Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-65450

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

PUBLISHED
Vendor
RomanCode
Product
MapSVG
Provider severity
HIGH
Conflicts
0

CVE-2026-65449

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

PUBLISHED
Vendor
RomanCode
Product
MapSVG
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65448

Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

PUBLISHED
Vendor
AcyMailing Newsletter Team
Product
Anti Spam and list cleaner &#8211; AcyChecker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65447

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

PUBLISHED
Vendor
Wasiliy Strecker / ContestGallery developer
Product
Contest Gallery
Provider severity
HIGH
Conflicts
0

CVE-2026-65446

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

PUBLISHED
Vendor
WP Chill
Product
Kali Forms
Provider severity
HIGH
Conflicts
0

CVE-2026-65445

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

PUBLISHED
Vendor
iSaumya
Product
Ad Invalid Click Protector (AICP)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65443

Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

PUBLISHED
Vendor
WP Media
Product
BackWPup
Provider severity
HIGH
Conflicts
0

CVE-2026-65442

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

PUBLISHED
Vendor
Subtle Web Inc
Product
FormCraft
Provider severity
HIGH
Conflicts
0

CVE-2026-65441

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

PUBLISHED
Vendor
Nexcess
Product
GiveWP
Provider severity
HIGH
Conflicts
0

CVE-2026-65440

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

PUBLISHED
Vendor
Roxnor
Product
GetGenie
Provider severity
HIGH
Conflicts
0

CVE-2026-65439

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

PUBLISHED
Vendor
Themefic
Product
Ultimate Addons for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-65438

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

PUBLISHED
Vendor
Kofi Mokome
Product
Message Filter for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-65437

Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

PUBLISHED
Vendor
CleanTalk Inc
Product
Spam protection, AntiSpam, FireWall by CleanTalk
Provider severity
HIGH
Conflicts
0

CVE-2026-65436

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

PUBLISHED
Vendor
Themeum
Product
Kirki
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65435

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

PUBLISHED
Vendor
Thrive Themes Coupon
Product
Thrive Leads Version
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65434

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

PUBLISHED
Vendor
yoomoney
Product
ЮKassa для WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65433

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

PUBLISHED
Vendor
themewant
Product
RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65431

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

PUBLISHED
Vendor
regularlabs.com
Product
GeoIP extension for Joomla
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65430

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

PUBLISHED
Vendor
regularlabs.com
Product
GeoIP extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-6543

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

PUBLISHED
Vendor
IBM
Product
Langflow Desktop
Provider severity
HIGH
Conflicts
0

CVE-2026-65423

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

PUBLISHED
Vendor
o6 Automation
Product
open62541
Provider severity
HIGH
Conflicts
1

CVE-2026-65421

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

PUBLISHED
Vendor
MZ Automation GmbH
Product
libiec61850
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-6542

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for another user's flow.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6541

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-00653

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special R

PUBLISHED
Vendor
Tigera, Tigera, Tigera
Product
Calico Enterprise, Calico Cloud, Calico
Provider severity
HIGH
Conflicts
2

CVE-2026-6539

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.

PUBLISHED
Vendor
Notepad++
Product
Notepad++
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6538

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6537

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6536

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6535

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6534

USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6533

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65325

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Traffic Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65324

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Traffic Server
Provider severity
HIGH
Conflicts
1

CVE-2026-65321

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax

PUBLISHED
Vendor
laughingman7743
Product
PyAthena
Provider severity
CRITICAL
Conflicts
1

CVE-2026-6532

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65319

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and extract plain-text content of all stored articles, including private newsletter content, personal page-

PUBLISHED
Vendor
Feedbin
Product
Feedbin
Provider severity
HIGH
Conflicts
1

CVE-2026-65318

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database

PUBLISHED
Vendor
Weaviate
Product
Verba
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-65317

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and port parameters to the

PUBLISHED
Vendor
Weaviate
Product
Verba
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-65316

XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can enumerate log records across all job groups by calling the logDetailCat endpoint with incremented logId parameter values, bypassing the permission check present in the sibling logDetailPage endpoint, and retrieve sensitiv

PUBLISHED
Vendor
xuxueli
Product
xxl-job
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-65315

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array counts that are used as allocation sizes without validation against remaining file size. Attackers can upload a sub-1KB crafted GGUF file via the blob upload and model create or pull API endpoints to

PUBLISHED
Vendor
Ollama
Product
Ollama
Provider severity
HIGH
Conflicts
1

CVE-2026-65314

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions.

PUBLISHED
Vendor
ElectricSQL
Product
Electric Postgres Sync
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65313

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

PUBLISHED
Vendor
ANDRITZ, ANDRITZ
Product
HIPASE-250, 250 SCALA
Provider severity
HIGH
Conflicts
2

CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.

PUBLISHED
Vendor
ANDRITZ, ANDRITZ
Product
250 SCALA, HIPASE-250
Provider severity
MEDIUM
Conflicts
2

CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.

PUBLISHED
Vendor
ANDRITZ, ANDRITZ
Product
HIPASE-250, 250 SCALA
Provider severity
HIGH
Conflicts
2

CVE-2026-6531

SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65309

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.

PUBLISHED
Vendor
ANDRITZ, ANDRITZ
Product
HIPASE-250, 250 SCALA
Provider severity
HIGH
Conflicts
2

CVE-2026-6530

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6529

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6528

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
MEDIUM
Conflicts
0