Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-13692

The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.

PUBLISHED
Vendor
Unknown
Product
PayU CommercePro Plugin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13690

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.

PUBLISHED
Vendor
Unknown
Product
UsersWP
Provider severity
HIGH
Conflicts
1

CVE-2026-1369

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

PUBLISHED
Vendor
Unknown
Product
Conditional CAPTCHA
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1368

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

PUBLISHED
Vendor
Unknown
Product
Video Conferencing with Zoom
Provider severity
HIGH
Conflicts
1

CVE-2026-13676

A flaw was found in fast-uri. This vulnerability occurs because fast-uri fails to properly convert Unicode (Internationalized Domain Name - IDN) hostnames for HTTP-family URLs. This can lead to a situation where security policies, such as denylists or redirect validations, are bypassed when applications use fast-uri to enforce these policies before passing the URL to another parser. A remote attacker could exploit this to circumvent security controls and potentially access unauthorized resources

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, fast-uri, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat build of Apicurio Registry 3, Red Hat Ansible Automation Platform 2, Red Hat Quay 3.16, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Virtualization 4, Red Hat Enterprise Linux AI (RHEL AI) 3, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, OpenShift Lightspeed, OpenShift Serverless, OpenShift Serverless, Red Hat Satellite 6, Red Hat OpenShift Container Platform 4.21, OpenShift Serverless, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, OpenShift Serverless, Red Hat Discovery 2, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat Satellite 6, Red Hat build of Apache Camel - HawtIO 4, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Red Hat OpenShift Container Platform 4.2, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 3, OpenShift Serverless, Red Hat Openshift Data Foundation 4, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, Network Observability Operator, Self-service automation portal 2, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, OpenShift Pipelines, fast-uri, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat Migration Toolkit for Applications 8.2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.2, Red Hat Developer Hub 1.10, Red Hat Openshift Data Foundation 4, OpenShift Serverless, Red Hat Satellite 6, Red Hat Developer Hub 1.10, Red Hat Edge Manager 1.1, Red Hat Data Grid 8, Red Hat OpenShift AI (RHOAI), Cryostat 4, Red Hat Quay 3.9, Red Hat OpenShift Dev Spaces 3.29, Red Hat Build of Podman Desktop, Red Hat Connectivity Link 1, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), OpenShift Pipelines, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Network Observability Operator, OpenShift Pipelines, Red Hat OpenShift Container Platform 4, OpenShift Lightspeed, Red Hat Openshift Data Foundation 4, Red Hat OpenShift Container Platform 4.22, Confidential Compute Attestation, OpenShift Serverless, Red Hat AMQ Broker 7, Red Hat Openshift Data Foundation 4, OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3, Multicluster Engine for Kubernetes, OpenShift Lightspeed, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9, Cryostat 4, Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.10, OpenShift Serverless, Red Hat Edge Manager 1.1, Red Hat Migration Toolkit 1.8
Provider severity
HIGH
Conflicts
3

CVE-2026-1367

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine ADSelfService Plus
Provider severity
HIGH
Conflicts
0

CVE-2026-1365

Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Sayax Energy Technologies Inc.
Product
OSOS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1364

IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system administrative functionalities.

PUBLISHED
Vendor
JNC, JNC
Product
I6, IAQS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-1363

IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.

PUBLISHED
Vendor
JNC, JNC
Product
I6, IAQS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-1361

ASDA-Soft Stack-based Buffer Overflow Vulnerability

PUBLISHED
Vendor
Delta Electronics
Product
ASDA-Soft
Provider severity
HIGH
Conflicts
0

CVE-2026-13609

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9's front-end display surfaces, resulting in stored cross-site scripting that executes in the browser

PUBLISHED
Vendor
Unknown
Product
Frontend Admin by DynamiApps
Provider severity
HIGH
Conflicts
1

CVE-2026-13605

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.

PUBLISHED
Vendor
Unknown
Product
PhotoSwipe
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13604

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emits publicly on every front-end page, that forwards client-supplied event data to the configured Facebook Conversions API using the administrator's stored access token. This allows an unauthenticated visitor to inject arbitrary conversion events into the administrator's Facebook ads account and exhaust the configured API quota.

PUBLISHED
Vendor
Unknown
Product
Pixelavo
Provider severity
Not asserted
Conflicts
0

CVE-2026-13603

The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technology. The integration of Oppwa, following their official documentation, includes a step where the user is redirected from the payment provider back to our system with a query parameter like ?resourcePath=/v1/checkouts/{checkoutId}/payment in the URL. Our system is then supposed to fetch the status of the transaction from the URL given by baseUrl +

PUBLISHED
Vendor
pretix
Product
pretix-oppwa
Provider severity
CRITICAL
Conflicts
1

CVE-2026-13602

We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay contain a code path that is intended for the transport of session parameters from a tab with isolated cookies (e.g. in the pretix widget) to a new ta

PUBLISHED
Vendor
pretix, pretix, pretix, pretix, pretix, pretix, pretix, pretix
Product
pretix-sofort, pretix-payone, pretix-secuconnect, pretix-oppwa, pretix-saferpay, pretix-bitpay, pretix, pretix-mollie
Provider severity
HIGH
Conflicts
2

CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6
Provider severity
HIGH
Conflicts
1

CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suit

PUBLISHED
Vendor
buddypress
Product
BuddyPress
Provider severity
HIGH
Conflicts
0

CVE-2026-13597

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.

PUBLISHED
Vendor
Unknown
Product
微信二维码登陆
Provider severity
CRITICAL
Conflicts
1

CVE-2026-13596

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

PUBLISHED
Vendor
Unknown
Product
Participants Database
Provider severity
CRITICAL
Conflicts
1

CVE-2026-13595

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13593

CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and whitespace.

PUBLISHED
Vendor
GTERMARS
Product
CSS::Minifier::XS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13592

A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issue is the function BufWriter::append of the component EtherNet IP Message Handler. Performing a manipulation results in out-of-bounds write. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The pat

PUBLISHED
Vendor
liftoff-sr
Product
CIPster
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-13591

A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of the component Contact Tracking. This manipulation of the argument _channelType causes improper authorization. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. Patch name: 9b4aff0f106d

PUBLISHED
Vendor
DeepMyst
Product
Mysti
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-13590

A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/header/ModbusLayer.h of the component Modbus Protocol Handler. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been released to the public and may be used for attacks. The

PUBLISHED
Vendor
seladb
Product
PcapPlusPlus
Provider severity
MEDIUM
Conflicts
2

CVE-2026-1359

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the genolve_setOpt() function in all versions up to, and including, 5.0.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to update arbitrary WordPress options, including enabling user registration and setting the default role to administrator, resulting in privilege escalation.

PUBLISHED
Vendor
genolve
Product
Genolve – Genolve AI Business Graphics, AI Images
Provider severity
HIGH
Conflicts
0

CVE-2026-13589

A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand of the file Packet++/src/TelnetLayer.cpp of the component Telnet Subnegotiation Packet Handler. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is publicly available and might be used. The identifier of the patch is 98e671010bc7c87b958

PUBLISHED
Vendor
seladb
Product
PcapPlusPlus
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13588

A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMessage::getHandshakeVersion of the file Packet++/src/SSLHandshake.cpp of the component TLS Hello Handler. Executing a manipulation of the argument handshakeVersion can lead to heap-based buffer overflow. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been publicly disclos

PUBLISHED
Vendor
seladb
Product
PcapPlusPlus
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13587

A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the file light_pcapng.c of the component LightPcapNg Parser. Performing a manipulation of the argument captured_packet_length results in heap-based buffer overflow. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been made public and could be used.

PUBLISHED
Vendor
seladb
Product
PcapPlusPlus
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-13586

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
BC-JAVA, BC-LTS-JAVA, BC-FJA
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13585

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.

PUBLISHED
Vendor
ASUS, ASUS, ASUS
Product
Business Manager, System Control Interface v3, System Control Interface
Provider severity
HIGH
Conflicts
2

CVE-2026-13584

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSER

PUBLISHED
Vendor
Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation
Product
Block-type remote module with safety functions NZ2GNSS2-8TE-K, Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN, Block-type remote module NZ2GN12A42-16DTE, Motion Control Software SWM-G, Block-type remote module NZ2GN2B1-32TE, GOT3000 Series GT3712-XRBA, AC Servo MELSERVO-JET MR-JET-G, AC Servo MELSERVO-J5 MR-J5-G-LL, CC-Link IE TSN expansion unit FCU8-EX569, Master/local module RJ71GN11-T2, GOT3000 Series GT3715-XRBD, Block-type remote module with safety functions NZ2GNSS2-8D-K, Inverter FR-A800/F800/E800 Series FR-E800-E, Industrial Computer MELIPC series MI2532-W, Block-type remote module NZ2GN2S1-32DTE, Inverter FR-A800/F800/E800 Series FR-A8NCG, Analog-Digital converter module NZ2GN2B-60AD4, GOT3000 Series GT3708-XRBD, Block-type remote module NZ2GNCF1-32D, AC Servo MELSERVO-J5 MR-J5-G, GOT3000 Series GT3712-XRBD, Liner Track System MTR-S series Linear track control module MTR-SCU00-4G, CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M, Remote Station Communication LSI with GbE-PHY NZ2GACP620-60, Block-type remote module NZ2GNCE3-32D, Block-type remote module with safety functions NZ2GNS12A2-14DT, Motion module RD78G16, Block-type remote module with safety functions NZ2GNS12A2-16DTE, CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL, GOT3000 Series GT3715-XRBA, Inverter FR-A800/F800/E800 Series FR-E800-SCE, CC-Link IE TSN interface board NZ81GN11-SX, Liner Track System MTR-S series Linear track control module MTR-SCU00-PG, Block-type remote module NZ2GN12A42-16DT, Block-type remote module NZ2GN2B1-32DTE, AC Servo MELSERVO-J5 MR-J5-G-HS, CC-Link IE TSN Communication Unit GT25-J71GN13-T2, AC Servo MELSERVO-J5 MR-J5D-G4, AC Servo MELSERVO-J5 MR-MD333G, Block-type remote module NZ2GN2S1-16D, MELSEC MX Controller MX-R model MXR500-256, Inverter FR-A800/F800/E800 Series FR-A8NCG-S, Master/local module FX5-CCLGN-MS, Digital-Analog converter module NZ2GN2B-60DA4, MELSEC MX Controller MX-F model MXF100-16-N32, Master/local module RJ71GN11-SX, MELSEC MX Controller MX-F model MXF100-8-P32, Block-type remote module with safety functions NZ2GNSS2-16DTE-K, MELSEC MX Controller MX-R model MXR300-64, FPGA module NZ2GN2S-D41PD02, Motion module RD78GHV, MELSEC MX Controller MX-F model MXF100-16-P32, Block-type remote module NZ2GN2B1-16TE, Block-type remote module NZ2GN2S1-16TE, Remote Station Communication LSI with GbE-PHY NZ2GACP621-90, CC-Link IE TSN interface board NZ81GN11-T2, Block-type remote module NZ2GN2S1-32D, Block-type remote module NZ2GNCF1-32T, Block-type remote module NZ2GN2B1-16D, Remote station software development kit SW1DNC-GNSDK1S-M, Master/Local module Designated communication LSI NZ2GACP610-60, Block-type remote module NZ2GN12A4-16DE, Block-type remote module with safety functions NZ2GNSS2-8D, MELSEC MX Controller MX-R model MXR300-16, MELSEC MX Controller MX-R model MXR500-128, CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M, Block-type remote module NZ2GN2B1-16T, Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN, Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M, CC-Link IE TSN compatible coupler NZ2FT-GN, Motion module FX5-80SSC-G, Block-type remote module NZ2GN12A4-16D, Block-type remote module NZ2GN12A2-16TE, Block-type remote module NZ2GN2S1-16T, GOT3000 Series GT3712-WXCBD, Analog-Digital converter module NZ2GN2S-60AD4, Block-type remote module NZ2GN2B1-32T, Block-type remote module with safety functions NZ2GNSS2-8TE, FPGA module NZ2GN2S-D41P01, MELSEC MX Controller MX-R model MXR300-32, Remote Station Communication LSI with GbE-PHY NZ2GACP621-720, Block-type remote module NZ2GN2S1-32T, Motion module RD78G8, GOT3000 Series GT3710-XRBD, FPGA module NZ2GN2S-D41D01, Block-type remote module NZ2GN2B1-32DT, Block-type remote module with safety functions NZ2GNSS2-16DTE, MELSEC MX Controller MX-F model MXF100-8-N32, CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB, Motion module RD78GHW, Remote station software development kit SW1DNC-GNSDK2S-M, Motion module FX5-40SSC-G, Remote Station Communication LSI with GbE-PHY NZ2GACP620-300, GOT3000 Series GT3715-FHCBD, Block-type remote module NZ2GN2S1-32DT, Block-type remote module NZ2GN12A2-16T, GOT3000 Series GT3710-XRBA, GOT3000 Series GT3708-XRBA, AC Servo MELSERVO-J5 MR-J5-G-RJ, Block-type remote module NZ2GNCE3-32DT, Tension meter LM7-2LG, Block-type remote module NZ2GN2S1-32TE, Inverter FR-A800/F800/E800 Series FR-A800-GN, Master/local module RJ71GN11-EIP, Tension meter LM7-1LG, Motion Control Software SWM-G-N1, Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51, Motion Control Board MR-EM441G, AC Servo MELSERVO-J5 MR-J5W-G, AC Servo MELSERVO-JET MR-JET-G4-HS, Motion module RD78G64, Industrial Computer MELIPC series MI2332-W, Motion module RD78G4, Digital-Analog converter module NZ2GN2S-60DA4, Block-type remote module NZ2GN2B1-32D
Provider severity
HIGH
Conflicts
1

CVE-2026-13583

A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
EW-7478APC
Provider severity
HIGH
Conflicts
2

CVE-2026-13582

A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. This manipulation of the argument UserName/Password causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
EW-7478APC
Provider severity
HIGH
Conflicts
2

CVE-2026-13581

A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
EW-7478APC
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13580

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
EW-7478APC
Provider severity
HIGH
Conflicts
2

CVE-2026-1358

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

PUBLISHED
Vendor
Airleader GmbH
Product
Airleader Master
Provider severity
CRITICAL
Conflicts
1

CVE-2026-13579

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
itsourcecode
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13578

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing a manipulation of the argument editid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
itsourcecode
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13577

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available. The fallback session id is generated from a SHA-1 hash of a call to the built-in rand function, the absolute path of the Dancer2::Core::Role::SessionFactory module, an internal counter, the process id, the

PUBLISHED
Vendor
CROMEDOME
Product
Dancer2
Provider severity
HIGH
Conflicts
1

CVE-2026-13572

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of the argument patientid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Hospital Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13571

A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Simple Food Ordering System
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13570

A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Inventory Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-1357

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it does not terminate execution and instead passes the boolean false value to the phpseclib library's A

PUBLISHED
Vendor
wpvividplugins
Product
WPvivid — Backup, Migration & Staging
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13569

A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component API. Such manipulation of the argument click_like leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
weng-xianhu
Product
EyouCMS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13568

A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
SourceCodester
Product
Inventory Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-13567

A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
code-projects
Product
Online Music Site
Provider severity
MEDIUM
Conflicts
2

CVE-2026-13566

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /preview3.php. The manipulation of the argument course_year_section leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
SourceCodester
Product
Class and Exam Timetabling System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-13565

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_class1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
SourceCodester
Product
Class and Exam Timetabling System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-13564

A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
EW-7478APC
Provider severity
HIGH
Conflicts
2

CVE-2026-13563

A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Edimax
Product
EW-7478APC
Provider severity
HIGH
Conflicts
2