Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-10600

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-1060

The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.7.7 via the /wp-json/adminify/v1/get-addons-list REST API endpoint. The endpoint is registered with permission_callback set to __return_true, allowing unauthenticated attackers to retrieve the complete list of available addons, their installation status, version numbers, and download URLs.

PUBLISHED
Vendor
litonice13
Product
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10597

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.

PUBLISHED
Vendor
ITPison
Product
OMICARD EDM
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10593

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes attacker-controlled QoS fields (interval, framing, phy, sdu, rtn, latency, pd) through the stream->qos pointer with only a stream != NULL guard. stream->qos is NULL for any stream that has been codec-configured via bt_bap_stream_config() but not yet added to a unicast group (it i

PUBLISHED
Vendor
zephyrproject
Product
zephyr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10592

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rejected by the issuing CA's permitted/excluded DNS name constraints could be accepted.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10591

Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.

PUBLISHED
Vendor
AWS
Product
Kiro IDE
Provider severity
HIGH
Conflicts
1

CVE-2026-10590

A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.

PUBLISHED
Vendor
Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo
Product
IdeaPad Pro 5 16AGP11 BIOS, Legion Pro 5 16IRX10 BIOS, Legion Pro 5 16IRX9 BIOS, IdeaPad Slim 3 16IRH8 BIOS, Legion 5 15APH9 BIOS, Legion Pro 7 16ARX8H BIOS, Legion Pro 7 16ADR10H BIOS, Yoga Pro 7 15IPH11 BIOS, ThinkBook Plus G6 Rollable BIOS, ThinkBook Plus G4 IRU BIOS, Legion Pro 7 16IRX9H BIOS, Lenovo S14 G3 IAP BIOS, Yoga Book 9 13IMU9 BIOS, Lenovo V15 G4 AMN BIOS, Legion Slim 5 14APH8 BIOS, IdeaPad Slim 3 14ITN9 BIOS, Legion 5 15AKP10 BIOS, Legion 5 15IAX10 BIOS, Lenovo V15 G2 IJL Laptop BIOS, Legion Pro 5 16ADR10 BIOS, Legion 7 16AGP11 BIOS, Legion 5 15IRX10 BIOS, Legion Pro 5 16AFR10 BIOS, Yoga 9 14IRP8 BIOS, Legion Pro 5 16ARX8 BIOS, ThinkBook 16p G6 IAX BIOS, Lenovo V15 G6 ARP BIOS, Yoga 9 2-in-1 14IMH9 BIOS, IdeaPad Pro 5 16IMH9 BIOS, IdeaPad Slim 3 15AMN8 BIOS, LOQ 15ARP10E BIOS, Legion 5 15IRX9 BIOS, Legion Pro 7 16AFR10H BIOS, IdeaPad Slim 3 16IRH10R BIOS, ThinkBook 16p G6 ADR BIOS, Legion Pro 5 16IAX10 BIOS, Legion 7 16IAX10 BIOS, Lenovo V15 G4 IAH BIOS, Yoga 9 2-in-1 14ILL10 BIOS, IdeaPad Pro 5 16IPH11 BIOS, Legion Pro 7 16ARX8H BIOS, ThinkBook 16p G5 IRX BIOS, IdeaPad Slim 3 16ARP10 BIOS, Yoga Pro 9 14IRP8 BIOS, Legion Pro 5 16ADR10 BIOS, IdeaPad Pro 5 16IAH10 BIOS, IdeaPad 5 15ABA7 BIOS, LOQ 15IAX9E BIOS, Lenovo V14 G6 ITN BIOS, IdeaPad Pro 5 16ASP10 BIOS, IdeaPad Pro 5 16IRH8 BIOS, Legion Pro 7 16IAX10H BIOS, Legion 5 15AHP10 BIOS, Yoga Book 9 14IAH10 BIOS, ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS, IdeaPad Slim 3 16IRU9 BIOS, Yoga Pro 9 16IMH9 BIOS, Legion 9 16IRX9 BIOS, Lenovo V15 G5 IRL BIOS, Yoga Book 9 14IAH10 BIOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-1059

A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknown functionality of the file /src/chkuser.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated

PUBLISHED
Vendor
FeMiner
Product
wms
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-10589

A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

PUBLISHED
Vendor
Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo
Product
ThinkBook 16p G5 IRX BIOS, IdeaPad Pro 5 16AGP11 BIOS, Yoga Book 9 14IAH10 BIOS, Yoga 9 2-in-1 14IMH9 BIOS, Legion Pro 5 16ADR10 BIOS, Lenovo V15 G5 IRL BIOS, Yoga Pro 7 15IPH11 BIOS, Legion Pro 7 16ARX8H BIOS, ThinkBook Plus G6 Rollable BIOS, Yoga Pro 9 14IRP8 BIOS, Legion Pro 7 16ARX8H BIOS, Legion 7 16AGP11 BIOS, Legion Slim 5 14APH8 BIOS, Lenovo V14 G6 ITN BIOS, IdeaPad 5 15ABA7 BIOS, Legion Pro 7 16ADR10H BIOS, IdeaPad Slim 3 16IRU9 BIOS, IdeaPad Slim 3 16ARP10 BIOS, Legion Pro 5 16IRX9 BIOS, LOQ 15ARP10E BIOS, ThinkBook Plus G4 IRU BIOS, IdeaPad Slim 3 15AMN8 BIOS, Legion Pro 5 16ADR10 BIOS, IdeaPad Slim 3 16IRH10R BIOS, Lenovo V15 G6 ARP BIOS, Legion Pro 5 16ARX8 BIOS, Yoga Book 9 14IAH10 BIOS, ThinkBook 16p G6 IAX BIOS, Legion 5 15APH9 BIOS, IdeaPad Slim 3 16IRH8 BIOS, Legion Pro 5 16IRX10 BIOS, IdeaPad Pro 5 16ASP10 BIOS, Legion 7 16IAX10 BIOS, Legion Pro 7 16IAX10H BIOS, IdeaPad Pro 5 16IPH11 BIOS, Legion Pro 7 16IRX9H BIOS, Legion 5 15IAX10 BIOS, Yoga 9 2-in-1 14ILL10 BIOS, Legion 5 15IRX10 BIOS, Legion 9 16IRX9 BIOS, Legion 5 15AHP10 BIOS, Lenovo V15 G4 AMN BIOS, IdeaPad Pro 5 16IRH8 BIOS, Legion Pro 5 16IAX10 BIOS, ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS, Lenovo S14 G3 IAP BIOS, Legion 5 15AKP10 BIOS, Lenovo V15 G4 IAH BIOS, Lenovo V15 G2 IJL Laptop BIOS, Legion 5 15IRX9 BIOS, Legion Pro 5 16AFR10 BIOS, Yoga Pro 9 16IMH9 BIOS, Yoga Book 9 13IMU9 BIOS, LOQ 15IAX9E BIOS, IdeaPad Pro 5 16IAH10 BIOS, Yoga 9 14IRP8 BIOS, IdeaPad Slim 3 14ITN9 BIOS, ThinkBook 16p G6 ADR BIOS, IdeaPad Pro 5 16IMH9 BIOS, Legion Pro 7 16AFR10H BIOS
Provider severity
MEDIUM
Conflicts
3

CVE-2026-10588

A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

PUBLISHED
Vendor
Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo
Product
Legion 5 15APH9 BIOS, IdeaPad Slim 3 15AMN8 BIOS, Legion 5 15IAX10 BIOS, Yoga 9 2-in-1 14ILL10 BIOS, IdeaPad Slim 3 16IRH10R BIOS, Yoga 9 14IRP8 BIOS, Lenovo V15 G4 AMN BIOS, Legion Pro 5 16IAX10 BIOS, Legion 5 15IRX9 BIOS, Legion Pro 7 16ARX8H BIOS, Legion Pro 5 16IRX10 BIOS, ThinkBook 16p G5 IRX BIOS, Legion Slim 5 14APH8 BIOS, IdeaPad Pro 5 16IPH11 BIOS, IdeaPad Pro 5 16ASP10 BIOS, Legion 7 16IAX10 BIOS, Legion 5 15AKP10 BIOS, Yoga 9 2-in-1 14IMH9 BIOS, IdeaPad Pro 5 16IMH9 BIOS, Yoga Pro 7 15IPH11 BIOS, Lenovo V15 G6 ARP BIOS, ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS, Yoga Pro 9 16IMH9 BIOS, IdeaPad Pro 5 16IRH8 BIOS, IdeaPad Slim 3 16ARP10 BIOS, Lenovo V15 G5 IRL BIOS, Legion 5 15AHP10 BIOS, IdeaPad Slim 3 14ITN9 BIOS, Legion Pro 7 16IRX9H BIOS, ThinkBook Plus G4 IRU BIOS, Lenovo V15 G4 IAH BIOS, Legion 7 16AGP11 BIOS, Legion Pro 7 16ADR10H BIOS, Yoga Pro 9 14IRP8 BIOS, IdeaPad Pro 5 16AGP11 BIOS, IdeaPad Pro 5 16IAH10 BIOS, Legion Pro 7 16AFR10H BIOS, LOQ 15ARP10E BIOS, IdeaPad Slim 3 16IRH8 BIOS, Lenovo V14 G6 ITN BIOS, Lenovo S14 G3 IAP BIOS, Legion Pro 5 16ADR10 BIOS, Legion Pro 7 16IAX10H BIOS, ThinkBook 16p G6 ADR BIOS, Yoga Book 9 14IAH10 BIOS, IdeaPad 5 15ABA7 BIOS, Yoga Book 9 13IMU9 BIOS, Legion 5 15IRX10 BIOS, LOQ 15IAX9E BIOS, ThinkBook 16p G6 IAX BIOS, IdeaPad Slim 3 16IRU9 BIOS, Legion Pro 7 16ARX8H BIOS, Legion Pro 5 16IRX9 BIOS, Legion 9 16IRX9 BIOS, Yoga Book 9 14IAH10 BIOS, Legion Pro 5 16AFR10 BIOS, Lenovo V15 G2 IJL Laptop BIOS, ThinkBook Plus G6 Rollable BIOS, Legion Pro 5 16ARX8 BIOS, Legion Pro 5 16ADR10 BIOS
Provider severity
MEDIUM
Conflicts
3

CVE-2026-10587

A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

PUBLISHED
Vendor
Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo, Lenovo
Product
Legion Pro 7 16AFR10H BIOS, Yoga 9 2-in-1 14ILL10 BIOS, ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS, Lenovo V15 G4 IAH BIOS, Legion Pro 7 16IAX10H BIOS, Lenovo V15 G4 AMN BIOS, Legion Pro 5 16ADR10 BIOS, Legion Pro 5 16IRX10 BIOS, Yoga Book 9 14IAH10 BIOS, Legion Pro 5 16AFR10 BIOS, IdeaPad Pro 5 16IRH8 BIOS, Legion Pro 7 16ARX8H BIOS, IdeaPad Pro 5 16IAH10 BIOS, Lenovo V14 G6 ITN BIOS, Yoga Pro 9 14IRP8 BIOS, Legion 5 15IRX10 BIOS, LOQ 15ARP10E BIOS, Yoga Pro 9 16IMH9 BIOS, ThinkBook Plus G4 IRU BIOS, IdeaPad Slim 3 16IRH10R BIOS, Yoga 9 2-in-1 14IMH9 BIOS, ThinkBook 16p G6 IAX BIOS, IdeaPad Pro 5 16ASP10 BIOS, Legion Pro 5 16ARX8 BIOS, Yoga Pro 7 15IPH11 BIOS, Legion Pro 7 16IRX9H BIOS, Legion Pro 7 16ADR10H BIOS, IdeaPad Slim 3 16IRU9 BIOS, Legion Pro 5 16IAX10 BIOS, IdeaPad Slim 3 16ARP10 BIOS, Lenovo V15 G6 ARP BIOS, Legion Pro 7 16ARX8H BIOS, Lenovo V15 G5 IRL BIOS, IdeaPad 5 15ABA7 BIOS, Legion 5 15IRX9 BIOS, Legion 5 15APH9 BIOS, ThinkBook 16p G6 ADR BIOS, Yoga Book 9 13IMU9 BIOS, Lenovo V15 G2 IJL Laptop BIOS, Legion Pro 5 16IRX9 BIOS, IdeaPad Pro 5 16AGP11 BIOS, IdeaPad Slim 3 14ITN9 BIOS, ThinkBook 16p G5 IRX BIOS, IdeaPad Pro 5 16IMH9 BIOS, Legion 5 15IAX10 BIOS, Legion 7 16AGP11 BIOS, Legion 5 15AKP10 BIOS, Yoga 9 14IRP8 BIOS, Legion 5 15AHP10 BIOS, LOQ 15IAX9E BIOS, Legion 9 16IRX9 BIOS, Legion 7 16IAX10 BIOS, IdeaPad Slim 3 15AMN8 BIOS, Lenovo S14 G3 IAP BIOS, IdeaPad Slim 3 16IRH8 BIOS, Legion Slim 5 14APH8 BIOS, Yoga Book 9 14IAH10 BIOS, Legion Pro 5 16ADR10 BIOS, ThinkBook Plus G6 Rollable BIOS, IdeaPad Pro 5 16IPH11 BIOS
Provider severity
MEDIUM
Conflicts
3

CVE-2026-10586

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PUBLISHED
Vendor
wpdevteam
Product
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
Provider severity
HIGH
Conflicts
0

CVE-2026-10585

A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not escape user-controlled Discussion titles before embedding them in a <script type="application/ld+json"> block, allowing the title to break out of the script context. The injection w

PUBLISHED
Vendor
GitHub
Product
Enterprise Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10584

Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.

PUBLISHED
Vendor
AWS
Product
Graph Explorer
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-10583

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.

PUBLISHED
Vendor
nextlevelbuilder
Product
GoClaw
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10581

A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used.

PUBLISHED
Vendor
n/a
Product
DedeCMS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10580

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrators and unauthenticated visitors — a value that HippooPermissions::has_role_access() unconditionally interprets as full administrator access — causing override_extension_permission

PUBLISHED
Vendor
hippooo
Product
Hippoo Mobile App for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-1058

The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses html_entity_decode() on user-supplied hidden field values without subsequent escaping before output, which converts HTML entity-encoded payloads back into executable JavaScript. This makes it possible for unauthenticated

PUBLISHED
Vendor
10web
Product
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-10577

A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device.

PUBLISHED
Vendor
Rockwell Auotmation
Product
1715 EtherNet/IP Communications Module
Provider severity
CRITICAL
Conflicts
0

CVE-2026-10573

A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.

PUBLISHED
Vendor
Rockwell Automation
Product
1734 POINT I/O
Provider severity
HIGH
Conflicts
0

CVE-2026-10570

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping in the symp_arfe_replace_content() function, which uses str_replace() to substitute raw ACF field values (retrieved via get_field()) directly into Elementor-rendered HTML without any escaping. This makes it possible for authenticated attackers, with Aut

PUBLISHED
Vendor
idocoh
Product
Sympl Repeater for ACF and Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10569

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.

PUBLISHED
Vendor
IBM, IBM
Product
UCD - IBM DevOps Deploy, UCD - IBM UrbanCode Deploy
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10568

A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Fees Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-10567

A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.7.0 will fix this issue. The identifier of the patch is c87682afa8df79853299f7

PUBLISHED
Vendor
1Panel-dev
Product
CordysCRM
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-10566

A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the argument mapping can lead to deserialization. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
FoundationAgents
Product
MetaGPT
Provider severity
MEDIUM
Conflicts
2

CVE-2026-10565

A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

PUBLISHED
Vendor
n/a
Product
Open5GS
Provider severity
LOW
Conflicts
1

CVE-2026-10564

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An authenticated attacker can exploit this to access internal resources including cloud metadata services (AWS/Azure/GCP IMDS), potentially exfiltrating IAM credentials and enumerating internal networks. The vulnerability can al

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
HIGH
Conflicts
0

CVE-2026-10562

An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface.  An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences. When processed by the embedded web server, these inputs may cause the device to respond with HTTP 3xx redirects to attacker-controlled external domains. This issue affects Archer AX20 V2.0: through 2.1.9 Build 20230829.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Archer AX20 V2.0
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10561

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-10560

IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
HIGH
Conflicts
0

CVE-2026-1056

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PUBLISHED
Vendor
inc2734
Product
Snow Monkey Forms
Provider severity
CRITICAL
Conflicts
0

CVE-2026-10559

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Pizzafy Ecommerce System
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10558

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Pizzafy Ecommerce System
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10557

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are readily extractable via APK decompilation. The credentials provide access to cloud MQTT brokers carrying real-time telemetry for the entire global Yarbo robot fleet. They allow both wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the robot's se

PUBLISHED
Vendor
Yarbo, Yarbo
Product
Yarbo Android/IOS mobile application, Yarbo Cloud MQTT infrastructure
Provider severity
CRITICAL
Conflicts
2

CVE-2026-10553

The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the jqFootnotes_options_subpanel function. This makes it possible for unauthenticated attackers to update the plugin's settings with arbitrary values that, because option values such as jqfoot_anchor_open, jqfoot_anchor_close, and jqfoot_title are echoed unescaped into frontend page content, can be chained i

PUBLISHED
Vendor
weaverlancegmailcom
Product
jQuery Hover Footnotes
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10552

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validation on the main admin panel (blcap_main_page) and on the Hall of Shame and Log subpages, which accept a 'blcap_action' / 'action' parameter from $_REQUEST and perform destructive operations (plugin uninstall via blcap_uninstall(), log deletion via blcap_delete_logs(), Hall of Shame deletion via blcap_delete_ip_db(), and adding I

PUBLISHED
Vendor
jotis
Product
Blue Captcha
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10551

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML minification process and abusing a regular expression. This allows an attacker to inject arbitrary HTML attributes in the final HTML output by anticipating the placeholder format.

PUBLISHED
Vendor
Unknown
Product
Breeze Cache
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10550

A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manipulation of the argument uploadPath causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
elunez
Product
eladmin
Provider severity
MEDIUM
Conflicts
2

CVE-2026-1055

The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disab

PUBLISHED
Vendor
talkjs
Product
TalkJS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10549

LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to the database.

PUBLISHED
Vendor
Yandex
Product
Yandex Database
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10548

A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way

PUBLISHED
Vendor
NousResearch
Product
hermes-agent
Provider severity
MEDIUM
Conflicts
1

CVE-2026-10546

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding.

PUBLISHED
Vendor
IBM
Product
Langflow OSS
Provider severity
HIGH
Conflicts
0

CVE-2026-10545

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.

PUBLISHED
Vendor
IBM
Product
Planning Analytics Local
Provider severity
HIGH
Conflicts
0

CVE-2026-10544

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10540

The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions

PUBLISHED
Vendor
BMC
Product
Control-M/Enterprise Manager
Provider severity
MEDIUM
Conflicts
1

CVE-2026-1054

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.

PUBLISHED
Vendor
metagauss
Product
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Provider severity
MEDIUM
Conflicts
0

CVE-2026-10539

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.

PUBLISHED
Vendor
BMC
Product
Control-M/Server
Provider severity
CRITICAL
Conflicts
1

CVE-2026-10538

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.

PUBLISHED
Vendor
BMC, BMC
Product
Control-M/Server, Control-M/Enterprise Manager
Provider severity
HIGH
Conflicts
2

CVE-2026-10536

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

PUBLISHED
Vendor
curl
Product
curl
Provider severity
CRITICAL
Conflicts
0

CVE-2026-10535

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.

PUBLISHED
Vendor
IBM
Product
Db2
Provider severity
HIGH
Conflicts
0