Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-13445

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (confidentiality breach). In overwrite mode, the attacker can replace victim file contents with arbitr

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
HIGH
Conflicts
0

CVE-2026-13444

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
HIGH
Conflicts
0

CVE-2026-13443

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in all versions up to, and including, 3.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
themeum
Product
Tutor LMS – eLearning and online course solution
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13442

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
HIGH
Conflicts
0

CVE-2026-13441

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the plugin's Gues

PUBLISHED
Vendor
metagauss
Product
EventPrime – Events Calendar, Bookings and Tickets
Provider severity
HIGH
Conflicts
0

CVE-2026-13440

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is possible because

PUBLISHED
Vendor
wedevs
Product
StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-1344

Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.

PUBLISHED
Vendor
Tanium
Product
Enforce Recovery Key Portal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13439

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a publicly-accessible nonce refresh endpoint (Emsfb/v1/nonce/refresh) that issues valid WordPress REST nonces to unauthenticated visitors. This makes it possible

PUBLISHED
Vendor
hassantafreshi
Product
Easy Form Builder by WhiteStudio – Drag & Drop Form Builder
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13437

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.

PUBLISHED
Vendor
Devolutions
Product
PowerShell Universal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13435

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13434

A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. The only admission check rejects empty strings; no DNS-1123 format validation, JSON detection, or special character rejection is performed. When the ExternalNetResourceInjection Beta feature ga

PUBLISHED
Vendor
Red Hat
Product
Red Hat OpenShift Virtualization 4
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13432

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher to deactivate the ThumbPress WordPress plugin before 6.2.2, disrupting the site's image-handling functionality.

PUBLISHED
Vendor
Unknown
Product
ThumbPress
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13430

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in ajax_import_media_start() uses pathinfo() on the raw ZIP entry name (e.g., 'shell.php.'), which returns an empty string for the extension, causing the allow-list guard to be skipped

PUBLISHED
Vendor
wpazleen
Product
Post Export Import with Media
Provider severity
HIGH
Conflicts
0

CVE-2026-1343

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.

PUBLISHED
Vendor
IBM, IBM, IBM, IBM
Product
Verify Identity Access, Security Verify Access Container, Verify Identity Access Container, Security Verify Access
Provider severity
HIGH
Conflicts
1

CVE-2026-13426

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532

PUBLISHED
Vendor
Mattermost
Product
github.com/mattermost/mattermost/server/public
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13425

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by unauthenticated attackers because Contact Form 7 accepts array-structured input for ordinary text field

PUBLISHED
Vendor
code4life
Product
Database for CF7
Provider severity
HIGH
Conflicts
0

CVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.

PUBLISHED
Vendor
Unknown
Product
Streamit
Provider severity
CRITICAL
Conflicts
1

CVE-2026-13422

The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and questions, create new quizzes, and change plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
harmonic_design
Product
HD Quiz
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1342

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

PUBLISHED
Vendor
IBM, IBM, IBM, IBM
Product
Verify Identity Access, Security Verify Access, Verify Identity Access Container, Security Verify Access Container
Provider severity
HIGH
Conflicts
1

CVE-2026-13410

Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and googleapis.com can intercept the OAuth2 token exchange and userinfo fetch, return a forged access_token and user profile, and be logged in to the Dancer application as any Google user.

PUBLISHED
Vendor
GARU
Product
Dancer::Plugin::Auth::Google
Provider severity
HIGH
Conflicts
0

CVE-2026-1341

Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

PUBLISHED
Vendor
Avation
Product
Avation Light Engine Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13402

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.

PUBLISHED
Vendor
Unknown
Product
Royal Addons for Elementor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13401

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.

PUBLISHED
Vendor
CODECHILD
Product
XML::Bare
Provider severity
HIGH
Conflicts
0

CVE-2026-13400

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.

PUBLISHED
Vendor
Unknown
Product
Simply Schedule Appointments
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1340

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

PUBLISHEDCISA KEV
Vendor
Ivanti
Product
Endpoint Manager Mobile
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13397

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition. Note that the latest version available on CPAN is version 0.02. Newer versions are available on the git repository.

PUBLISHED
Vendor
CODECHILD
Product
HTML::Bare
Provider severity
HIGH
Conflicts
0

CVE-2026-13395

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.

PUBLISHED
Vendor
Unknown
Product
Online Scheduling and Appointment Booking System
Provider severity
HIGH
Conflicts
1

CVE-2026-13393

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the ses

PUBLISHED
Vendor
Unknown
Product
ElementsKit Elementor Addons
Provider severity
LOW
Conflicts
1

CVE-2026-13392

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution

PUBLISHED
Vendor
Unknown
Product
ElementsKit Elementor Addons
Provider severity
HIGH
Conflicts
1

CVE-2026-13390

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a hidden comment record.

PUBLISHED
Vendor
Unknown
Product
The Events Calendar
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13389

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.

PUBLISHED
Vendor
Unknown
Product
webtoffee-cookie-consent
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13385

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the '  Security Update for ASUS Router Firmware  ' section on the ASUS Security Advisory for more information.

PUBLISHED
Vendor
ASUS
Product
Router
Provider severity
CRITICAL
Conflicts
1

CVE-2026-13384

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
HIGH
Conflicts
0

CVE-2026-13383

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
HIGH
Conflicts
0

CVE-2026-13381

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.

PUBLISHED
Vendor
VSee, VSee
Product
Clinic, Clinic
Provider severity
HIGH
Conflicts
1

CVE-2026-13380

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated S

PUBLISHED
Vendor
VSee, VSee
Product
Clinic, Clinic
Provider severity
CRITICAL
Conflicts
2

CVE-2026-1338

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

PUBLISHED
Vendor
OpenVPN
Product
OpenVPN
Provider severity
MEDIUM
Conflicts
1

CVE-2026-13378

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wpvibes
Product
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database
Provider severity
HIGH
Conflicts
0

CVE-2026-13377

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13376

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13375

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13374

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13373

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-13372

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.

PUBLISHED
Vendor
Devolutions
Product
Remote Desktop Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-13371

An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1337

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain text if using versions prior to 2026.01. Proof of concept exploit:  https://github.com/JoakimBulow/CVE-2026-1337

PUBLISHED
Vendor
neo4j, neo4j
Product
Community Edition, Enterprise Edition
Provider severity
LOW
Conflicts
1

CVE-2026-13369

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a client-supplied saveProgress flag, bypassing all upload validation, path normalization, and database record creation steps, and allowing an attacker-supplied file_path value to reach

PUBLISHED
Vendor
SaturdayDrive
Product
Ninja Forms - File Uploads
Provider severity
HIGH
Conflicts
0

CVE-2026-13368

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-13362

The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to create a sendpulse_form post

PUBLISHED
Vendor
sendpulse
Product
SendPulse Email Marketing Newsletter
Provider severity
MEDIUM
Conflicts
0