Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-0665

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0664

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wproyal
Product
Royal Addons for Elementor – Addons and Templates Kit for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0663

Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.

PUBLISHED
Vendor
M-Files Corporation
Product
M-Files Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0662

A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.

PUBLISHED
Vendor
Autodesk
Product
3ds Max
Provider severity
HIGH
Conflicts
0

CVE-2026-0661

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

PUBLISHED
Vendor
Autodesk
Product
3ds Max
Provider severity
HIGH
Conflicts
0

CVE-2026-0660

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

PUBLISHED
Vendor
Autodesk
Product
3ds Max
Provider severity
HIGH
Conflicts
0

CVE-2026-0659

A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

PUBLISHED
Vendor
Autodesk, Autodesk, Autodesk
Product
Arnold, USD for Arnold, 3ds Max
Provider severity
HIGH
Conflicts
1

CVE-2026-0658

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

PUBLISHED
Vendor
Unknown
Product
Five Star Restaurant Reservations
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0656

The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'check_ipaymu_response' function. This is due to the plugin not validating webhook request authenticity through signature verification or origin checks. This makes it possible for unauthenticated attackers to mark WooCommerce orders as paid by sending crafted POST requests to the webhook endpoint without any payment occurring, as well as enum

PUBLISHED
Vendor
ipaymu
Product
iPaymu Payment Gateway for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-0655

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authenticated adjacent attacker to read arbitrary files or cause denial of service.  This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Deco BE25 v1.0
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0654

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Deco BE25 v1.0
Provider severity
HIGH
Conflicts
0

CVE-2026-0653

On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without authorization, resulting in unauthorized device state manipulation but not full code execution.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc.
Product
Tapo D235 v1, Tapo C260 v1
Provider severity
HIGH
Conflicts
1

CVE-2026-0652

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
Tapo C260 v1
Provider severity
HIGH
Conflicts
0

CVE-2026-0651

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may

PUBLISHED
Vendor
TP Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc.
Product
Tapo C520WS v2.6, Tapo C260 v1, Tapo D235 v1
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0650

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.

PUBLISHED
Vendor
OpenFlagr
Product
Flagr
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0649

A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of the file /app/Jobs/Util/Import.php of the component Migration Import. The manipulation of the argument company_logo leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
invoiceninja
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0648

The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the return value of osek_get_counter(). Specifically, the current code checks if cntr_id equals 0u to determine failure, but @osek_get_counter() actually returns E_OS_SYS_STACK (defined as 12U) when it fails. This mismatch causes the error branch to never execute even when the counter pool is exhausted. As a result, when the c

PUBLISHED
Vendor
Eclipse Foundation
Product
Eclipse ThreadX
Provider severity
HIGH
Conflicts
0

CVE-2026-0647

An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of the device’s embedded web server’s availability.

PUBLISHED
Vendor
Rockwell Automation
Product
FLEX I/O EtherNet/IP Adapters
Provider severity
HIGH
Conflicts
0

CVE-2026-0646

A denial-of-service security issue exists within the 1794-AENTR adapter due to improper memory handling of CIP protocol requests. This vulnerability can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover.

PUBLISHED
Vendor
Rockwell Automation
Product
FLEX I/O EtherNet/IP Adapters
Provider severity
HIGH
Conflicts
0

CVE-2026-0643

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.

PUBLISHED
Vendor
projectworlds
Product
House Rental and Property Listing
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-0642

A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
projectworlds
Product
House Rental and Property Listing
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-0641

A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
WA300
Provider severity
MEDIUM
Conflicts
2

CVE-2026-0640

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Tenda
Product
AC23
Provider severity
HIGH
Conflicts
2

CVE-2026-0639

in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.

PUBLISHED
Vendor
OpenHarmony
Product
OpenHarmony
Provider severity
LOW
Conflicts
0

CVE-2026-0636

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
BC-JAVA, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, streams for Apache Kafka 2, Red Hat Data Grid 8, streams for Apache Kafka 3, Red Hat AMQ Broker 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift Dev Spaces 3.28, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Debezium 3, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apicurio Registry 3, Red Hat AMQ Clients, Red Hat Fuse 7, Red Hat AMQ Broker 7.12.7, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat OpenShift AI (RHOAI), Red Hat build of Debezium 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat AMQ Broker 7.13.5, Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform 8.1, Red Hat AMQ Clients, Red Hat Enterprise Linux 9, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 7, Red Hat Data Grid 8, Red Hat Enterprise Linux 8, Red Hat Fuse 7, Red Hat Data Grid 8, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, streams for Apache Kafka 2, Red Hat Fuse 7, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, OpenShift Developer Tools and Services, Red Hat OpenShift Dev Spaces 3.28, Red Hat Process Automation 7, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Cryostat 4, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat build of Debezium 3, Red Hat Process Automation 7, streams for Apache Kafka 3, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Single Sign-On 7, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 7, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Red Hat Fuse 7, Red Hat build of Quarkus 3.27.3.SP1, Red Hat Fuse 7, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, OpenShift Developer Tools and Services, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat Fuse 7, Red Hat build of Quarkus 3.20.6.SP1, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat build of Apicurio Registry 3, OpenShift Developer Tools and Services
Provider severity
MEDIUM
Conflicts
3

CVE-2026-0635

The Responsive Accordion Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resp_accordion_silder_save_images' function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify any slider's image metadata including titles, descriptions, alt text, and links.

PUBLISHED
Vendor
techknowprime
Product
Responsive Accordion Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0634

Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.

PUBLISHED
Vendor
TECNO Mobile
Product
TECNO Pova7 Pro 5G
Provider severity
HIGH
Conflicts
0

CVE-2026-0633

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0. This is due to the use of a forgeable cookie value derived only from the entry ID and current user ID without a server-side secret. This makes it possible for unauthenticated attackers to access form submission entry data via MetForm shortcodes for entries created within the transient TTL (default is 15 minutes

PUBLISHED
Vendor
roxnor
Product
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
Provider severity
LOW
Conflicts
0

CVE-2026-0632

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.12 via the 'saveDataSource' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PUBLISHED
Vendor
techjewel
Product
Fluent Forms Pro Add On Pack
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0631

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although sim

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc.
Product
Archer BE230 v1.2, Archer AXE75 v1
Provider severity
HIGH
Conflicts
1

CVE-2026-0630

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar

PUBLISHED
Vendor
TP Link Systems Inc., TP-Link Systems Inc.
Product
AXE75 v1.0, Archer BE230 v1.2
Provider severity
HIGH
Conflicts
1

CVE-2026-0629

Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc.
Product
VIGI Cx45 Series (C345/C445), VIGI C230I Mini, VIGI C540S / EasyCam C540S, VIGI C240 1.0, VIGI C440-W 2.0, VIGI Cx30I 1.0 Series (C230I 1.0/C330I 1.0/C430I 1.0), VIGI Cx20I 1.20 Series (C220I 1.20/C320I 1.20/C420I 1.20), VIGI InSight Sx25 Series (S225/S325/S425), VIGI C250, VIGI Cx40I 1.0 Series (C240I 1.0/C340I 1.0/C440I 1.0), VIGI InSight Sx55 Series (S355/S455), VIGI C540-W 2.0, VIGI Cx30I 1.20 Series (C230I 1.20/C330I 1.20/C430I 1.20), VIGI C540 2.0, VIGI Cx40I 1.20 Series (C240I 1.20/C340I 1.20/C440I 1.20), VIGI Cx55 Series (C355/C455), VIGI C540V, VIGI Cx20I 1.0 Series (C220I 1.0/C320I 1.0/C420I 1.0), VIGI Cx20 Series (C320/C420), VIGI C340 2.0, VIGI Cx85 Series (C385/C485), VIGI InSight Sx85 Series (S285/S385), VIGI InSight S655I, VIGI InSight Sx85PI Series (S385PI/S485PI), VIGI InSight Sx45ZI Series (S245ZI/S345ZI/S445ZI), VIGI C540-4G, VIGI InSight S345-4G, VIGI Cx30 1.20 Series (C230 1.20/C330 1.20/C430 1.20), VIGI C340-W 2.x Series (C340-W 2.0/C340-W 2.20), VIGI InSight Sx45 Series (S245/S345/S445), VIGI C340S, VIGI Cx30 1.0 Series (C230 1.0/C330 1.0/C430 1.0), VIGI C440 2.0, VIGI Cx50 Series (C350/C450)
Provider severity
HIGH
Conflicts
1

CVE-2026-0628

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-0627

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `<script>` tags while allowing other XSS vectors such as event handlers (onload, onerror, onmouseover), foreignObject elements, and SVG animation attributes. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scr

PUBLISHED
Vendor
mohammed_kaludi
Product
AMP for WP – Accelerated Mobile Pages
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0626

The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all versions up to, and including, 3.7.9 due to insufficient input sanitization and output escaping of the 'button_icon' parameter. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user access

PUBLISHED
Vendor
getwpfunnels
Product
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0625

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was lever

PUBLISHED
Vendor
D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link, D-Link
Product
DIR-905L, DSL-2640B, DNS-345, DIR-608, DIR-610, DIR-611, DSL-500, DSL-526B, DNS-325, DSL-500G, DSL-2740R, DIR-615, DIR-600, DNS-320, DSL-2640T, DSL-2780B, DSL-502G
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0622

Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

PUBLISHED
Vendor
NewPlane
Product
open5GS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0621

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can trigger catastrophic backtracking on specially crafted inputs, resulting in excessive CPU consumption. An attacker can exploit this by supplying a malicious URI that causes the Node.

PUBLISHED
Vendor
Anthropic
Product
MCP TypeScript SDK
Provider severity
HIGH
Conflicts
0

CVE-2026-0620

When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled.  This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.

PUBLISHED
Vendor
TP-Link Systems Inc.
Product
AXE75
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0619

A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to trigger a denial of service. A hard reset is required to recover the device.

PUBLISHED
Vendor
silabs.com
Product
Silicon Labs Matter
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0618

Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.

PUBLISHED
Vendor
Devolutions
Product
PowerShell Universal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0617

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the customer's activity history.

PUBLISHED
Vendor
latepoint
Product
LatePoint – Calendar Booking Plugin for Appointments and Events
Provider severity
HIGH
Conflicts
0

CVE-2026-0616

TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into the internal TheLibrarian backend system. The vendor has fixed the vulnerability in all affected versions.

PUBLISHED
Vendor
TheLibrarian
Product
TheLibrarian.io
Provider severity
HIGH
Conflicts
0

CVE-2026-0615

The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running processes within TheLibrarian backend. The vendor has fixed the vulnerability in all affected versions.

PUBLISHED
Vendor
TheLibrarian
Product
TheLibrarian.io
Provider severity
HIGH
Conflicts
0

CVE-2026-0613

The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.

PUBLISHED
Vendor
TheLibrarian
Product
TheLibrarian.io
Provider severity
HIGH
Conflicts
0

CVE-2026-0612

The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.

PUBLISHED
Vendor
TheLibrarian
Product
TheLibrarian.io
Provider severity
HIGH
Conflicts
0

CVE-2026-0611

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentine

PUBLISHED
Vendor
Spacelabs Healthcare
Product
Sentinel
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0610

SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-0609

The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt text in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping in the 'logo-slider' shortcode. This makes it possible for authenticated attackers, with author level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
logichunt
Product
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-0608

The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head-meta-data' post meta field in all versions up to, and including, 20251118 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
specialk
Product
Head Meta Data
Provider severity
MEDIUM
Conflicts
0