Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-21419

Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Access ('Link Following') vulnerability in the Installer and Service. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges

PUBLISHED
Vendor
Dell
Product
Display and Peripheral Manager (Windows)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21418

Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

PUBLISHED
Vendor
Dell
Product
Unity
Provider severity
HIGH
Conflicts
0

CVE-2026-21417

Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

PUBLISHED
Vendor
Dell
Product
CloudBoost Virtual Appliance
Provider severity
HIGH
Conflicts
0

CVE-2026-21413

A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, LibRaw, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8, LibRaw, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.6 Extended Update Support
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-21411

Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.

PUBLISHED
Vendor
Plat'Home Co.,Ltd., Plat'Home Co.,Ltd., Plat'Home Co.,Ltd., Plat'Home Co.,Ltd., Plat'Home Co.,Ltd., Plat'Home Co.,Ltd.
Product
OpenBlocks IX9 models with FW (FW5.0.x), OpenBlocks IDM RX1 (FW5.0.x), OpenBlocks IoT FX1 (FW5.0.x), OpenBlocks IoT EX/BX models (FW5.0.x), OpenBlocks IoT VX2 (FW5.0.x), OpenBlocks IoT DX1 (FW5.0.x)
Provider severity
HIGH
Conflicts
2

CVE-2026-21410

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

PUBLISHED
Vendor
InSAT
Product
MasterSCADA BUK-TS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-2141

A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
WuKongOpenSource
Product
WukongCRM
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21409

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication between the affected product and its user, and some crafted request is processed by the product, the user's registration information and/or OIDC (OpenID Connect) tokens may be retrieved.

PUBLISHED
Vendor
Ricoh Company, Ltd.
Product
RICOH Streamline NX
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-21408

beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with SYSTEM privileges.

PUBLISHED
Vendor
FUJIFILM Business Innovation Corp.
Product
beat-access for Windows
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-21404

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.

PUBLISHED
Vendor
NAVTOR
Product
NavBox
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2140

A vulnerability was identified in Tenda TX9 up to 22.03.02.10_multi. Affected by this issue is the function sub_4223E0 of the file /goform/setMacFilterCfg. Such manipulation of the argument deviceList leads to buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Tenda
Product
TX9
Provider severity
HIGH
Conflicts
2

CVE-2026-21393

Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

PUBLISHED
Vendor
Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd., Six Apart Ltd.
Product
Movable Type (Cloud Edition), Movable Type (Software Edition), Movable Type Advanced (Software Edition), Movable Type Premium (Advanced Edition) (Software Edition), Movable Type Premium (Cloud Edition), Movable Type Premium (Software Edition)
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2139

A vulnerability was determined in Tenda TX9 up to 22.03.02.10_multi. Affected by this vulnerability is the function sub_432580 of the file /goform/fast_setting_wifi_set. This manipulation of the argument ssid causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
TX9
Provider severity
HIGH
Conflicts
2

CVE-2026-21389

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.

PUBLISHED
Vendor
Copeland, Copeland, Copeland
Product
Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Provider severity
HIGH
Conflicts
1

CVE-2026-21388

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
LOW
Conflicts
0

CVE-2026-21386

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21385

Memory corruption while using alignments for memory allocation.

PUBLISHEDCISA KEV
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21384

Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21383

Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21382

Memory Corruption when handling power management requests with improperly sized input/output buffers.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21381

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21380

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-2138

A vulnerability was found in Tenda TX9 up to 22.03.02.10_multi. Affected is the function sub_42D03C of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Tenda
Product
TX9
Provider severity
HIGH
Conflicts
2

CVE-2026-21379

Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21378

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21376

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21375

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21374

Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21373

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21372

Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21371

Memory Corruption when retrieving output buffer with insufficient size validation.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21370

Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2137

A vulnerability has been found in Tenda TX3 up to 16.03.13.11_multi. This impacts an unknown function of the file /goform/SetIpMacBind. The manipulation of the argument list leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
TX3
Provider severity
HIGH
Conflicts
2

CVE-2026-21369

Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21368

Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21367

Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-21365

Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Substance3D - Painter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21364

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Substance3D - Painter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21363

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Substance3D - Painter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21362

Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
Illustrator
Provider severity
HIGH
Conflicts
0

CVE-2026-21361

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and

PUBLISHED
Vendor
Adobe
Product
Adobe Commerce
Provider severity
HIGH
Conflicts
0

CVE-2026-21360

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restricted path. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe
Product
Adobe Commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2136

A flaw has been found in projectworlds Online Food Ordering System 1.0. This affects an unknown function of the file /view-ticket.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
projectworlds
Product
Online Food Ordering System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-21359

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited impact to the integrity and availability of data. The exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

PUBLISHED
Vendor
Adobe
Product
Adobe Commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21358

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
InDesign Desktop
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21357

InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
InDesign Desktop
Provider severity
HIGH
Conflicts
0

CVE-2026-21355

DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
DNG SDK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21354

DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
DNG SDK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-21353

DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
DNG SDK
Provider severity
HIGH
Conflicts
0

CVE-2026-21352

DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
DNG SDK
Provider severity
HIGH
Conflicts
0