSH
Product
Termix
Provider severity
HIGH
Conflicts
1

CVE-2026-22803

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a large amount of memory, causing DoS via memory exhaustion. This vulnerability is fixed in 2.49.5.

PUBLISHED
Vendor
sveltejs
Product
kit
Provider severity
HIGH
Conflicts
0

CVE-2026-22801

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to

PUBLISHED
Vendor
pnggroup
Product
libpng
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22800

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Request Forgery (CSRF) vulnerability exists in an administrative API endpoint responsible for terminating all active video conferences on a single server. The affected endpoint performs a destructive action but is exposed via an HTTP GET request. Although proper authorization checks are enforced and the endpoint cannot be triggered cross-site, the use of GET allows the action to be

PUBLISHED
Vendor
THM-Health
Product
PILOS
Provider severity
LOW
Conflicts
0

CVE-2026-2280

The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been d

PUBLISHED
Vendor
larsdrasmussen
Product
rexCrawler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22799

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers (with a valid API key or admin session cookie) to upload arbitrary files (including malicious PHP scripts) to the server. An attacker can obtain the API key either by gaining administrator access to enable the REST API set

PUBLISHED
Vendor
emlog
Product
emlog
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22798

hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1.

PUBLISHED
Vendor
softwarepub
Product
hermes
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22797

A flaw was found in OpenStack keystonemiddleware. The external_oauth2_token middleware fails to properly sanitize incoming authentication headers. An authenticated attacker can exploit this by sending forged identity headers, such as X-Is-Admin-Project, X-Roles, or X-User-Id. This can lead to privilege escalation or impersonation of other users within the system.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, OpenStack, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenShift Container Platform 4.19, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenShift Container Platform 4.18, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, keystonemiddleware, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4.17, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenShift Container Platform 4.21, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenShift Container Platform 4.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 18.0, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 18.0
Provider severity
CRITICAL
Conflicts
3

CVE-2026-22796

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a

PUBLISHED
Vendor
Siemens, OpenSSL
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, OpenSSL
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22795

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to

PUBLISHED
Vendor
Siemens, OpenSSL
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, OpenSSL
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22794

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.

PUBLISHED
Vendor
appsmithorg
Product
appsmith
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22793

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such as Electron’s electron.mcp) are exposed, resulting in full compromise of the host system. Version 0.1

PUBLISHED
Vendor
nanbingxyz
Product
5ire
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22792

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML rendering permits untrusted HTML (including on* event attributes) to execute in the renderer context. An attacker can inject an `<img onerror=...>` payload to run arbitrary JavaScript in the renderer, which can call exposed bridge APIs such as `window.bridge.mcpServersManager.createServer`. This enables unauthorized creation of MCP servers and lead to remo

PUBLISHED
Vendor
nanbingxyz
Product
5ire
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22791

openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.

PUBLISHED
Vendor
opencryptoki
Product
opencryptoki
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22790

EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from network-provided frames. Version 2026.02.0 contains a patch.

PUBLISHED
Vendor
EVerest
Product
everest-core
Provider severity
HIGH
Conflicts
0