By severity

High-severity vulnerabilities

CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 16 of 42

  • CVE-2026-3144HIGH 8.1

    IBM API Connect versions 12.1.0.0 through 12.1.0.3 ship with hardcoded default credentials that remain active until administrators manually enforce a password change. An attacker with network access can use these credentials to gain full unauthorized access to the API management platform before credential enforcement takes effect, potentially compromising API infrastructure, traffic, and data.

  • CVE-2026-31928HIGH 8.1

    Daktronics DMP-5000, DMP-8000, and VFC-DMP-5000 devices ship with preset administrative accounts that use weak or default credentials. These accounts grant complete system control and cannot be disabled during initial setup or normal operation. An authenticated attacker with network access can exploit these weak credentials to take full control of affected displays and related infrastructure.

  • CVE-2026-31985HIGH 8.1

    A configuration flaw in the Remote Collector setup tool (n2os-tui) causes it to disable TLS certificate verification when connecting to upstream Guardian or CMC systems, with no way to re-enable it. This leaves the connection vulnerable to man-in-the-middle (MITM) attacks where an attacker on the network path could intercept, eavesdrop on, or manipulate the entire data stream between systems.

  • CVE-2026-32804HIGH 8.1

    Dell PowerFlex Manager versions before 5.1.0.1 contain an authentication flaw that allows an attacker on the same network segment to gain unauthorized access without credentials. The vulnerability does not require any user interaction and can be exploited by someone already positioned on an adjacent network—making it particularly risky in environments where trust in lateral network access may be assumed. An attacker exploiting this could modify storage configurations, disable services, or access sensitive data.

  • CVE-2026-33390HIGH 8.1

    A privilege escalation vulnerability exists in Nozomi Networks devices where the synchronization feature incorrectly grants administrative command-line interface (CLI) permissions to Arc sensors. An authenticated user with limited privileges can exploit this to push administrative commands through the sync mechanism, potentially reconfiguring devices or disrupting their operation. The vulnerability requires an attacker to be already authenticated to the system, but does not require any user interaction to trigger.

  • CVE-2026-35019HIGH 8.1

    NetComm NF20MESH routers contain a critical flaw that allows attackers to bypass login requirements and gain full administrative control of the device without knowing the real password. The vulnerability exists because the router uses the same hardcoded encryption key across all devices to protect administrative session cookies. An attacker can use this shared key to create a fake but valid login session and gain admin access to the web management interface, even while a legitimate administrator is logged in.

  • CVE-2026-35025HIGH 8.1

    ProFTPD versions through 1.3.9b and 1.3.10rc2 contain a flaw that allows authenticated FTP users to bypass directory access controls. By manipulating file paths in rename commands using a /proc/self/root prefix, attackers can circumvent restrictions meant to prevent access to sensitive directories. The vulnerability enables them to rename files in restricted areas and then download those files, effectively gaining unauthorized access to protected content. Systems using ProFTPD's chroot feature (DefaultRoot) are protected from this issue.

  • CVE-2026-35076HIGH 8.1

    A vulnerability in MBS Solutions gateway and protocol-conversion products allows authenticated users to delete files from the affected system without proper authorization. The flaw exists in the 'bac-scanresult' method, which fails to validate user-supplied input adequately. An attacker who has legitimate credentials can exploit this to remove critical files, potentially disrupting system operations or causing data loss.

  • CVE-2026-35077HIGH 8.1

    A vulnerability in MBS Solutions gateway products allows authenticated users to delete files they shouldn't have access to. An attacker with valid user credentials can exploit the ugw-delete-file method to remove arbitrary files from affected systems by bypassing input validation controls. This is especially concerning in industrial automation environments where these gateways often handle critical protocol conversions and data flows.

  • CVE-2026-35078HIGH 8.1

    A vulnerability in MBS Solutions gateway products allows authenticated users to delete files from affected systems without proper authorization. An attacker with valid user credentials can exploit the ugw-logstop method to remove arbitrary files, potentially disrupting system operations or destroying evidence. This is classified as a high-severity flaw because it requires only standard user access and can cause significant damage to system integrity and availability.

  • CVE-2026-35079HIGH 8.1

    CVE-2026-35079 is a file deletion vulnerability in MBS Solutions' Universal Gateway firmware and related gateway products. An attacker who already has valid user credentials can exploit the ugw-restore method to delete arbitrary files on the device. Because the vulnerability requires existing user access, the risk depends heavily on your organization's internal security posture and whether these devices are exposed to untrusted users.

  • CVE-2026-35080HIGH 8.1

    A flaw in MBS Solutions gateway firmware allows authenticated users to delete files they shouldn't have access to. An attacker with valid login credentials can exploit the ugw-restoreinfo method to remove arbitrary files from affected devices, potentially disrupting operations or destroying critical system data. The vulnerability requires existing user privileges but poses a serious risk to the integrity and availability of gateway-based infrastructure.

  • CVE-2026-35081HIGH 8.1

    A vulnerability in MBS Solutions' gateway and protocol conversion products allows authenticated users to remotely stop arbitrary processes on affected devices. An attacker who already has valid user credentials can exploit insufficient input validation in the ugw-logstop method to terminate critical services, potentially disrupting device functionality or causing a denial of service. This is a HIGH severity issue requiring prompt attention in networked industrial and building automation environments.

  • CVE-2026-35276HIGH 8.1

    Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 contain a high-severity vulnerability in the Application Server component that allows an unauthenticated attacker on the network to fully compromise the system. An attacker with HTTP access can exploit this to gain complete control, potentially affecting confidentiality, integrity, and availability of PeopleSoft data and services. The vulnerability is difficult to exploit, meaning it requires specific conditions or knowledge, but the impact of successful exploitation is severe.

  • CVE-2026-35277HIGH 8.1

    Oracle REST Data Services contains a flaw that allows authenticated users with basic network access to read and modify sensitive data they shouldn't be able to access. An attacker with a low-privilege account can exploit this remotely without user interaction, potentially accessing, changing, or deleting critical information across the service. This is a significant risk because it bypasses normal data access controls.

  • CVE-2026-35279HIGH 8.1

    CVE-2026-35279 is a network-accessible vulnerability in Oracle PeopleSoft Enterprise PT PeopleTools (versions 8.61 and 8.62) that allows an unauthenticated attacker to gain complete control of the affected system over HTTP. The vulnerability exists in the Performance Monitor component and can result in full compromise of confidentiality, integrity, and availability. While rated as difficult to exploit due to the specific attack complexity required, successful exploitation grants an attacker the ability to take over the entire PeopleTools environment.

  • CVE-2026-35289HIGH 8.1

    Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 contain a vulnerability in its Deployment Package component that allows an unauthenticated attacker to remotely compromise the system over HTTPS. Despite being difficult to exploit, successful attacks could result in complete system takeover, affecting confidentiality, integrity, and availability. The vulnerability stems from missing or insufficient authentication mechanisms (CWE-306), permitting network-based attacks without user interaction.

  • CVE-2026-35552HIGH 8.1

    CAXperts has released security advisories for two products affected by an authorization bypass vulnerability. If you're using UPVWebServices versions 2.4.2212.603 through 2.7.6 or UDiTH Portal versions 2026.0.0 through 2026.2.0, an authenticated user—even one without administrative privileges—can call a restricted API endpoint to deactivate your application's license. This doesn't require special tricks or user interaction; an attacker who has any valid login credential can exploit it immediately. The practical impact is service disruption: a disabled license typically renders the application inoperable.

  • CVE-2026-36603HIGH 8.1

    The Mercusys AC12G (EU) V1 router running firmware version AC12G(EU)_V1_200909 contains a critical authentication bypass vulnerability in its UPnP (Universal Plug and Play) implementation. Any device connected to the router's local network can manipulate port forwarding rules and retrieve WAN connection details without providing credentials. Since UPnP is enabled by default, attackers with LAN access gain the ability to redirect internet traffic, expose internal services, or exfiltrate data—creating a serious risk for home and small-office networks.

  • CVE-2026-36720HIGH 8.1

    Bookcars version 8.3 contains a privilege escalation vulnerability that allows logged-in users to upgrade their account to administrator status by manipulating their user type settings. An attacker who has obtained valid credentials—whether through compromise, social engineering, or as a legitimate user—can exploit weak permission controls to gain full administrative access to the system without requiring additional authentication or authorization checks.

  • CVE-2026-3688HIGH 8.1

    A WordPress plugin called WCFM Membership that manages vendor roles in multivendor WooCommerce marketplaces contains a permission flaw. An authenticated user with vendor-level access can exploit a missing permission check in the membership management system to elevate any other user—including administrators—to vendor status, effectively hijacking their account capabilities.

  • CVE-2026-38057HIGH 8.1

    The iDirect iQ200 satellite communication device is vulnerable to cross-site request forgery (CSRF) attacks on its administrative control interface. An attacker can trick an authenticated administrator into visiting a malicious webpage that silently triggers a device reboot by exploiting the lack of CSRF token validation and improper session cookie configuration. This can lead to immediate loss of satellite connectivity and, if repeated, sustained service disruption.

  • CVE-2026-39253HIGH 8.1

    Pivotal CRM version 6.6.04.08 contains a critical vulnerability that allows attackers on the network to run malicious code on affected systems without needing valid credentials. The flaw exists in two core components responsible for data handling and service conversion, making it a direct path to system compromise. An attacker would need specific technical conditions to exploit this, but once successful, they gain complete control over the affected system.

  • CVE-2026-39539HIGH 8.1

    Unauthenticated attackers can inject malicious PHP objects into Alloggio Hotel Booking plugin versions 2.1.2 and earlier, potentially gaining control of affected WordPress sites without requiring login credentials. This is a deserialization vulnerability—a common but severe weakness where untrusted data is converted back into executable code. Because no authentication is required and the attack can be carried out remotely, this poses an immediate risk to any exposed installation.

  • CVE-2026-39550HIGH 8.1

    Aperitif, a WordPress theme by Elated-Themes, contains a deserialization flaw that allows attackers to inject malicious objects into the application. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary code or compromise the integrity and confidentiality of affected websites. The vulnerability exists in versions 1.6 and earlier.

  • CVE-2026-39551HIGH 8.1

    A critical flaw in Elated-Themes' Töbel plugin allows attackers to inject malicious objects through unsafe deserialization. An unauthenticated remote attacker can exploit this vulnerability to achieve arbitrary code execution, data theft, or system compromise. The attack requires some specific conditions to be met, but once exploited, grants full control over affected systems.

  • CVE-2026-39552HIGH 8.1

    Code Supply Co. Blueprint contains a vulnerability that allows attackers to include and execute arbitrary local files through PHP, provided they can craft specific requests to the affected application. While the vulnerability is classified as "remote" in nature due to network accessibility, exploitation requires specific conditions including high complexity in attack construction. Versions before 1.1.5 are affected. Organizations running Blueprint should prioritize upgrading to the patched version.

  • CVE-2026-39553HIGH 8.1

    A PHP Local File Inclusion (LFI) vulnerability exists in Select-Themes WaveRide versions up to and including 1.4. The flaw allows an attacker to manipulate filename parameters used in PHP include or require statements, potentially enabling unauthorized file access and code execution on affected systems. The vulnerability is triggered through network requests and does not require authentication or user interaction.

  • CVE-2026-39555HIGH 8.1

    A critical flaw has been discovered in Elated-Themes' Askka plugin (versions up to and including 1.3.1) that allows attackers to inject malicious objects through deserialization of untrusted data. When the plugin processes serialized data from an untrusted source without proper validation, an attacker can craft a specially designed payload that, when deserialized by the vulnerable code, instantiates arbitrary PHP objects. This object injection can lead to remote code execution, data theft, or system compromise depending on available gadget chains within the application environment.

  • CVE-2026-40138HIGH 8.1

    BeyondTrust Remote Support and Privileged Remote Access contain a critical flaw in how they validate authentication credentials before a user logs in. An attacker on the network can exploit this weakness to bypass normal login protections and gain unauthorized access to the appliance, potentially including high-privilege accounts. The vulnerability only affects systems where a specific authentication configuration is enabled, which limits but does not eliminate the risk footprint.

  • CVE-2026-40523HIGH 8.1

    FrontAccounting versions before 2.4.20 contain a SQL injection vulnerability in the Audit Trail report feature. An attacker with basic reporting permissions (SA_GLANALYTIC) can inject malicious SQL commands into report parameters, potentially reading sensitive database records or causing the database to become unresponsive by consuming all available connections. This is a post-authentication risk—the attacker must already have a valid user account—but the permission required is not administrator-level, making it a concern in environments where junior staff or contractors have analytics access.

  • CVE-2026-40524HIGH 8.1

    FrontAccounting versions before 2.4.20 contain a SQL injection flaw in a financial reporting function that allows authenticated users with analytics permissions to extract sensitive journal entry data. An attacker with the right role can manipulate a filter parameter to inject SQL commands that bypass the intended query logic, potentially exposing confidential transaction records. The vulnerability requires existing account access but no user interaction, making it a reliable attack vector for insider threats or compromised credentials.

  • CVE-2026-40859HIGH 8.1

    Apache Camel's vertx-http component contains a critical deserialization flaw that can lead to remote code execution. When the component is configured to transfer exceptions from backend HTTP responses (an opt-in setting), it deserializes Java objects from responses without any safety checks. An attacker controlling or intercepting the backend service can send a malicious serialized object that, if suitable gadget classes exist in the application's dependencies, executes arbitrary code on the Camel host. This vulnerability requires non-default configuration to trigger and relies on either compromising the backend service or intercepting unencrypted HTTP traffic.

  • CVE-2026-41013HIGH 8.1

    A flaw in how Cloud Foundry's Diego release handles SMB volume mounts allows a developer with basic access to a shared environment to bypass security restrictions and inject malicious mount commands. This could let them gain elevated privileges or circumvent security controls on multi-tenant systems where multiple teams share the same infrastructure.

  • CVE-2026-41045HIGH 8.1

    A timing vulnerability in qSnapper's authentication system allows local users to bypass security protections that normally require administrative privileges. An attacker with access to the system could exploit this flaw to gain root-level control by manipulating the timing of authentication checks, circumventing the intended permission model.

  • CVE-2026-41699HIGH 8.1

    Spring for GraphQL applications that use pagination features are vulnerable to a deserialization attack that can allow remote code execution. An attacker sends a specially crafted GraphQL query to a paginated endpoint; if the application's runtime environment contains certain gadget classes, the attack can execute arbitrary code on the server. The vulnerability affects Spring for GraphQL versions 1.3.0–1.3.8, 1.4.0–1.4.5, and 2.0.0–2.0.3.

  • CVE-2026-41700HIGH 8.1

    Spring for GraphQL applications using WebSocket transport have a Cross-Site WebSocket Hijacking vulnerability. An attacker can craft a malicious webpage that, when visited by an authenticated user, hijacks that user's WebSocket connection and executes arbitrary GraphQL queries or mutations on their behalf. The victim's session credentials are automatically sent with WebSocket requests, making them a natural target for this type of attack. This is particularly dangerous because it requires minimal user interaction—just visiting a page—and gives attackers full access to perform any GraphQL operation the victim is authorized to perform.

  • CVE-2026-41717HIGH 8.1

    Spring Data MongoDB has a vulnerability where specially crafted database queries can execute arbitrary code on your application server. This happens when developers use the @Query annotation with certain placeholder patterns in their custom repository methods. An attacker who can influence the query parameters—either through application input or by compromising a data source—can inject malicious expressions that the framework will execute with your application's privileges.

  • CVE-2026-41729HIGH 8.1

    Spring Data REST, a popular framework for building REST APIs on top of Spring Data repositories, contains a vulnerability in how it processes JSON Patch requests when entities include Map-type properties. An authenticated attacker can inject malicious SpEL (Spring Expression Language) expressions by crafting a specially formatted JSON Patch request. The framework fails to sanitize the map key derived from the JSON Pointer path, allowing the attacker to execute arbitrary code on the server. This requires valid credentials but no additional user interaction to exploit.

  • CVE-2026-41731HIGH 8.1

    Spring for Apache Kafka contains a flaw in how it validates trusted message header types. When a developer trusts a package for deserialization, the framework actually trusts that entire package and all of its subpackages. An attacker who can produce Kafka messages can exploit this overly broad trust to craft malicious header values that force the consumer to deserialize and instantiate arbitrary JDK classes. Combined with Jackson's default deserialization behavior, this can lead to remote code execution on systems processing the poisoned messages.

  • CVE-2026-41732HIGH 8.1

    A flaw in Spring for Apache Pulsar's type-header validation allows an attacker to deserialize untrusted Java objects when the library is configured with a trusted-packages allowlist. The vulnerability has two related problems: first, trusting a package name implicitly trusts all of its subpackages due to a prefix-matching check, and second, an empty trusted-packages configuration defaults to trusting all packages instead of safely rejecting unknown types. An attacker on the network can exploit this by sending specially crafted messages to deserialize malicious objects, potentially leading to remote code execution.

  • CVE-2026-41855HIGH 8.1

    Spring Framework's JMS message converters contain a deserialization flaw that allows attackers to instantiate arbitrary classes when processing untrusted messages from a JMS broker. An attacker with access to a JMS broker—or one who can inject malicious messages into it—can exploit gadget classes present on the application's classpath to execute unauthorized actions, including potential remote code execution. The vulnerability affects multiple recent versions of Spring Framework across several release branches.

  • CVE-2026-42055HIGH 8.1

    NGINX Plus and NGINX Open Source contain a heap buffer overflow vulnerability in their HTTP/2 and gRPC proxy modules. When specific configuration conditions are met—proxy_http_version set to 2 or grpc_pass enabled, ignore_invalid_headers turned off, and large_client_header_buffers exceeding 2MB—an attacker can craft oversized headers to trigger a buffer overflow. This can crash the NGINX worker process or, under certain circumstances (particularly when ASLR is disabled), lead to remote code execution. The vulnerability requires specific configuration and network conditions but poses significant risk to affected deployments.

  • CVE-2026-42211HIGH 8.1

    React Router versions 7.0.0 through 7.14.1 contain a high-severity vulnerability that could enable remote code execution when using Framework Mode. The attack is two-stage: it requires an application to already contain a prototype pollution flaw, which an attacker can then exploit to trigger unauthorized code execution on the server. Applications using the library's Declarative Mode or Data Mode routing are unaffected. The vulnerability was patched in version 7.14.2.

  • CVE-2026-42488HIGH 8.1

    CVE-2026-42488 is a memory safety issue in hypervisor shadow paging logic where certain error handling paths fail to synchronize the active vCPU's page-table references with internal metadata structures. This desynchronization corrupts the mapcache—a critical component that tracks memory mappings—potentially allowing an attacker to read, modify, or crash the virtualized system. The flaw requires specific conditions to trigger (high complexity attack surface) but carries severe consequences if exploited.

  • CVE-2026-42527HIGH 8.1

    Apache Camel contains a deserialization vulnerability that allows attackers to trigger DNS queries during message processing. When serialized Java objects are sent to affected Camel components—particularly JMS consumers—the framework's default security filter allows certain classes like java.net.URL through. An attacker can craft a HashMap with malicious URL keys that, when deserialized, causes the JVM to issue DNS queries to attacker-controlled servers. This creates an out-of-band information disclosure channel without requiring code execution. The risk is highest in JMS deployments where message deserialization happens by default.

  • CVE-2026-42530HIGH 8.1

    NGINX Open Source contains a vulnerability in its HTTP/3 (QUIC) module that allows remote attackers to trigger a crash in worker processes by sending specially crafted HTTP/3 session packets. Under specific conditions—particularly on systems without ASLR protection or where ASLR has been bypassed—attackers may achieve code execution. The flaw stems from improper memory management when handling QPACK encoder streams, creating a use-after-free condition that can be exploited without authentication.

  • CVE-2026-42588HIGH 8.1

    Apache ActiveMQ's web console exposes a remote interface (Jolokia) that allows authenticated users to interact with the message broker's management functions. An attacker who has legitimate access credentials can craft a specially formed network connector request that tricks the broker into loading and executing arbitrary code hidden in a Spring XML configuration file. The vulnerability exists because the broker doesn't properly validate the input before processing it, and Spring automatically instantiates code within those XML files before any security checks occur.

  • CVE-2026-42835HIGH 8.1

    Microsoft Teams for Android contains an injection vulnerability that allows an authenticated attacker to extract sensitive information from the application. The flaw stems from improper handling of special characters in data passed to downstream components, creating a pathway for unauthorized data disclosure. An attacker must already have valid credentials to exploit this vulnerability, but once authenticated, they can access information without triggering user interaction or modifying data.

  • CVE-2026-42863HIGH 8.1

    FlowiseAI versions prior to 3.1.2 contain a mass assignment vulnerability in their chatflow update feature. An authenticated user can modify internal system properties—such as workspace assignment, deployment status, and visibility settings—that should only be controlled by administrators. This allows attackers to reassign workflows to other workspaces, change deployment states without authorization, and alter public/private visibility of chatflows. The vulnerability requires valid login credentials but no additional special access.

  • CVE-2026-42974HIGH 8.1

    A flaw in Windows Performance Monitor allows an attacker to crash or take control of a system by sending specially crafted network requests. The vulnerability stems from how the Performance Monitor handles very large numbers, causing it to malfunction and execute unauthorized code. An attacker does not need valid credentials or user interaction to exploit this; they only need network access to the affected system.

  • CVE-2026-42981HIGH 8.1

    Windows Performance Monitor contains an integer underflow vulnerability that allows attackers to execute arbitrary code on affected systems over a network without authentication. The flaw affects multiple versions of Windows 11 and Windows Server 2022/2025. While exploitation requires specific conditions (reflected in the CVSS complexity rating), successful attacks could grant an attacker full control of the compromised system.

  • CVE-2026-42987HIGH 8.1

    CVE-2026-42987 is a use-after-free memory vulnerability in Windows Deployment Services (WDS) that allows an attacker to execute arbitrary code on vulnerable servers over the network without authentication or user interaction. The vulnerability affects multiple Windows Server versions and has a CVSS score of 8.1 (HIGH severity), indicating a significant risk to organizations relying on WDS for operating system deployment.

  • CVE-2026-43735HIGH 8.1

    A vulnerability in Apple's Safari browser and related operating systems allows attackers to steal sensitive data from users by tricking them into visiting a malicious website. The flaw bypasses security boundaries that normally prevent websites from accessing data belonging to other websites, creating a cross-origin data leakage risk. Users must visit the malicious site for the attack to work, but no other user interaction beyond clicking a link is required.

  • CVE-2026-43865HIGH 8.1

    Apache Camel's Hazelcast integration component has a critical flaw in how it handles data coming from cluster nodes. When Camel automatically creates and manages Hazelcast instances without custom configuration, it doesn't protect against malicious serialized Java objects. An attacker positioned on or able to reach the Hazelcast cluster can send a specially crafted object that gets automatically deserialized on every Camel node, executing arbitrary code. This happens silently in the background for any route using Hazelcast consumers or certain Camel repositories—no special endpoint setup is required for the vulnerability to exist.

  • CVE-2026-43994HIGH 8.1

    Coturn, a widely-used open source TURN/STUN server for WebRTC applications, contains a critical stack buffer overflow vulnerability in its OAuth token handling code. When Coturn is configured with the --oauth mode (commonly recommended for security), it fails to validate the length of a nonce field embedded in OAuth tokens before copying data into a fixed 256-byte buffer. An attacker can send a specially crafted token that triggers an overflow, potentially writing over 700 bytes of malicious data onto the stack. Notably, the attacker does not need valid OAuth credentials—the overflow happens before any cryptographic verification occurs. This could allow attackers to crash the server or potentially execute arbitrary code, depending on system protections. The vulnerability affects all versions prior to 4.10.0.

  • CVE-2026-44237HIGH 8.1

    FreePBX versions before 17.0.8 contain a flaw in their OAuth2 implementation that allows an attacker to bypass credential verification. If an attacker discovers or guesses a valid client application ID, they can request OAuth2 access tokens without needing the corresponding secret passphrase. This grants them the ability to authenticate and interact with the FreePBX API as if they were a legitimate application, potentially enabling unauthorized access to voice, data, and configuration controls.

  • CVE-2026-44249HIGH 8.1

    Netty is a widely-used Java networking framework that powers many protocol servers and clients. A flaw in how it filters IPv6 traffic has been discovered: the masking logic in the IPv6 subnet filtering rules is broken, allowing attackers to craft IP addresses that appear to bypass intended network access controls. If your application relies on Netty to restrict traffic to specific IPv6 subnets, an attacker could send requests from addresses that should have been blocked, potentially gaining unauthorized access to protected services.

  • CVE-2026-44271HIGH 8.1

    Dell Wyse Management Suite (WMS) versions before 2605 contain a SQL injection flaw that allows a logged-in attacker to query or modify the underlying database without proper authorization. An attacker with low-level access to the management interface can craft malicious input to bypass SQL protections, potentially reading sensitive configuration data or disrupting system availability. The vulnerability requires network access and valid credentials but does not require user interaction to trigger.

  • CVE-2026-44454HIGH 8.1

    Coder is a platform that lets organizations set up remote development environments through Terraform automation. A vulnerability in versions before 2.29.7 and 2.30.2 allowed attackers to run arbitrary code inside provisioned workspaces by injecting shell commands into the dotfiles configuration. An attacker could craft a special URL that automatically provisions a workspace with malicious code, requiring only a user click—no explicit confirmation needed. Coder fixed this by validating user input and removing unsafe shell execution patterns.

  • CVE-2026-44654HIGH 8.1

    LibreChat is an open-source ChatGPT alternative that integrates multiple AI providers. A critical flaw in versions up to 0.8.3 allows a user with editing privileges on a shared agent to permanently delete files — not just from that shared agent, but globally across the entire system. This means if a file owner has reused the same file across multiple private agents, an attacker with edit access to just one shared agent can destroy those files, leaving the owner's other agents broken with orphaned file references. The owner doesn't control the attacker's edit access to their own private agents; they simply stop working.

  • CVE-2026-44825HIGH 8.1

    Apache Solr's authentication setup tool comes with hardcoded default credentials that are silently installed in addition to any user-specified accounts. A remote attacker who knows these public defaults can bypass the security layer entirely and gain full administrative control of the Solr cluster. This affects versions 9.4.0 through 9.10.1 and 10.0.0, but only if the basic authentication setup tool was used during cluster initialization.

  • CVE-2026-44882HIGH 8.1

    Portainer Community Edition versions 2.33.0 through 2.33.7 contain an authorization bypass vulnerability in how it proxies requests to Kubernetes clusters. When a user's token validation fails during a security check, the application incorrectly continues processing the request instead of stopping it. This allows an authenticated Portainer user without permission to access a specific Kubernetes cluster to send requests directly to that cluster anyway, circumventing the intended access controls. An attacker must already have a valid Portainer session to exploit this.

  • CVE-2026-44973HIGH 8.1

    Billy is a Go library that provides an abstraction layer for filesystem operations. Versions before 5.9.0 contain path traversal vulnerabilities that allow attackers with authenticated access to bypass directory restrictions using specially crafted paths (such as those containing ".." sequences). An attacker could potentially read or modify files outside the intended directory boundaries. Applications that depend on Billy for filesystem isolation are at risk of exposing sensitive files on the system.

  • CVE-2026-45013HIGH 8.1

    ApostropheCMS, a popular Node.js-based content management system, contains a critical flaw in its password reset functionality. When the application isn't configured with an explicit base URL, it automatically derives the reset link domain from the incoming HTTP Host header—which attackers can manipulate. This means an attacker with knowledge of a victim's email address can trigger a password reset that sends the victim a link pointing to the attacker's server. If the victim clicks it, the valid reset token leaks directly to the attacker, granting them full control of the account. The vulnerability affects all versions up to and including 4.29.0, and no patch has been released as of this publication.

  • CVE-2026-45062HIGH 8.1

    FrankenPHP, a PHP application server, contains a critical flaw in how it processes file extensions when request paths include non-ASCII characters. Versions 1.11.2 through 1.12.2 are vulnerable to an attack where an attacker can trick FrankenPHP into executing a non-PHP file as if it were PHP code. If your deployment allows file uploads or stores user-controlled content, an attacker could upload a malicious file and then craft a specially-formed URL to trigger code execution on your server. The vulnerability has been fixed in version 1.12.3.

  • CVE-2026-45135HIGH 8.1

    Caddy, a popular TLS-enabled web server platform, contains a flaw in its FastCGI request routing logic that could allow an attacker to execute arbitrary code on affected servers. The vulnerability exists when Caddy processes HTTP requests with non-ASCII characters in the path. An attacker who can upload files or control content served through FastCGI can exploit this misconfiguration to trick Caddy into treating non-script files (like images or documents) as executable scripts, leading to remote code execution. The issue affects versions 2.7.0 through 2.11.2 and is resolved in version 2.11.3.

  • CVE-2026-45156HIGH 8.1

    Nextcloud's User OIDC (OpenID Connect) authentication system fails to verify signatures from ID4me identity authorities. An attacker controlling a malicious ID4me authority can forge authentication tokens to impersonate any user on an affected Nextcloud instance. This is a high-severity authentication bypass that requires user interaction—typically a user clicking a login link or being redirected to a compromised identity provider. The vulnerability spans multiple version branches and has been patched across supported releases.

  • CVE-2026-45178HIGH 8.1

    Idira Secrets Manager Self-Hosted versions 13.8.0 and earlier contain a flaw that allows authenticated users with basic node-level credentials to access internal cluster communication channels they shouldn't be able to reach. An attacker with valid login credentials could exploit these unsecured endpoints to steal secrets stored in the system or disrupt its availability. The vulnerability requires prior authentication, so it represents an insider or compromised-credential risk rather than an unauthenticated attack vector.

  • CVE-2026-45233HIGH 8.1

    HTMLy CMS versions up to and including 3.1.1 contain a file manipulation vulnerability affecting authenticated users. An attacker with login credentials can exploit an admin autosave endpoint to move files to unintended locations on the server by crafting requests with path traversal sequences. Since the endpoint fails to properly validate or restrict file paths, an authenticated attacker could relocate sensitive application or configuration files to web-accessible directories or other locations that could lead to information disclosure or system compromise.

  • CVE-2026-45281HIGH 8.1

    Nextcloud Server contains an authorization flaw in its calendar functionality that allows authenticated attackers to access other users' calendars if they know the target's principal URL. An attacker with valid Nextcloud credentials can exploit improper access controls to view and modify calendars belonging to other users, effectively bypassing permission boundaries. The vulnerability requires prior knowledge of another user's identifier and valid authentication to the Nextcloud instance.

  • CVE-2026-45344HIGH 8.1

    LinkAce, a self-hosted web link archival tool, contains a critical vulnerability in its initial setup wizard that allows remote attackers to inject malicious database credentials. When an attacker provides specially crafted input during the database configuration step on a fresh LinkAce instance, the application writes unsanitized data into the .env configuration file. By controlling the database and injecting mail configuration variables, an attacker can execute arbitrary commands when the application attempts to send emails. This flaw affects all versions prior to 2.5.6.

  • CVE-2026-45503HIGH 8.1

    CVE-2026-45503 is a HIGH severity vulnerability in Microsoft Exchange Server that allows an already-authenticated attacker to access sensitive information over the network without user interaction. The flaw stems from improper authorization controls—meaning the server fails to properly verify what an authorized user should be allowed to see. An attacker with valid Exchange credentials can exploit this to read data they shouldn't have access to, such as emails, calendar entries, or other mailbox contents.

  • CVE-2026-45565HIGH 8.1

    Roxy-WI, a web management interface for popular open-source load balancers and reverse proxes, contains a flaw in how it validates user input across dozens of fields—including SSH credentials and server descriptions. An attacker with login credentials can bypass security checks by appending certain shell metacharacters to a path traversal payload, allowing them to read or modify files outside the intended scope. The vulnerability affects versions 8.2.6.4 and earlier, with no public patches available at publication.

  • CVE-2026-45569HIGH 8.1

    Roxy-WI, a web-based control panel for managing HAProxy, Nginx, Apache, and Keepalived servers, contains a path-traversal vulnerability in versions 8.2.6.4 and earlier. A security patch was attempted but contained a critical logic error: it checks whether the string '..' appears as an exact match in a list of values, rather than checking whether '..' appears anywhere within a file path. This means attackers can still bypass the check using common path-traversal payloads like '../../etc/passwd' or '..\..\/etc/passwd'. An authenticated user can exploit this to read, modify, or delete arbitrary configuration files on the server.

  • CVE-2026-45599HIGH 8.1

    A use-after-free vulnerability in Windows UPnP (upnp.dll) allows an attacker to run unauthorized code on affected systems over the network without requiring user interaction or special privileges. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server, making it a broad concern for enterprises. While exploitation requires specific network conditions (reflected in the CVSS score of 8.1), successful attacks could lead to complete system compromise.

  • CVE-2026-45635HIGH 8.1

    A type confusion vulnerability in Windows' Universal Plug and Play (UPnP) component allows attackers to execute code remotely on affected systems without authentication. The flaw stems from improper handling of incompatible data types in upnp.dll, which can be exploited over a network to gain full system compromise. This affects a broad range of Windows versions from Windows 10 through Windows 11, as well as Windows Server deployments.

  • CVE-2026-45707HIGH 8.1

    n8n-MCP is a server component that bridges AI assistants to n8n automation workflows. In multi-tenant deployments (where one operator hosts multiple customer accounts), versions before 2.51.2 had a critical credential-handling flaw: when requests lacked the headers specifying which tenant's n8n instance to target, the system fell back to the operator's own administrative credentials instead of rejecting the request or requiring proper tenant identification. An authenticated user in one tenant could exploit this to execute operations against the operator's primary n8n instance, potentially compromising the entire service.

  • CVE-2026-45732HIGH 8.1

    n8n, an open-source workflow automation platform, contains a permission-escalation vulnerability in its OAuth credential reconnect endpoints. An authenticated user with read-only access to a shared OAuth credential can hijack that credential's stored tokens by initiating a reconnect flow and supplying tokens from their own external account. This allows the attacker to redirect workflows that depend on the credential to execute under their identity, potentially exfiltrating data to attacker-controlled services or taking over shared integrations permanently. The issue affects versions prior to 1.123.43, 2.22.1, and 2.20.7.

  • CVE-2026-45743HIGH 8.1

    Termix is a web-based platform for managing remote servers via SSH, offering terminal access, port tunneling, and file editing. A critical flaw in 16 file-manager endpoints allows any authenticated user to hijack another user's active SSH session by guessing or learning their session ID. Once hijacked, an attacker gains full file access on the victim's connected server—they can read sensitive files, modify or delete critical data, download files, and execute arbitrary commands. This is a privilege escalation vulnerability: you only need valid credentials to Termix itself, not the target SSH host. The vulnerability has been fixed in version 2.3.2.

  • CVE-2026-45749HIGH 8.1

    Termix, a web-based server management platform, has a critical flaw in how it protects two-factor authentication (2FA) settings. Before version 2.3.2, an attacker who knows a user's password can disable TOTP (a common 2FA method) or reset backup codes without needing the user's phone or any 2FA code. This means that if your password leaks—whether through phishing, credential stuffing, or a separate data breach—an attacker can lock you out of your 2FA protection and gain full access to your account. The vulnerability has been patched in version 2.3.2.

  • CVE-2026-46138HIGH 8.1

    A flaw in the Linux kernel's Bluetooth event handler can cause the kernel to read memory beyond the bounds of a data structure and enter an infinite loop. The vulnerability occurs when a Bluetooth controller sends a specific event (LE_Create_BIG_Complete) with mismatched or insufficient data. An attacker with local or adjacent network access to a vulnerable system could exploit this to cause a denial of service by freezing the kernel with a lock held, making the system unresponsive.

  • CVE-2026-46232HIGH 8.1

    A vulnerability exists in the Linux kernel's PlayStation HID (Human Interface Device) driver that allows a malicious or malfunctioning PlayStation controller to cause the system to read beyond the bounds of a memory buffer. When processing touch input data, the driver fails to validate the number of touch reports claimed by the device, potentially exposing up to 2 KB of kernel memory that may then be leaked to userspace through input event channels if certain conditions are met. An attacker with physical access to a system or the ability to present a rogue USB device could exploit this to read sensitive information from kernel memory.

  • CVE-2026-46402HIGH 8.1

    Microsoft UFO, an open-source framework for intelligent automation, contains a path traversal vulnerability in version 3.0.1-4-ge2626659. An authenticated user can manipulate task names to write log files and directories outside the intended logs directory, potentially overwriting critical files or gaining unauthorized file system access on the affected system.

  • CVE-2026-46484HIGH 8.1

    Headplane, a web interface for managing Headscale VPN infrastructure, contains a path traversal and authorization bypass flaw in how it handles node and user rename operations. An authenticated attacker can exploit this to access or modify resources they should not be permitted to touch, potentially affecting the integrity and availability of the VPN management system. Versions 0.6.3 and 0.7.0-beta.3 contain the fix.

  • CVE-2026-46489HIGH 8.1

    SolidInvoice versions before 2.3.17 contain a stored cross-site scripting (XSS) vulnerability in the company logo upload feature. An authenticated administrator can upload an SVG file with embedded JavaScript that executes in the browsers of all authenticated users whenever they view any page in the application. The malicious script persists in the application's database and runs every time an affected page loads, giving an attacker the ability to steal session tokens, modify application data, or perform actions on behalf of legitimate users.

  • CVE-2026-46622HIGH 8.1

    SolidInvoice, an open-source invoicing platform, stores API authentication tokens as plain, unencrypted text in its database. Before version 2.3.17, anyone who gains read access to the database—whether through SQL injection, leaked backups, misconfigured database replicas, or insider access—immediately acquires all API credentials for every user without needing to decrypt or crack anything. This turns database compromise into immediate authentication compromise across your entire API surface.

  • CVE-2026-46828HIGH 8.1

    A vulnerability in Oracle Payroll (part of Oracle E-Business Suite) allows a low-privileged user with network access to read sensitive payroll data and make unauthorized changes to it. An attacker who already has valid credentials to the system—or gains them through other means—can exploit this flaw via HTTP requests to view or alter critical employee and compensation information. This is not a vulnerability requiring special technical skill or complex exploitation chains, making it a realistic risk for organizations running affected versions.

  • CVE-2026-46849HIGH 8.1

    A security flaw in Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38 allows someone with basic user credentials and network access to read, modify, or delete financial records they shouldn't be able to touch. The vulnerability requires an attacker to have valid login credentials but does not require any user interaction—once authenticated, the attacker can exploit it directly. This puts sensitive student financial data at significant risk.

  • CVE-2026-46851HIGH 8.1

    A vulnerability in Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) allows an unauthenticated attacker on the network to gain complete control of the system through an HTTP connection. While the vulnerability is rated as difficult to exploit, successful attacks result in full system compromise, including unauthorized access, data modification, and service disruption. No user interaction is required for exploitation.

  • CVE-2026-46891HIGH 8.1

    A vulnerability in Oracle JD Edwards EnterpriseOne Accounts Payable version 9.2 allows a low-privileged, authenticated user with network access to read, create, modify, or delete critical financial data without authorization. The attacker needs valid login credentials and can exploit the flaw via standard HTTP connections. The vulnerability primarily affects data confidentiality and integrity, making it a significant risk for organizations relying on JD Edwards for accounts payable operations.

  • CVE-2026-46898HIGH 8.1

    Oracle Enterprise Command Center Framework versions 15 and 16 contain a vulnerability that allows an unauthenticated attacker to gain unauthorized access to sensitive data or modify critical information through a network-based attack over HTTPS. The attack requires tricking a user into taking an action, but the attacker themselves does not need valid credentials. Once successful, an attacker can read, create, delete, or modify data depending on what the compromised user can access within the framework.

  • CVE-2026-46920HIGH 8.1

    A vulnerability in Oracle's Siebel CRM Cloud Manager allows an unauthenticated attacker with network access to take over a Siebel CRM Cloud Applications deployment. The attack requires some specific conditions to be met (high attack complexity) but does not require user interaction or valid credentials. If successfully exploited, an attacker gains full control over confidentiality, integrity, and availability of the affected CRM system. Versions 17.0 through 26.5 are vulnerable.

  • CVE-2026-46927HIGH 8.1

    Oracle Receivables, a core component of Oracle E-Business Suite, contains a network-accessible vulnerability in versions 12.2.3 through 12.2.15 that allows an unauthenticated attacker to remotely compromise the system. The vulnerability is exposed via SOAP web services and, if successfully exploited, grants an attacker full control over the Receivables application—potentially enabling them to read, modify, or destroy critical financial data. The attack requires specific conditions to be met (high attack complexity), but the absence of authentication requirements and the severity of potential impact make this a significant security concern for organizations running affected versions.

  • CVE-2026-46939HIGH 8.1

    A vulnerability exists in Oracle's Configure to Order product, a component of Oracle E-Business Suite used for managing complex product configurations and orders. An attacker with basic user credentials and network access can exploit this flaw to read sensitive data, create unauthorized records, modify existing data, or delete information—all without requiring user interaction or special technical conditions. The vulnerability affects versions 12.2.3 through 12.2.15 and carries a CVSS score of 8.1, reflecting significant risk to data confidentiality and integrity.

  • CVE-2026-47339HIGH 8.1

    Apache APISIX has an authorization flaw in its authz-casdoor plugin that allows attackers with valid credentials to bypass authentication controls and gain access using credentials from a different authentication source. This is possible when the plugin is deployed with its default settings. The vulnerability affects APISIX versions 2.14.1 through 3.16.0, and upgrading to version 3.17.0 eliminates the issue.

  • CVE-2026-47631HIGH 8.1

    Microsoft Exchange Server contains a cross-site scripting (XSS) vulnerability that could allow attackers to inject malicious scripts into web pages served by the Exchange interface. An attacker can trick users into visiting a crafted link, causing their browser to execute malicious code in the context of their Exchange session. This could lead to account compromise, email theft, or impersonation of the user to other Exchange recipients. The vulnerability requires user interaction (clicking a link) but does not require special privileges to exploit.

  • CVE-2026-47740HIGH 8.1

    Shopper is a headless e-commerce admin panel that manages orders and payments. Before version 2.8.0, the application had a critical permission bypass flaw: users with read-only access to orders could perform actions meant only for administrators with edit permissions. This included canceling orders, marking them as paid or complete, capturing payments from customer credit cards, and modifying shipment tracking. A low-privilege employee or attacker with basic read access could therefore manipulate any order's lifecycle and trigger real financial transactions without authorization.

  • CVE-2026-47930HIGH 8.1

    Adobe ColdFusion contains a flaw that allows a user with basic system access to bypass built-in security controls and read or modify data they shouldn't be able to access. The vulnerability stems from improper validation of user input and affects multiple recent ColdFusion versions. Notably, an attacker does not need to trick an end user into clicking a malicious link or opening a file—the exploit can happen automatically if an authenticated user with low privileges interacts with an affected application.

  • CVE-2026-48610HIGH 8.1

    A vulnerability in UniFi OS devices allows attackers on the network to make unauthorized changes to affected devices due to improper access controls. Under specific network configurations, an attacker doesn't need valid credentials to modify device settings—a significant risk for organizations relying on UniFi infrastructure for network management and security.