Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-21255

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2025, Windows 11 Version 23H2, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 26H1, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016, Windows Server 2022, Windows 10 Version 1809, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 22H3, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21253

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, Windows 10 Version 1809, Windows Server 2012 (Server Core installation), Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows 11 version 26H1, Windows Server 2016 (Server Core installation), Windows Server 2019 (Server Core installation), Windows Server 2019, Windows 10 Version 1607, Windows Server 2016, Windows Server 2025 (Server Core installation), Windows Server 2012 R2, Windows 11 Version 25H2, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows 10 Version 22H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-21251

Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2016, Windows Server 2022, Windows Server 2016 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21250

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 26H1, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-21249

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 version 26H1, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2016, Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 11 Version 26H1, Windows Server 2012 R2, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 22H3, Windows 10 Version 21H2, Windows Server 2022
Provider severity
LOW
Conflicts
1

CVE-2026-21248

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 22H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2016, Windows 11 Version 26H1, Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2025 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 22H3, Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 21H2
Provider severity
HIGH
Conflicts
1

CVE-2026-21247

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows 10 Version 1809, Windows 11 Version 26H1, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 26H1, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows Server 2016, Windows 11 Version 23H2, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 10 Version 1607
Provider severity
HIGH
Conflicts
2

CVE-2026-21246

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows Server 2025, Windows Server 2012 R2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 23H2, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2019 (Server Core installation), Windows Server 2012, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2019, Windows 11 version 22H3
Provider severity
HIGH
Conflicts
1

CVE-2026-21245

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows 11 Version 24H2, Windows 11 version 26H1, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-21244

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019, Windows 11 Version 23H2, Windows 10 Version 1809, Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2022, Windows 10 Version 22H2, Windows Server 2016, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows 10 Version 1607, Windows 11 version 22H3, Windows 11 Version 26H1, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-21243

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows Server 2019, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21242

Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 26H1, Windows 11 Version 24H2, Windows 10 Version 22H2, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 11 version 22H3, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-21241

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows 11 Version 26H1, Windows Server 2025, Windows 11 Version 25H2, Windows 11 Version 24H2, Windows Server 2022, Windows 11 version 26H1, Windows 11 Version 23H2
Provider severity
HIGH
Conflicts
1

CVE-2026-21240

Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2022, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 26H1, Windows 11 Version 25H2, Windows 10 Version 22H2, Windows 10 Version 1809, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-21239

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2012 (Server Core installation), Windows 10 Version 1607, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2012 R2, Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows 11 Version 25H2, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21238

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2012 R2, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 version 22H3, Windows Server 2019 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2022, Windows Server 2012, Windows 10 Version 22H2, Windows Server 2012 R2 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2016, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 11 Version 26H1, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 10 Version 1607
Provider severity
HIGH
Conflicts
1

CVE-2026-21237

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 26H1, Windows Server 2025, Windows 11 version 22H3, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 22H2, Windows 11 Version 23H2, Windows Server 2022, Windows 10 Version 21H2, Windows 11 Version 25H2, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
2

CVE-2026-21236

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2019 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2012 (Server Core installation), Windows Server 2025, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 11 version 26H1, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows 11 Version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2012, Windows Server 2019, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2026-21235

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows 11 version 22H3, Windows Server 2022, Windows 11 Version 26H1, Windows Server 2019, Windows Server 2016, Windows 10 Version 1607, Windows 11 Version 23H2, Windows 10 Version 22H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows 11 version 26H1, Windows Server 2012 R2, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 10 Version 1809, Windows Server 2012 R2 (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21234

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2019, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2025, Windows 11 Version 25H2, Windows 10 Version 1809, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 version 26H1, Windows 10 Version 22H2, Windows 11 Version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-21232

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 25H2, Windows 11 Version 26H1, Windows 11 Version 23H2, Windows 11 version 26H1, Windows 11 Version 24H2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation)
Provider severity
HIGH
Conflicts
1

CVE-2026-21231

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 version 26H1, Windows 10 Version 1607, Windows Server 2019, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2016 (Server Core installation), Windows 11 Version 24H2, Windows Server 2012 R2, Windows 11 Version 26H1, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows Server 2022, Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2016
Provider severity
HIGH
Conflicts
1

CVE-2026-2123

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability

PUBLISHED
Vendor
OpenText
Product
Operations Agent
Provider severity
HIGH
Conflicts
0

CVE-2026-21229

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Power BI Report Server
Provider severity
HIGH
Conflicts
0

CVE-2026-21228

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Local
Provider severity
HIGH
Conflicts
0

CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Logic Apps
Provider severity
HIGH
Conflicts
0

CVE-2026-21226

Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Core shared client library for Python
Provider severity
HIGH
Conflicts
0

CVE-2026-21224

Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Azure Connected Machine Agent
Provider severity
HIGH
Conflicts
0

CVE-2026-21223

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-21222

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 10 Version 1809, Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2025, Windows Server 2019 (Server Core installation), Windows Server 2012 R2, Windows Server 2016, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows 10 Version 1607, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 version 22H3, Windows Server 2019, Windows Server 2025 (Server Core installation)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-21221

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation)
Provider severity
HIGH
Conflicts
2

CVE-2026-2122

A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.php of the component WAF Firewall. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Xiaopi
Product
Panel
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21219

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
Windows SDK
Provider severity
HIGH
Conflicts
0

CVE-2026-21218

Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft
Product
.NET 9.0, .NET 8.0, .NET 10.0
Provider severity
HIGH
Conflicts
1

CVE-2026-2121

The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in all versions up to, and including, 1.8.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This primarily affects multisite installatio

PUBLISHED
Vendor
wpweaver
Product
Weaver Show Posts
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2120

A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation of the argument terminal_addr/server_ip/server_port leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
D-Link
Product
DIR-823X
Provider severity
HIGH
Conflicts
2

CVE-2026-2118

A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
UTT
Product
HiPER 810
Provider severity
HIGH
Conflicts
2

CVE-2026-2117

A vulnerability was found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
itsourcecode
Product
Society Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2116

A vulnerability has been found in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/edit_expenses.php. Such manipulation of the argument expenses_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Society Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2115

A flaw has been found in itsourcecode Society Management System 1.0. This issue affects some unknown processing of the file /admin/delete_expenses.php. This manipulation of the argument expenses_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Society Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2114

A vulnerability was detected in itsourcecode Society Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_admin.php. The manipulation of the argument admin_id results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Society Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2113

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
yuan1994
Product
tpadmin
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2112

The Dam Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due to missing nonce verification on the pending comment deletion action in the cleanup page. This makes it possible for unauthenticated attackers to delete all pending comments via a forged request granted they can trick an admin into performing an action such as clicking on a link.

PUBLISHED
Vendor
webguyio
Product
Dam Spam
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2111

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument filePath can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
JeecgBoot
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2110

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation results in improper restriction of excessive authentication attempts. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation appears to be difficult. The exploit has been released to the public and may be used for attacks. This produc

PUBLISHED
Vendor
Tasin1025
Product
SwiftBuy
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-2109

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
jsbroks
Product
COCO Annotator
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2108

A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api/info/long_task of the component Endpoint. This manipulation causes denial of service. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
jsbroks
Product
COCO Annotator
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2107

A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function loadAllLoginfo/deleteLoginfo/batchDeleteLoginfo of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\LoginfoController.java of the component Log Info Handler. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why informa

PUBLISHED
Vendor
yeqifu
Product
warehouse
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2106

A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. The impacted element is the function addNotice/updateNotice/deleteNotice/batchDeleteNotice of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\NoticeController.java of the component Notice Management. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with r

PUBLISHED
Vendor
yeqifu
Product
warehouse
Provider severity
MEDIUM
Conflicts
2

CVE-2026-21057

Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.

PUBLISHED
Vendor
Samsung Mobile
Product
Samsung Pass
Provider severity
MEDIUM
Conflicts
0