Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint.

PUBLISHED
Vendor
Three Learning
Product
Koollab LMS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover.

PUBLISHED
Vendor
Three Learning
Product
Koollab LMS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-63228

An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.

PUBLISHED
Vendor
Three Learning
Product
Koollab LMS
Provider severity
LOW
Conflicts
0

CVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.

PUBLISHED
Vendor
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.
Product
Koollab LMS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-63226

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.

PUBLISHED
Vendor
Ricoh Company
Product
Ricoh printers and Multifunction Printers (MFPs)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63223

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched vers

PUBLISHED
Vendor
codeigniter4
Product
CodeIgniter4
Provider severity
CRITICAL
Conflicts
0

CVE-2026-63222

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.

PUBLISHED
Vendor
codeigniter4
Product
CodeIgniter4
Provider severity
HIGH
Conflicts
0

CVE-2026-63221

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4.

PUBLISHED
Vendor
codeigniter4
Product
CodeIgniter4
Provider severity
CRITICAL
Conflicts
0

CVE-2026-63220

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecureRequests, or similar logic to enforce HTTPS-only access or make security-sensitive decisions. Expl

PUBLISHED
Vendor
codeigniter4
Product
CodeIgniter4
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6322

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, fast-uri, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Serverless, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.0, Red Hat build of Apache Camel - HawtIO 4, Red Hat OpenShift AI (RHOAI), Red Hat Advanced Cluster Management for Kubernetes 2.16, Red Hat Build of Podman Desktop - Tech Preview, Confidential Compute Attestation, Red Hat Quay 3.9, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.12, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 9, OpenShift Serverless, Red Hat Ansible Automation Platform 2, Red Hat Developer Hub 1.9, OpenShift Pipelines, Self-service automation portal 2, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 10, Red Hat Edge Manager 1.0, Cryostat 4, Cryostat 4, Red Hat Openshift Data Foundation 4, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6.18, OpenShift Pipelines, Cluster Observability Operator 1.5.0, OpenShift Pipelines, Cluster Observability Operator 1.5.0, Network Observability Operator, OpenShift Lightspeed, Red Hat Edge Manager 1.1, Red Hat OpenShift Container Platform 4.21, Red Hat Openshift Data Foundation 4, OpenShift Serverless, OpenShift Lightspeed, Cluster Observability Operator 1.5.0, OpenShift Pipelines, Red Hat OpenShift Container Platform 4.2, Red Hat Discovery 2, Red Hat OpenShift Container Platform 4.22, Red Hat OpenShift AI (RHOAI), Red Hat Edge Manager 1.1, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2.5 for RHEL 8, OpenShift Serverless, Red Hat Build of Podman Desktop, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat AMQ Broker 7, Cluster Observability Operator 1.5.0, Red Hat OpenShift Dev Spaces, OpenShift Serverless, Red Hat Openshift Data Foundation 4, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, fast-uri, Red Hat Quay 3.1, Red Hat Developer Hub 1.10, Red Hat Migration Toolkit for Applications 8.2, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift Container Platform 4.2, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4, Cluster Observability Operator 1.5.0, Red Hat Edge Manager 1.1, Red Hat Ansible Automation Platform 2.7, Red Hat Migration Toolkit 1.8, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, multicluster engine for Kubernetes 2.11, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.22, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2.6 for RHEL 9, OpenShift Pipelines, OpenShift Serverless, Red Hat Edge Manager 1.1, Red Hat Satellite 6, OpenShift Serverless, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4.21, Red Hat Data Grid 8.6.2, Red Hat OpenShift Container Platform 4.19, Red Hat Satellite 6, Red Hat OpenShift Container Platform 4.21, OpenShift Serverless, Red Hat Quay 3.16, Red Hat OpenShift Container Platform 4.22, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
3

CVE-2026-6321

A flaw was found in fast-uri. A remote attacker could exploit this vulnerability by providing a specially crafted Uniform Resource Locator (URL) containing percent-encoded path separators and dot segments. Due to incorrect processing, fast-uri would decode these elements before proper normalization, leading to distinct URLs resolving to the same internal path. This could allow an attacker to bypass security policies that rely on path-based comparisons, potentially gaining unauthorized access to

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, fast-uri, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat Build of Podman Desktop - Tech Preview, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Cluster Observability Operator 1.5.0, Red Hat Satellite 6, Network Observability (NETOBSERV) 1.12.0, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.19, Cluster Observability Operator 1.5.0, Red Hat Satellite 6, Confidential Compute Attestation, Red Hat Openshift Data Foundation 4.18, Red Hat Ansible Automation Platform 2.6, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.18, Red Hat Build of Podman Desktop, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.16, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.16, HawtIO HawtIO 4.4.0, streams for Apache Kafka 2, Red Hat Openshift Data Foundation 4.18, Red Hat Data Grid 8, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Dev Spaces 3.28, Red Hat Ansible Automation Platform 2.6, Red Hat Developer Hub 1.8, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.19, Red Hat Developer Hub 1.9, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.16, Red Hat Enterprise Linux 10, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.16, Red Hat Ansible Automation Platform 2, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.16, Red Hat Ansible Automation Platform 2.5, Red Hat Developer Hub, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.18, Red Hat Openshift Data Foundation 4.19, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.19, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.18, fast-uri, Red Hat Build of Podman Desktop, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.16, Cryostat 4, Cluster Observability Operator 1.5.0, Red Hat Enterprise Linux 9, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Cluster Observability Operator 1.5.0, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.16, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Discovery 2, Red Hat Satellite 6, Red Hat Openshift Data Foundation 4.18, Red Hat OpenShift AI (RHOAI), Cluster Observability Operator 1.5.0, Cluster Observability Operator 1.5.0, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.19, Red Hat OpenShift Container Platform 4, streams for Apache Kafka 3, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat Openshift Data Foundation 4.16, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.19, Red Hat Openshift Data Foundation 4.18, Red Hat Openshift Data Foundation 4.16, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat Openshift Data Foundation 4.19, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
3

CVE-2026-6320

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it possible for unauthenticated attackers to read arbitrary local files and exfiltrate them via booking confirmation email attachments.

PUBLISHED
Vendor
wordpresschef
Product
Salon Booking System – Free Version
Provider severity
HIGH
Conflicts
0

CVE-2026-6319

Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-6318

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-63175

PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies, browser storage, HTTP credentials, proxy configuration, user-agent settings, geolocation information, and captured request data. In a multi-user or concurrent deployment, information supplied during one capture could therefor

PUBLISHED
Vendor
Lookyloo
Product
PlaywrightCapture
Provider severity
HIGH
Conflicts
0

CVE-2026-6317

Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-6316

Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-6315

Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-63145

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs an insufficient authorization check. The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-63144

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deployments, this results in complete service outage; in multi-node clusters, it causes repeated node re

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-63143

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-63142

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-63141

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-63140

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6314

Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-63139

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana server process to terminate and resulting in a denial of service for all users of the affected Kibana instance.

PUBLISHED
Vendor
Elastic
Product
Kibana
Provider severity
MEDIUM
Conflicts
0

CVE-2026-63136

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.

PUBLISHED
Vendor
Elastic
Product
Elasticsearch
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6313

Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
LOW
Conflicts
1

CVE-2026-6312

Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
LOW
Conflicts
1

CVE-2026-63119

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets without a byte limit, allowing a peer that sends data without a newline to exhaust process memory. This issue is fixed in version 0.23.0.

PUBLISHED
Vendor
modelcontextprotocol
Product
ruby-sdk
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63118

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host or Origin request headers, which allows a malicious browser page to use DNS rebinding to reach a locally running MCP server and invoke exposed tools. This issue is fixed in version 0.23.0.

PUBLISHED
Vendor
modelcontextprotocol
Product
ruby-sdk
Provider severity
MEDIUM
Conflicts
1

CVE-2026-6311

Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-63108

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts replaces parameter expansions with opaque placeholders before extracting command substitutions, causing the containsDangerousSubstitution guard to miss nested payloads, which are then auto-approved based on the outer allowlis

PUBLISHED
Vendor
RooCodeInc
Product
Roo-Code
Provider severity
HIGH
Conflicts
1

CVE-2026-63107

LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host header in the getTemplateData() function to reach internal network services, cloud metadata endpoints, and extract sensitive credentials such as IAM tokens from instance metadata servic

PUBLISHED
Vendor
LimeSurvey
Product
LimeSurvey
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-63102

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not a

PUBLISHED
Vendor
rConfig
Product
rConfig v8 Core
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63101

Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any authentication decorator. Attackers can enumerate sequential group IDs via brute-force, trigger an export via the unauthenticated POST endpoint, then poll the unauthenticated task status endp

PUBLISHED
Vendor
fossasia
Product
open-event-server
Provider severity
HIGH
Conflicts
1

CVE-2026-63100

Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsController, where the before_action ensure_admin filter is applied only to the clear_cache action. Attackers can read the operator's Synth API key rendered in plaintext via a form field value attribute, overwrite it with an attacker-controlled value, togg

PUBLISHED
Vendor
maybe-finance
Product
maybe
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-6310

Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-63099

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the missing organization-scoped authorization check in AttachmentSrv.visible, which is implemented as a pass-through traversal, to download arbitrary attachments.

PUBLISHED
Vendor
TheHive-Project
Product
TheHive
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-63098

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.

PUBLISHED
Vendor
TheHive-Project
Product
TheHive
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63097

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check that evaluates only the RoomExists field while ignoring IsInRoom, HasBeenInRoom, and Membership fields. Attackers who have left a room can call the rooms context API endpoint for a previously permitted event and receive unfiltered current room sta

PUBLISHED
Vendor
matrix-org
Product
dendrite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63096

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit distinguishable error response classes and leaked internal IP addresses in error messages to perform blind port scanning and enumerate internal network topology.

PUBLISHED
Vendor
matrix-org
Product
dendrite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63095

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack th

PUBLISHED
Vendor
matrix-org
Product
dendrite
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-63094

SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.

PUBLISHED
Vendor
SigNoz
Product
signoz
Provider severity
HIGH
Conflicts
2

CVE-2026-63093

Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor automatically resolves and executes the workspace-resident git.exe during IDE startup and on a recurring timed cadence without any user interaction, running the malicious binary under the privileges of the current user.

PUBLISHED
Vendor
Anysphere, Inc.
Product
Cursor
Provider severity
HIGH
Conflicts
1

CVE-2026-63092

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in lib/areas.php returns the complete key via ModulesLicense::readKey() without performing an administrator check, as the dialog is gated only by the access.system permission which defaults to

PUBLISHED
Vendor
medienbaecker
Product
kirby-modules
Provider severity
MEDIUM
Conflicts
1

CVE-2026-63091

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process

PUBLISHED
Vendor
proftpd
Product
proftpd
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-63090

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem str

PUBLISHED
Vendor
proftpd
Product
proftpd
Provider severity
HIGH
Conflicts
1

CVE-2026-6309

Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

PUBLISHED
Vendor
Google
Product
Chrome
Provider severity
HIGH
Conflicts
1

CVE-2026-63089

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID, as the token is computed using CRC32 over a random value constrained to 0-999. Attackers can enumerate candidate tokens against the unauthenticated /cnf/:oneTimeLink route, which lacks rate limiting and do

PUBLISHED
Vendor
wg-easy
Product
wg-easy
Provider severity
CRITICAL
Conflicts
2