Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-16327

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
D-Link
Product
DNS-320
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16326

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.

PUBLISHED
Vendor
HashiCorp
Product
Tooling
Provider severity
CRITICAL
Conflicts
0

CVE-2026-16324

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Metasoft 美特软件
Product
MetaCRM
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-1632

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

PUBLISHED
Vendor
RISS SRL
Product
MOMA Seismic Station
Provider severity
CRITICAL
Conflicts
1

CVE-2026-16318

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes the existing pointer before allocating new memory, causing the first allocation to be leaked. This can occur during normal QUIC traffic when a client offers a key share group the server does not pr

PUBLISHED
Vendor
Amazon
Product
s2n-tls
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16317

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content_type of all encrypted TLS 1.3 records must be application_data (0x17). The s2n-tls AEAD implementation hardcodes this value in the additional authenticated data rather than using the actual wire byte, so the outer

PUBLISHED
Vendor
AWS
Product
s2n-tls
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 7
Provider severity
HIGH
Conflicts
1

CVE-2026-1631

The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This makes it possible for subscribers and above delete the license key.

PUBLISHED
Vendor
Unknown
Product
Feeds for YouTube (YouTube video, channel, and gallery plugin)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16308

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

PUBLISHED
Vendor
IBM
Product
Enterprise Build of Quarkus
Provider severity
HIGH
Conflicts
0

CVE-2026-16300

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

PUBLISHED
Vendor
Unknown
Product
ChamaWP
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1630

WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in versions 2026.1.3.109 and 2025.2.1.293.

PUBLISHED
Vendor
WEBCON
Product
WEBCON BPS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16297

The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.

PUBLISHED
Vendor
Unknown
Product
Clearfy Cache
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16292

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled, the same action is reachable unauthenticated against any user's file.

PUBLISHED
Vendor
Unknown
Product
Frontend File Manager Plugin
Provider severity
Not asserted
Conflicts
0

CVE-2026-16291

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.

PUBLISHED
Vendor
Unknown
Product
ProfileGrid
Provider severity
Not asserted
Conflicts
0

CVE-2026-1629

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16289

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.

PUBLISHED
Vendor
Unknown
Product
ProfileGrid
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16287

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.

PUBLISHED
Vendor
TUBITAK BILGEM Software Technologies Research Institute
Product
pardus-update
Provider severity
HIGH
Conflicts
0

CVE-2026-16285

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.

PUBLISHED
Vendor
Unknown
Product
Product Attachment for WooCommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-16280

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.

PUBLISHED
Vendor
Imagination Technologies
Product
Graphics DDK
Provider severity
CRITICAL
Conflicts
0

CVE-2026-1628

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16277

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16276

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.

PUBLISHED
Vendor
Unknown
Product
Classified Listing
Provider severity
Not asserted
Conflicts
0

CVE-2026-16274

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private posts owned by other users — regardless of ownership.

PUBLISHED
Vendor
Unknown
Product
Classified Listing
Provider severity
Not asserted
Conflicts
0

CVE-2026-16273

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged user who views the affected post.

PUBLISHED
Vendor
Unknown
Product
Narrative Publisher
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16270

Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack. This issue was fixed in version 0.6.4.

PUBLISHED
Vendor
Open Mercato
Product
Open Mercato
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1627

An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.

PUBLISHED
Vendor
SICK AG, SICK AG
Product
SICK LMS1000, SICK MRS1000
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16266

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__.

PUBLISHED
Vendor
n/a
Product
mongo-object
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16261

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.

PUBLISHED
Vendor
Unknown
Product
login-social
Provider severity
HIGH
Conflicts
1

CVE-2026-1626

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.

PUBLISHED
Vendor
SICK AG, SICK AG
Product
SICK MRS1000, SICK LMS1000
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16256

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.

PUBLISHED
Vendor
Unknown
Product
POUCO Import Users
Provider severity
Not asserted
Conflicts
0

CVE-2026-16254

A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4, Red Hat Quay 3, Red Hat Advanced Cluster Security 4, Red Hat Quay 3, Red Hat Advanced Cluster Security 4, Red Hat Advanced Cluster Security 4
Provider severity
MEDIUM
Conflicts
1

CVE-2026-16252

A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp?Shine ID=aaa. The manipulation of the argument Structure_ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Beijing Shenzhou Shihan Technology
Product
Multimedia Integrated Business Display System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.

PUBLISHED
Vendor
Unknown
Product
Personal QR Message
Provider severity
Not asserted
Conflicts
0

CVE-2026-1625

A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boafrm/formSmsManage of the component SMS Message. Performing a manipulation of the argument action_value results in command injection. The attack may be initiated remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
D-Link
Product
DWR-M961
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16248

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

PUBLISHED
Vendor
Tenda
Product
AC10
Provider severity
HIGH
Conflicts
2

CVE-2026-16247

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData% are deleted and replaced, granting the Windows group Everyone full control instead of restricting access to %ProgramData%\Bizerba\_connect.BRAIN or %ProgramData%\Bizerba\BCT. Starting with _connect.BRAIN 5.06, the setup no longer executes this tool.

PUBLISHED
Vendor
Bizerba SE & Co. KG
Product
_connect.BRAIN
Provider severity
HIGH
Conflicts
0

CVE-2026-16246

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full control over %ProgramData% instead of being restricted to %ProgramData%\Bizerba\BRAIN2\. Starting with BRAIN2 3.09, the setup no longer executes this tool. However, the optional component Bizerba ScriptService still executes it. Bizerba ScriptService is being deprecated and will no longer be included starting with BRAIN2 version 3.11.

PUBLISHED
Vendor
Bizerba SE & Co. KG
Product
BRAIN2
Provider severity
HIGH
Conflicts
0

CVE-2026-16244

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16243

In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse OMR
Provider severity
MEDIUM
Conflicts
0

CVE-2026-16242

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift API for Data Protection, OpenShift API for Data Protection, multicluster engine for Kubernetes 2.8, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.6, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.17, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, multicluster engine for Kubernetes 2.9, Multicluster Engine for Kubernetes, Logging Subsystem for Red Hat OpenShift, multicluster engine for Kubernetes 2.11, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4
Provider severity
CRITICAL
Conflicts
1

CVE-2026-1624

A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
D-Link
Product
DWR-M961
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16236

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affect

PUBLISHED
Vendor
realtyna
Product
Realtyna Organic IDX plugin + WPL Real Estate
Provider severity
HIGH
Conflicts
0

CVE-2026-16235

Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

PUBLISHED
Vendor
DRSTEVE
Product
Crypt::Password
Provider severity
CRITICAL
Conflicts
0

CVE-2026-16232

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this

PUBLISHEDCISA KEV
Vendor
checkpoint, checkpoint
Product
Multi-Domain Security Management, Quantum Security Management
Provider severity
CRITICAL
Conflicts
2

CVE-2026-1623

A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument FileName causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Totolink
Product
A7000R
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16229

A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Courier Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16228

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Class and Exam Timetabling System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16227

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Class and Exam Timetabling System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-16226

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.

PUBLISHED
Vendor
SourceCodester
Product
Pizzafy Ecommerce System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-16225

A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bounds write. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
davenardella
Product
snap7
Provider severity
MEDIUM
Conflicts
2