Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-22555

Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
HIGH
Conflicts
0

CVE-2026-22554

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

PUBLISHED
Vendor
MediaArea
Product
MediaInfoLib
Provider severity
HIGH
Conflicts
0

CVE-2026-22553

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

PUBLISHED
Vendor
InSAT
Product
MasterSCADA BUK-TS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22552

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption o

PUBLISHED
Vendor
ePower
Product
epower.ie
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22551

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented att

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse Theia
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22550

OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WRC-X6000XST-G, WRC-XE5400GSA-G, WRC-X6000QSA-G, WRC-X3000GS2-W, WRC-X1500GSA-B, WRC-X6000XS-G, WRC-X3000GS2A-B, WRC-X3000GST2-B, WRC-X1800GSA-B, WRC-XE5400GS-G, WRC-X1800GS-B, WRC-X1800GSH-B, WRC-X6000QS-G, WRC-X3000GS2-B, WRC-X1500GS-B
Provider severity
HIGH
Conflicts
2

CVE-2026-2255

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

PUBLISHED
Vendor
Hitachi Vantara
Product
Pentaho Data Integration and Analytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22549

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
F5 BIG-IP Container Ingress Services
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22548

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-22547

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22545

Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
LOW
Conflicts
0

CVE-2026-22544

An attacker with a network connection could detect credentials in clear text.

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
HIGH
Conflicts
0

CVE-2026-22543

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22542

An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22541

The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
HIGH
Conflicts
0

CVE-2026-22540

The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

PUBLISHED
Vendor
EFACEC
Product
QC60/90/120
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2254

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

PUBLISHED
Vendor
Hitachi Vantara
Product
Pentaho Data Integration and Analytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22539

As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could obtain information about the charger via OCPP v1.6.

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22537

The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files containing clear-text credentials or valuable information for an attacker.

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22536

The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
HIGH
Conflicts
0

CVE-2026-22535

An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications

PUBLISHED
Vendor
EFACEC
Product
QC 60/90/120
Provider severity
HIGH
Conflicts
0

CVE-2026-2253

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

PUBLISHED
Vendor
Hitachi Vantara
Product
Pentaho Data Integration and Analytics
Provider severity
HIGH
Conflicts
0

CVE-2026-22524

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows Reflected XSS.This issue affects Legacy Admin: from n/a through <= 9.5.

PUBLISHED
Vendor
themepassion
Product
Legacy Admin
Provider severity
HIGH
Conflicts
0

CVE-2026-22523

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra WordPress Admin: from n/a through <= 11.7.

PUBLISHED
Vendor
themepassion
Product
Ultra WordPress Admin
Provider severity
HIGH
Conflicts
0

CVE-2026-22522

Missing Authorization vulnerability in Munir Kamal Block Slider block-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Block Slider: from n/a through <= 2.2.3.

PUBLISHED
Vendor
Munir Kamal
Product
Block Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22521

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework handmade-framework allows PHP Local File Inclusion.This issue affects Handmade Framework: from n/a through <= 3.9.

PUBLISHED
Vendor
G5Theme
Product
Handmade Framework
Provider severity
HIGH
Conflicts
0

CVE-2026-22520

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Handmade Framework handmade-framework allows Reflected XSS.This issue affects Handmade Framework: from n/a through <= 3.9.

PUBLISHED
Vendor
G5Theme
Product
Handmade Framework
Provider severity
HIGH
Conflicts
0

CVE-2026-2252

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.  Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on -  https://www.support.xerox.com/en-us/product/core/downloads

PUBLISHED
Vendor
Xerox
Product
FreeFlow Core
Provider severity
HIGH
Conflicts
1

CVE-2026-22519

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPress mediapress allows Stored XSS.This issue affects MediaPress: from n/a through <= 1.6.2.

PUBLISHED
Vendor
BuddyDev
Product
MediaPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22518

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows DOM-Based XSS.This issue affects X Addons for Elementor: from n/a through <= 1.0.23.

PUBLISHED
Vendor
pencilwp
Product
X Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22517

Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0.

PUBLISHED
Vendor
Passionate Brains
Product
GA4WP: Google Analytics for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22516

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wizor's wizors-investments allows PHP Local File Inclusion.This issue affects Wizor's: from n/a through <= 2.12.

PUBLISHED
Vendor
AncoraThemes
Product
Wizor's
Provider severity
HIGH
Conflicts
0

CVE-2026-22515

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows PHP Local File Inclusion.This issue affects VegaDays: from n/a through <= 1.2.0.

PUBLISHED
Vendor
AncoraThemes
Product
VegaDays
Provider severity
HIGH
Conflicts
0

CVE-2026-22514

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Unica unica allows PHP Local File Inclusion.This issue affects Unica: from n/a through <= 1.4.1.

PUBLISHED
Vendor
AncoraThemes
Product
Unica
Provider severity
HIGH
Conflicts
0

CVE-2026-22513

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Triompher triompher allows PHP Local File Inclusion.This issue affects Triompher: from n/a through <= 1.1.0.

PUBLISHED
Vendor
AncoraThemes
Product
Triompher
Provider severity
HIGH
Conflicts
0

CVE-2026-22512

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Roisin roisin allows PHP Local File Inclusion.This issue affects Roisin: from n/a through <= 1.2.1.

PUBLISHED
Vendor
Elated-Themes
Product
Roisin
Provider severity
HIGH
Conflicts
0

CVE-2026-22511

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes NeoBeat neobeat allows PHP Local File Inclusion.This issue affects NeoBeat: from n/a through <= 1.2.

PUBLISHED
Vendor
Elated-Themes
Product
NeoBeat
Provider severity
HIGH
Conflicts
0

CVE-2026-22510

Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection.This issue affects Melody: from n/a through <= 1.6.3.

PUBLISHED
Vendor
AncoraThemes
Product
Melody
Provider severity
HIGH
Conflicts
0

CVE-2026-2251

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads

PUBLISHED
Vendor
Xerox
Product
FreeFlow Core
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22509

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gioia gioia allows PHP Local File Inclusion.This issue affects Gioia: from n/a through <= 1.4.

PUBLISHED
Vendor
Elated-Themes
Product
Gioia
Provider severity
HIGH
Conflicts
0

CVE-2026-22508

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Dentalux dentalux allows PHP Local File Inclusion.This issue affects Dentalux: from n/a through <= 3.3.

PUBLISHED
Vendor
AncoraThemes
Product
Dentalux
Provider severity
HIGH
Conflicts
0

CVE-2026-22507

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

PUBLISHED
Vendor
AncoraThemes
Product
Beelove
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22506

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Amoli amoli allows PHP Local File Inclusion.This issue affects Amoli: from n/a through <= 1.0.

PUBLISHED
Vendor
Elated-Themes
Product
Amoli
Provider severity
HIGH
Conflicts
0

CVE-2026-22505

Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection.This issue affects Morning Records: from n/a through <= 1.2.

PUBLISHED
Vendor
AncoraThemes
Product
Morning Records
Provider severity
HIGH
Conflicts
0

CVE-2026-22504

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion.This issue affects ProLingua: from n/a through <= 1.1.12.

PUBLISHED
Vendor
ThemeREX
Product
ProLingua
Provider severity
HIGH
Conflicts
0

CVE-2026-22503

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Nelson nelson allows PHP Local File Inclusion.This issue affects Nelson: from n/a through <= 1.2.0.

PUBLISHED
Vendor
ThemeREX
Product
Nelson
Provider severity
HIGH
Conflicts
0

CVE-2026-22502

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mr. Cobbler mr-cobbler allows PHP Local File Inclusion.This issue affects Mr. Cobbler: from n/a through <= 1.1.9.

PUBLISHED
Vendor
AncoraThemes
Product
Mr. Cobbler
Provider severity
HIGH
Conflicts
0

CVE-2026-22501

Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2.

PUBLISHED
Vendor
axiomthemes
Product
Mounthood
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22500

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.

PUBLISHED
Vendor
axiomthemes
Product
m2 | Construction and Tools Store
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2250

The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration.

PUBLISHED
Vendor
METIS Cyberspace Technology SA
Product
METIS WIC
Provider severity
HIGH
Conflicts
1