Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-22316

A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to trigger a stack-based Buffer Overflow, resulting in a DoS attack.

PUBLISHED
Vendor
Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact, Phoenix Contact
Product
FL SWITCH 5916SFP-8GC-4SFP+, FL SWITCH 2506-2SFP/K1, FL SWITCH 2207-FX, FL SWITCH 2308 PN, FL SWITCH 2414-2SFX, FL SWITCH TSN 2316, FL SWITCH 2414-2SFX PN, FL SWITCH 2508, FL SWITCH 2306-2SFP, FL SWITCH 2008, FL SWITCH 2105, FL SWITCH 2708, FL SWITCH 2508/K1, FL SWITCH 5924-4GC, FL SWITCH 2108, FL NAT 2008, FL SWITCH 2206-2FX ST, FL SWITCH 2312-2GC-2SFP, FL SWITCH 2314-2SFP PN, FL SWITCH 2608, FL SWITCH 2316 PN, FL SWITCH TSN 2312-2GC-2SFP, FL SWITCH 2304-2GC-2SFP, FL SWITCH 2208 PN, FL SWITCH 2206-2FX SM ST, FL SWITCH 2504-2GC-2SFP, FL SWITCH 2216, FL SWITCH 2116, FL SWITCH 2404-2TC-2SFX, FL SWITCH 2016, FL SWITCH 2506-2SFP PN, FL SWITCH 2205, FL SWITCH TSN 2314-2SFP, FL SWITCH 2516, FL SWITCH 2206-2FX, FL SWITCH 2308, FL SWITCH 5924SFP-4GC, FL SWITCH 2514-2SFP, FL SWITCH 2516 PN, FL SWITCH 2316/K1, FL SWITCH 2512-2GC-2SFP, FL SWITCH 2206-2SFX, FL SWITCH 2214-2FX SM, FL SWITCH 2416 PN, FL SWITCH 2206-2SFX PN, FL SWITCH 2314-2SFP, FL SWITCH 2408 PN, FL SWITCH 2608 PN, FL SWITCH 2008F, FL SWITCH 2306-2SFP PN, FL SWITCH 2508 PN, FL SWITCH 5916-8GC-4SFP+, FL SWITCH 2216 PN, FL SWITCH 2214-2SFX PN, FL SWITCH 2416, FL SWITCH 2408, FL SWITCH 2214-2FX, FL SWITCH 2206-2FX SM, FL NAT 2208, FL SWITCH 2506-2SFP, FL NAT 2304-2GC-2SFP, FL SWITCH 2514-2SFP PN, FL SWITCH 2708 PN, FL SWITCH 2208C, FL SWITCH 2204-2TC-2SFX, FL SWITCH 2212-2TC-2SFX, FL SWITCH 2214-2SFX, FL SWITCH 2406-2SFX PN, FL SWITCH 2406-2SFX, FL SWITCH 2207-FX SM, FL SWITCH 2005, FL SWITCH 2412-2TC-2SFX, FL SWITCH 2303-8SP1, FL SWITCH 5924-4SFP+, FL SWITCH 2208, FL SWITCH 2316, FL SWITCH 2206C-2FX
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22315

Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

PUBLISHED
Vendor
Mesalvo, Mesalvo
Product
Meona Client Launcher Component, Meona Server Component
Provider severity
HIGH
Conflicts
1

CVE-2026-22314

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

PUBLISHED
Vendor
Mesalvo, Mesalvo
Product
Meona Client Launcher Component, Meona Server Component
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22313

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.

PUBLISHED
Vendor
Radiflow
Product
iSAP Smart Collector
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22312

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

PUBLISHED
Vendor
Radiflow
Product
iSAP Smart Collector
Provider severity
HIGH
Conflicts
0

CVE-2026-2231

The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
techjewel
Product
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution
Provider severity
HIGH
Conflicts
0

CVE-2026-2230

The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, and booking permissions granted by an Administrator, to modify other users' plugin settings, such as booking calendar display options, which can disrupt the booking calendar functiona

PUBLISHED
Vendor
wpdevelop
Product
Booking Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2229

A flaw was found in the undici WebSocket client. A remote malicious server can exploit this vulnerability by sending a WebSocket frame with an invalid `server_max_window_bits` parameter within the permessage-deflate extension. This improper validation causes the client's Node.js process to terminate, leading to a denial-of-service (DoS) condition for the client.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, undici, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat OpenShift Dev Spaces, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.16, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.28, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.9, Red Hat Developer Hub, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat Enterprise Linux 10.0 Extended Update Support, Cluster Observability Operator 1.5.0, undici, Red Hat JBoss Enterprise Application Platform 8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.8, Red Hat Enterprise Linux 8, Self-service automation portal 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Pipelines 1.2, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 10, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
2

CVE-2026-22285

Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access.

PUBLISHED
Vendor
Dell
Product
Device Management Agent (DDMA)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22284

Dell SmartFabric OS10 Software, versions prior to 10.5.6.12, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

PUBLISHED
Vendor
Dell
Product
SmartFabric OS10 Software
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22283

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

PUBLISHED
Vendor
Dell
Product
PowerFlex
Provider severity
HIGH
Conflicts
0

CVE-2026-22281

Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to denial of service.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS
Provider severity
LOW
Conflicts
0

CVE-2026-22280

Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting from 9.11.0.0 and prior to 9.13.0.0, contains an incorrect permission assignment for critical resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22279

Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information tampering.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22278

Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS
Provider severity
HIGH
Conflicts
0

CVE-2026-22277

Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

PUBLISHED
Vendor
Dell
Product
UnityVSA
Provider severity
HIGH
Conflicts
0

CVE-2026-22276

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

PUBLISHED
Vendor
Dell
Product
ObjectScale
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22275

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

PUBLISHED
Vendor
Dell
Product
ObjectScale
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22274

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric Syslog. An unauthenticated attacker with remote access could potentially exploit this vulnerability to intercept and modify information in transit.

PUBLISHED
Vendor
Dell
Product
ObjectScale
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22273

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

PUBLISHED
Vendor
Dell
Product
ObjectScale
Provider severity
HIGH
Conflicts
0

CVE-2026-22271

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

PUBLISHED
Vendor
Dell
Product
ObjectScale
Provider severity
HIGH
Conflicts
0

CVE-2026-22270

Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, elevation of privileges, and information disclosure.

PUBLISHED
Vendor
Dell
Product
PowerScale OneFS,
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2227

A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DCS-931L
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22269

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22268

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service of a Dell Enterprise Support connection.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22267

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-22266

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.

PUBLISHED
Vendor
Dell
Product
PowerProtect Data Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22265

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py line 87, where the grep parameter is used twice - once sanitized and once raw. This vulnerability is fixed in 8.2.8.2.

PUBLISHED
Vendor
roxy-wi
Product
roxy-wi
Provider severity
HIGH
Conflicts
0

CVE-2026-22264

Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusted rulesets or run with less than 65536 signatures that can match on the same packet.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2026-22263

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22262

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets `save` nor `state` options.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22261

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuration. The setting is disabled by default.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
LOW
Conflicts
0

CVE-2026-22260

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As a workaround, use default values for `request-body-limit` and `response-body-limit`.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2026-2226

A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
DouPHP
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22259

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
1

CVE-2026-22258

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable. DCERPC/TCP in the default configuration should not be vulnerable as the default stream depth is limited to 1MiB. Versions 8.0.3 and 7.0.14 contain a patch. Some workarounds are avail

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
1

CVE-2026-22257

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload a file. This issue has been patched in version 0.88.1.

PUBLISHED
Vendor
salvo-rs
Product
salvo
Provider severity
HIGH
Conflicts
0

CVE-2026-22256

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected XSS using the fact that request path is decoded and normalized in the matching stage but not is inserted raw in the html view (current.path), the only constraint here is for the root path (eg. /files in the PoC example) to have a sub directory (e.g c

PUBLISHED
Vendor
salvo-rs
Product
salvo
Provider severity
HIGH
Conflicts
0

CVE-2026-22255

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in `CIccCLUT::Init()` at `IccProfLib/IccTagLut.cpp`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-22254

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets. The Winter CMS maintainers strongly recommend that the cms.manage_assets permission only be reserved to

PUBLISHED
Vendor
wintercms
Product
winter
Provider severity
NONE
Conflicts
1

CVE-2026-22253

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.

PUBLISHED
Vendor
charmbracelet
Product
soft-serve
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22252

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2.

PUBLISHED
Vendor
danny-avila
Product
LibreChat
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22251

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

PUBLISHED
Vendor
WeblateOrg
Product
wlc
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22250

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.

PUBLISHED
Vendor
WeblateOrg
Product
wlc
Provider severity
LOW
Conflicts
0

CVE-2026-2225

A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
News Portal Project
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-22249

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability is fixed in 0.24.0.

PUBLISHED
Vendor
docmost
Product
docmost
Provider severity
HIGH
Conflicts
0

CVE-2026-22248

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation. This vulnerability is fixed in 11.0.5.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
HIGH
Conflicts
0

CVE-2026-22247

GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22246

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of severed relationships for a particular event fails to check the owner of the list before returning the lost relationships. Any registered local user can access the list of lost followers and followed users caused by any seve

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22245

Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in `ALLOWED_PRIVATE_ADDRESSES`) to avoid the "confused deputy" problem. The list of disallowed IP address ranges was lacking some IP address ranges that can be used to reach local IP addresses. An attacker can use an IP address in t

PUBLISHED
Vendor
mastodon
Product
mastodon
Provider severity
HIGH
Conflicts
0