Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-2179

A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
PHPGurukul
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21789

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

PUBLISHED
Vendor
HCLSoftware
Product
Connections
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21788

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.

PUBLISHED
Vendor
HCLSoftware
Product
Connections
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21786

HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

PUBLISHED
Vendor
HCLSoftware
Product
Sametime for iOS
Provider severity
LOW
Conflicts
0

CVE-2026-21785

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

PUBLISHED
Vendor
HCLSoftware
Product
BigFix Remote Control Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21783

HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.  Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks.

PUBLISHED
Vendor
HCLSoftware
Product
Traveler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2178

A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affecte

PUBLISHED
Vendor
r-huijts
Product
xcode-mcp-server
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21770

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

PUBLISHED
Vendor
HCLSoftware
Product
HCL Traveler for Microsoft Outlook (HTMO)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2177

A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown function of the component Login. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Prison Management System
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-21768

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

PUBLISHED
Vendor
HCLSoftware
Product
Verse for Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21767

HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

PUBLISHED
Vendor
HCLSoftware
Product
BigFix Platform
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21765

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

PUBLISHED
Vendor
HCLSoftware
Product
BigFix Platform
Provider severity
HIGH
Conflicts
1

CVE-2026-21764

HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.

PUBLISHED
Vendor
HCLSoftware
Product
DevOps Loop
Provider severity
LOW
Conflicts
0

CVE-2026-21762

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.

PUBLISHED
Vendor
HCLSoftware
Product
DevOps Loop
Provider severity
LOW
Conflicts
0

CVE-2026-21761

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.

PUBLISHED
Vendor
HCLSoftware
Product
DevOps Loop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21760

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.

PUBLISHED
Vendor
HCLSoftware
Product
DevOps Loop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2176

A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Such manipulation of the argument selecteditem[0] leads to sql injection. The attack can be executed remotely.

PUBLISHED
Vendor
code-projects
Product
Contact Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2175

A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
D-Link
Product
DIR-823X
Provider severity
HIGH
Conflicts
2

CVE-2026-21743

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint.

PUBLISHED
Vendor
Fortinet
Product
FortiAuthenticator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21742

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if

PUBLISHED
Vendor
Fortinet, Fortinet
Product
FortiSOAR PaaS, FortiSOAR on-premise
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21741

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.

PUBLISHED
Vendor
Fortinet
Product
FortiNAC-F
Provider severity
LOW
Conflicts
0

CVE-2026-2174

A security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely.

PUBLISHED
Vendor
code-projects
Product
Contact Management System
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-21736

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21734

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very small value in GPU shader code can cause a segmentation fault in the GPU shader compiler due to am out-of-bounds write.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
HIGH
Conflicts
0

CVE-2026-21733

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protections.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
HIGH
Conflicts
1

CVE-2026-21732

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very large value in switch statements in GPU shader code can cause a segmentation fault in the GPU shader compiler due to an out-of-bounds write access.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
CRITICAL
Conflicts
0

CVE-2026-21730

Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization, an attacker can inject a malicious XSS payload into the username field. This payload will be executed in the context of the administrator’s browser when the admin accesses the web

PUBLISHED
Vendor
Verint
Product
Verba
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2173

A vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely.

PUBLISHED
Vendor
code-projects
Product
Online Examination System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-21729

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

PUBLISHED
Vendor
Grafana
Product
Loki
Provider severity
HIGH
Conflicts
0

CVE-2026-21728

A flaw was found in Tempo. A remote attacker can exploit this vulnerability by sending large queries to the Tempo service. This can lead to excessive memory allocations, potentially causing a Denial of Service (DoS) by impacting the availability of the service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Grafana, Grafana, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Ceph Storage 6, Red Hat Enterprise Linux 9, Multicluster Global Hub 1.3.4, Multicluster Global Hub, Red Hat OpenShift distributed tracing 3, Red Hat OpenShift distributed tracing 3, Red Hat Enterprise Linux 10, Logging Subsystem for Red Hat OpenShift, Red Hat Ceph Storage 9, Red Hat OpenShift distributed tracing 3, Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Global Hub 1.7.1, Red Hat OpenShift distributed tracing 3, Tempo, Enterprise Traces (GET), Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4, Red Hat multicluster global hub 1.6.0, Red Hat Ceph Storage 5
Provider severity
HIGH
Conflicts
3

CVE-2026-21727

--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana severity: Low cve: CVE-2026-21727 cvss_score: "3.3" cvss_vector: "CVSS:3.3/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" fixed_versions: - ">=11.6.11 >=12.0.9 >=12.1.6 >=12.2.4" --- A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affectin

PUBLISHED
Vendor
Grafana
Product
Grafana Correlations
Provider severity
LOW
Conflicts
0

CVE-2026-21726

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

PUBLISHED
Vendor
Grafana
Product
Loki
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21725

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The n

PUBLISHED
Vendor
Grafana
Product
Grafana
Provider severity
LOW
Conflicts
0

CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

PUBLISHED
Vendor
Grafana
Product
Grafana OSS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21723

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

PUBLISHED
Vendor
Grafana
Product
Grafana OSS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21722

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

PUBLISHED
Vendor
Grafana, Grafana
Product
grafana/grafana-enterprise, grafana/grafana
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

PUBLISHED
Vendor
Red Hat, Grafana, Grafana, Grafana, Grafana, Red Hat, Grafana, Red Hat, Red Hat, Red Hat, Red Hat, Grafana, Red Hat, Grafana, Red Hat, Grafana, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Grafana, Red Hat, Red Hat, Grafana
Product
Red Hat Ceph Storage 8, grafana/grafana-enterprise, grafana/grafana-enterprise, grafana/grafana, grafana/grafana-enterprise, Red Hat Advanced Cluster Management for Kubernetes 2.12, grafana/grafana-enterprise, Red Hat Ceph Storage 5, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Ceph Storage 6, grafana/grafana-enterprise, Multicluster Global Hub, grafana/grafana, Red Hat Ceph Storage 8, grafana/grafana, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Ceph Storage 6, Red Hat Enterprise Linux 10, Red Hat Ceph Storage 5, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Ceph Storage 8, Red Hat Enterprise Linux 9, grafana/grafana, Red Hat Ceph Storage 6, Red Hat Ceph Storage 5, grafana/grafana
Provider severity
HIGH
Conflicts
3

CVE-2026-21720

A flaw was found in Grafana. A remote attacker can exploit this vulnerability by sending a sustained volume of uncached /avatar/:hash requests. This action causes the system to create and block goroutines, which are lightweight concurrent functions, leading to a continuous increase in memory usage. Over time, this resource exhaustion can cause Grafana to crash, resulting in a Denial of Service (DoS).

PUBLISHED
Vendor
Grafana, Grafana, Grafana, Red Hat, Grafana, Red Hat, Grafana, Grafana, Grafana, Grafana, Red Hat, Red Hat, Red Hat, Grafana, Grafana
Product
grafana/grafana, grafana/grafana, grafana/grafana, Red Hat Enterprise Linux 9, grafana/grafana-enterprise, Red Hat Ceph Storage 8, grafana/grafana, grafana/grafana-enterprise, grafana/grafana-enterprise, grafana/grafana, Red Hat Ceph Storage 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, grafana/grafana-enterprise, grafana/grafana-enterprise
Provider severity
HIGH
Conflicts
3

CVE-2026-2172

A vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the component Login Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
code-projects
Product
Online Application System for Admission
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-21719

An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to execute an arbitrary OS command.

PUBLISHED
Vendor
CubeCart Limited
Product
CubeCart
Provider severity
HIGH
Conflicts
1

CVE-2026-21718

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.

PUBLISHED
Vendor
Copeland, Copeland, Copeland
Product
Copeland XWEB 300D PRO, Copeland XWEB 500B PRO, Copeland XWEB 500D PRO
Provider severity
CRITICAL
Conflicts
1

CVE-2026-21717

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table.

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21716

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted `--allow-fs-write` can still use promise-based `FileHandle` methods to modify file permissions and ownership on already-open file descriptors, bypassing the intended write restrictions. T

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
LOW
Conflicts
0

CVE-2026-21715

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
LOW
Conflicts
0

CVE-2026-21714

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21713

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an in

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21712

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21711

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the

PUBLISHED
Vendor
nodejs
Product
node
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21710

A flaw was found in Node.js. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request that includes a header named `__proto__`. When a Node.js application processes this request and attempts to access distinct headers, it encounters an unhandled error, leading to an application crash. This can result in a Denial of Service (DoS), making the affected service unavailable to users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, nodejs, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support, node, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Provider severity
HIGH
Conflicts
3

CVE-2026-2171

A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Online Student Management System
Provider severity
HIGH, MEDIUM
Conflicts
2