Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-22100

The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.

PUBLISHED
Vendor
EVbee
Product
DC-80
Provider severity
HIGH
Conflicts
0

CVE-2026-2210

A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
D-Link
Product
DIR-823X
Provider severity
HIGH
Conflicts
2

CVE-2026-22099

The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive information leakage, triggering reboots, or pushing a firmware update URL.

PUBLISHED
Vendor
EVbee
Product
DC-80
Provider severity
HIGH
Conflicts
0

CVE-2026-22098

Various sensitive information such as passwords and charging card UIDs are written to log files.

PUBLISHED
Vendor
EVbee
Product
DC-80
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22097

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.

PUBLISHED
Vendor
EVbee
Product
DC-80
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22096

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.

PUBLISHED
Vendor
EVbee
Product
DC-80
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22095

The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

PUBLISHED
Vendor
EVbee
Product
DC-80
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22093

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and server. The traffic is weakly encrypted using RC4 with a hardcoded key, which allows an attacker to gain access to the communication. Part of this communication involves access codes to charging stations. This issue af

PUBLISHED
Vendor
EVbee
Product
EVbee Service
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2209

A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can be launched remotely. Upgrading to version 8.19 is sufficient to fix this issue. The patch is identified as f244a43771f6ebf40218b83b9f46dba6b940d7de. It is suggested to upgrade the affected component.

PUBLISHED
Vendor
n/a
Product
WeKan
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22082

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session ID during insecure transmission. Successful exploitation of this vulnerability could allow the attacker to hijack an authenticated session and compromise sensitive configuration

PUBLISHED
Vendor
Tenda
Product
300Mbps Wireless Router F3 and N300 Easy Setup Router
Provider severity
HIGH
Conflicts
0

CVE-2026-22081

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device

PUBLISHED
Vendor
Tenda
Product
300Mbps Wireless Router F3 and N300 Easy Setup Router
Provider severity
HIGH
Conflicts
0

CVE-2026-22080

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the Base64-encoded credentials. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unauthor

PUBLISHED
Vendor
Tenda
Product
300Mbps Wireless Router F3 and N300 Easy Setup Router
Provider severity
HIGH
Conflicts
0

CVE-2026-2208

A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version 8.21 is recommended to address this issue. The identifier of the patch is a787bcddf33ca28afb13ff5ea9a4cb92dceac005. The affected component should be upgraded.

PUBLISHED
Vendor
n/a
Product
WeKan
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22079

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the credentials transmitted in plaintext. Successful exploitation of this vulnerability could allow the attacker to obtain s

PUBLISHED
Vendor
Tenda
Product
300Mbps Wireless Router F3 and N300 Easy Setup Router
Provider severity
HIGH
Conflicts
0

CVE-2026-22078

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

PUBLISHED
Vendor
OPPO
Product
O+ Connect
Provider severity
HIGH
Conflicts
0

CVE-2026-22077

OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information disclosure.

PUBLISHED
Vendor
OPPO
Product
OPPO Wallet APP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

PUBLISHED
Vendor
OPPO
Product
ColorOS Assistant
Provider severity
HIGH
Conflicts
0

CVE-2026-2207

A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the component Activity Publication Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. Upgrading to version 8.21 is capable of addressing this issue. This patch is called 91a936e07d2976d4246dfe834281c3aaa87f9503. You should upgrade the affected component.

PUBLISHED
Vendor
n/a
Product
WeKan
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22068

Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Traffic Server
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-2206

A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. Upgrading to version 8.21 is able to resolve this issue. The patch is named 4ce181d17249778094f73d21515f7f863f554743. It is advisable to upgrade the affected component.

PUBLISHED
Vendor
n/a
Product
WeKan
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22055

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

PUBLISHED
Vendor
NETAPP
Product
Active IQ OneCollect
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22054

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

PUBLISHED
Vendor
NETAPP
Product
Active IQ Config Advisor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22052

ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.

PUBLISHED
Vendor
NETAPP
Product
ONTAP 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22051

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.

PUBLISHED
Vendor
NETAPP
Product
StorageGRID (formerly StorageGRID Webscale)
Provider severity
LOW
Conflicts
1

CVE-2026-22050

ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snapshot expiry time to none.

PUBLISHED
Vendor
NETAPP
Product
ONTAP 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2205

A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. Upgrading to version 8.21 is able to mitigate this issue. The name of the patch is 0f5a9c38778ca550cbab6c5093470e1e90cb837f. Upgrading the affected component is advised.

PUBLISHED
Vendor
n/a
Product
WeKan
Provider severity
MEDIUM
Conflicts
2

CVE-2026-22049

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

PUBLISHED
Vendor
NETAPP
Product
ONTAP 9
Provider severity
HIGH
Conflicts
1

CVE-2026-22048

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.

PUBLISHED
Vendor
NETAPP
Product
StorageGRID (formerly StorageGRID Webscale)
Provider severity
HIGH
Conflicts
1

CVE-2026-22047

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in `SIccCalcOp::Describe()` at `IccProfLib/IccMpeCalc.cpp`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-22046

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in `CIccProfileXml::ParseBasic()` at `IccXML/IccLibXML/IccProfileXml.cpp`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

PUBLISHED
Vendor
InternationalColorConsortium
Product
iccDEV
Provider severity
HIGH
Conflicts
1

CVE-2026-22045

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entry point. The vulner

PUBLISHED
Vendor
traefik
Product
traefik
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22044

GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.

PUBLISHED
Vendor
glpi-project
Product
glpi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22043

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables privilege escalation and bypass of session/inline policy restrictions. Version 1.0.0-alpha.79 fixes the issue.

PUBLISHED
Vendor
rustfs
Product
rustfs
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22042

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions to perform import operations. Since importing IAM data performs privileged write actions (creating/updating users, groups, policies, and service accounts), this can lead to unauthorized IAM modification and privilege escalation. Version 1.0.0-alpha.79

PUBLISHED
Vendor
rustfs
Product
rustfs
Provider severity
MEDIUM
Conflicts
1

CVE-2026-22041

Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictionary keys. Prior to version 0.0.6, non-string types are converted into string types, leading to type errors in %d conversions. The problem has been patched in version 0.0.6. No known workarounds are available.

PUBLISHED
Vendor
armurox
Product
loggingredactor
Provider severity
LOW
Conflicts
0

CVE-2026-22040

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffic pattern of high-frequency publishes and rapid reconnect/kick-out using the same ClientID and massive subscribe/unsubscribe jitter, it is possible to reliably trigger heap memory corruption in the Broker process, causing it to exit immediately with SIGABRT due to free(): invalid pointer. As of time of publication, no known patched versions are available.

PUBLISHED
Vendor
nanomq
Product
nanomq
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller ServiceAccount, with no enforcement that the request is limited to the policy’s namespace. As a result, any authenticated user with permission to create a namespaced Policy can cause Kyverno to perform Kubernetes API requests

PUBLISHED
Vendor
kyverno
Product
kyverno
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22038

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.46, the AutoGPT platform's Stagehand integration blocks log API keys and authentication secrets in plaintext using logger.info() statements. This occurs in three separate block implementations (StagehandObserveBlock, StagehandActBlock, and StagehandExtractBlock) where the code explicitly calls api_key.get_secret_value

PUBLISHED
Vendor
Significant-Gravitas
Product
AutoGPT
Provider severity
HIGH
Conflicts
0

CVE-2026-22037

The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin` instead of `/admin`). While the middleware engine fails to match the encoded path and skips execution, the underlying Fastify router correctly decodes the path and matches the route handler, allowing attackers to access protected endp

PUBLISHED
Vendor
fastify
Product
fastify-express
Provider severity
HIGH
Conflicts
1

CVE-2026-22036

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

PUBLISHED
Vendor
nodejs
Product
undici
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22035

Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments method in ExternalCommandDestination.cs:269 uses string.Format() to insert user-controlled filenames directly into shell commands without sanitization, allowing attackers to execute arbitrary commands by crafting malicious filenames containing shell metacharacters. This issue is fixed in version 1.3.311.

PUBLISHED
Vendor
greenshot
Product
greenshot
Provider severity
HIGH
Conflicts
0

CVE-2026-22034

Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployments of Snuffleupagus prior to version 0.13.0 with the non-default upload validation feature enabled and configured to use one of the upstream validation scripts based on Vulcan Logic Disassembler (VLD) while the VLD extension is not available to the CLI SAPI, all files from multipart POST requests are evaluated as PHP code. The issue was fixed in ve

PUBLISHED
Vendor
jvoisin
Product
snuffleupagus
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22033

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the templates/base.html template. Because the application exposes an API token en

PUBLISHED
Vendor
HumanSignal
Product
label-studio
Provider severity
HIGH
Conflicts
1

CVE-2026-22032

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayState` parameter is intended to preserve the user's original destination. However, while the login initiation flow validates redirect targets against allowed domains, this validation is not applied to the callback endpoint. This allows an attacker to craft a mal

PUBLISHED
Vendor
directus
Product
directus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22031

@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin` instead of `/admin`). While the middleware engine fails to match the encoded path and skips execution, the underlying Fastify router correctly decodes the path and matches the route handler, allowing attackers to access prot

PUBLISHED
Vendor
fastify
Product
middie
Provider severity
HIGH
Conflicts
0

CVE-2026-22030

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes. There is no impact if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been p

PUBLISHED
Vendor
remix-run
Product
react-router
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2203

A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

PUBLISHED
Vendor
Tenda
Product
AC8
Provider severity
HIGH
Conflicts
2

CVE-2026-22029

A cross site scripting flaw has been discovered in the npm react-router and @remix-run/router packages. React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, remix-run, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, remix-run, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Edge Manager preview, Red Hat Single Sign-On 7, multicluster engine for Kubernetes 2.6, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, @remix-run/router, OpenShift Service Mesh 3, Red Hat JBoss Enterprise Application Platform 8, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift AI 3.3, OpenShift Service Mesh 3, Red Hat OpenShift Virtualization 4, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift Service Mesh 3.2, OpenShift Pipelines, Red Hat Openshift Data Foundation 4.18, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 3.1, Multicluster Engine for Kubernetes, Red Hat OpenShift AI 2.25, Red Hat Quay 3, Red Hat Edge Manager preview, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Edge Manager 1.0, Red Hat OpenShift AI (RHOAI), Node HealthCheck Operator, Red Hat Build of Kueue, Red Hat Edge Manager 1.1, Migration Toolkit for Virtualization, Red Hat Openshift Data Foundation 4.19, Red Hat Advanced Cluster Management for Kubernetes 2.12, Red Hat Advanced Cluster Management for Kubernetes 2.13, multicluster engine for Kubernetes 2.7, Red Hat Advanced Cluster Security 4.9, Red Hat Edge Manager preview, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.6, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Container Platform 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Edge Manager preview, Red Hat Advanced Cluster Security 4, Red Hat Ansible Automation Platform 2, Red Hat Migration Toolkit 1.8, Red Hat Openshift Data Foundation 4.18, Red Hat Build of Kueue, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Node HealthCheck Operator, Red Hat Enterprise Linux 9, Red Hat Openshift Data Foundation 4.2, Red Hat Advanced Cluster Security 4, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat Edge Manager preview, Red Hat OpenShift Dev Spaces, Red Hat build of Apache Camel - HawtIO 4, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift Container Platform 4.2, Migration Toolkit for Applications 8, Red Hat OpenShift Service Mesh 3.0, Logging Subsystem for Red Hat OpenShift, OpenShift Pipelines, Red Hat Edge Manager preview, Red Hat Satellite 6, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.18, Network Observability Operator, Red Hat Edge Manager preview, Red Hat Openshift Data Foundation 4.2, Red Hat Edge Manager preview, Migration Toolkit for Applications 7, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.19, Red Hat Enterprise Linux 8, OpenShift Pipelines, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Satellite 6, multicluster engine for Kubernetes 2.1, Red Hat OpenShift GitOps, react-router, Migration Toolkit for Virtualization, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager preview, Red Hat Edge Manager 1.0, multicluster engine for Kubernetes 2.8, Red Hat Advanced Cluster Security 4, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 2, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.2, Red Hat Connectivity Link 1, Node HealthCheck Operator, Red Hat OpenShift Container Platform 4.2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift distributed tracing 3, Red Hat Fuse 7, Logging Subsystem for Red Hat OpenShift, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Advanced Cluster Security 4.8, Red Hat OpenShift AI 2.25, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Virtualization 4, Red Hat Edge Manager preview, Red Hat OpenShift Service Mesh 3.0, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Build of Kueue, Red Hat OpenShift Container Platform 4.18, Red Hat Developer Hub, Red Hat Advanced Cluster Management for Kubernetes 2.15, Red Hat Edge Manager preview, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift Service Mesh 3.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift Container Platform 4, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Edge Manager 1.1, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.18, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.18, Red Hat Advanced Cluster Security 4, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Gatekeeper 3, Logging Subsystem for Red Hat OpenShift, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.2, Cryostat 4, Red Hat Openshift Data Foundation 4.2, Red Hat OpenShift Container Platform 4.21, Red Hat Openshift Data Foundation 4.2, Red Hat Ansible Automation Platform 2, Red Hat Edge Manager preview, Red Hat OpenShift Container Platform 4, Logging Subsystem for Red Hat OpenShift, Red Hat Trusted Artifact Signer 1.3, Red Hat Advanced Cluster Security 4, Red Hat build of OptaPlanner 8, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift GitOps, Red Hat Openshift Data Foundation 4.2, Red Hat Quay 3, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Service Mesh 3.1, Red Hat Openshift Data Foundation 4.19, Red Hat build of Apicurio Registry 2, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat OpenShift Dev Spaces (RHOSDS) 3.26, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift Container Platform 4.17, OpenShift Pipelines, Red Hat OpenShift AI 3.3, Red Hat Process Automation 7, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2.5 for RHEL 9, OpenShift Lightspeed, Logging Subsystem for Red Hat OpenShift, OpenShift Lightspeed, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Container Platform 4.19, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat Openshift Data Foundation 4.19, Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Logging Subsystem for Red Hat OpenShift, Node HealthCheck Operator, Red Hat Openshift Data Foundation 4.2, Red Hat Openshift Data Foundation 4.18, Red Hat Edge Manager preview, Red Hat Advanced Cluster Management for Kubernetes 2, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift GitOps, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat Openshift Data Foundation 4.18, Red Hat Build of Kueue, Red Hat Openshift Data Foundation 4.19, Red Hat Advanced Cluster Management for Kubernetes 2, OpenShift Service Mesh 2, Red Hat Discovery 2, Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2, Network Observability Operator, Red Hat OpenShift Container Platform 4, Red Hat Data Grid 8
Provider severity
HIGH
Conflicts
2

CVE-2026-22028

Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON payloads are assumed to be strings and passed unmodified to Preact as children, a specially-crafted JSON payload could be constructed that would be incorrectly treated as a valid VNode. When this chain of failures occurs it c

PUBLISHED
Vendor
preactjs
Product
preact
Provider severity
HIGH
Conflicts
0

CVE-2026-22027

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the convert_hexstring_to_byte_array() function in the MariaDB SA interface writes decoded bytes into a caller-provided buffer without any capacity check. When importing SA fields from the database (e.g., IV, ARSN, ABM), a malformed or oversized

PUBLISHED
Vendor
nasa
Product
CryptoLib
Provider severity
MEDIUM
Conflicts
0