By severity
High-severity vulnerabilities
CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 6 of 42
- CVE-2026-46444HIGH 8.8
Flowise versions prior to 3.1.2 contain a critical authentication flaw in the OpenAI Assistants Vector Store endpoints. Any authenticated user with a valid API key can perform unrestricted create, read, update, and delete operations on vector store data without additional permission checks. This means a low-privileged user or compromised API key can manipulate vector stores that should only be accessible to specific users or administrative roles.
- CVE-2026-46475HIGH 8.8
Flowise, a platform for building customized LLM workflows through a drag-and-drop interface, contains a privilege escalation vulnerability in its assistant management features. Prior to version 3.1.2, an authenticated attacker can exploit mass-assignment flaws in the create and update endpoints to take over assistants belonging to other workspaces, potentially accessing or modifying shared LLM configurations across organizational boundaries.
- CVE-2026-46476HIGH 8.8
Flowise, a visual tool for building customized large language model workflows, contains a vulnerability in how it handles template creation and updates. Attackers with user access can exploit mass-assignment flaws to take control of templates across different workspaces—essentially hijacking template configurations that should be isolated from one another. The vulnerability affects all versions prior to 3.1.2 and has been resolved in that release.
- CVE-2026-46477HIGH 8.8
Flowise, a visual interface for building and customizing language model workflows, contains a mass-assignment vulnerability in its dataset management functions. Before version 3.1.2, an authenticated attacker could exploit weak input validation during dataset creation or updates to access and modify datasets across different workspaces—effectively taking over datasets belonging to other users or teams. The vulnerability requires a valid user account to exploit but poses a serious risk to multi-tenant Flowise deployments where data isolation is critical.
- CVE-2026-46478HIGH 8.8
Flowise, a popular drag-and-drop interface for building customized language model workflows, contains a privilege escalation flaw in its DatasetRow functionality. Before version 3.1.2, an authenticated attacker could manipulate how new dataset rows are created or updated, allowing them to inject or modify rows belonging to other workspaces. This mass-assignment vulnerability effectively grants an attacker control over another organization's data within the same Flowise deployment, provided they have valid login credentials.
- CVE-2026-46479HIGH 8.8
Flowise, a no-code platform for building customized LLM workflows, contains a privilege escalation vulnerability in its evaluation management system. Attackers with valid user credentials can modify evaluation records in ways that bypass workspace isolation, allowing them to view, edit, or delete evaluations belonging to other teams or organizations. The vulnerability stems from improper input validation in the create and update endpoints—a classic mass-assignment flaw. Version 3.1.2 and later patch this issue.
- CVE-2026-46480HIGH 8.8
Flowise, a no-code platform for building customized large language model workflows, contains a privilege escalation vulnerability in its evaluator management feature. An authenticated attacker can exploit improper input validation during evaluator creation or updates to gain unauthorized access to evaluators across different workspaces. This allows an attacker to take over evaluators belonging to other users or teams, potentially manipulating AI workflow logic and data without authorization. The vulnerability requires an existing login but no elevated privileges to exploit.
- CVE-2026-46490HIGH 8.8
A flaw in samlify, a Node.js SAML authentication library, allows attackers to inject malicious XML into SAML assertions. When user attributes (like email or display name) are processed during single sign-on, an attacker can add fake authorization attributes that get signed by the identity provider and trusted by the service provider. This can lead to privilege escalation if the application relies on SAML attributes for access control decisions.
- CVE-2026-46519HIGH 8.8
mcp-server-kubernetes is a protocol server that helps manage Kubernetes clusters through a standardized interface. The software offers three environment variables designed to limit which cluster operations a user can perform—read-only mode, non-destructive operations only, or a custom whitelist. Before version 3.6.0, these restrictions only applied when listing available tools, but not when actually executing them. An authenticated user could bypass all restrictions by directly invoking a tool name they discovered, gaining full control over the cluster regardless of the configured safety mode. Version 3.6.0 fixes this enforcement gap.
- CVE-2026-46580HIGH 8.8
Eclipse Theia contains a vulnerability that allows attackers to hijack AI chat functionality by embedding malicious prompt template files in repositories. When a developer opens an untrusted repository in Theia, the application automatically loads prompt files from a `.prompts/*.prompttemplate` directory, which can overwrite the AI agent's instructions with attacker-controlled commands. This indirect prompt injection can be chained with other Theia features to steal data or execute arbitrary commands on the developer's machine.
- CVE-2026-46590HIGH 8.8
Apache Camel's post-quantum cryptography (PQC) component has a critical flaw in how it handles cryptographic key metadata. When key managers like HashiCorp Vault or AWS Secrets Manager retrieve stored keys, they deserialize data using an unsafe Java deserialization method without any validation. An attacker who can write to the backend storage system (Vault or AWS Secrets Manager) can inject a malicious serialized object that executes arbitrary code when the application deserializes it during normal key operations. This is particularly dangerous because the vulnerability persists from an earlier incomplete fix and affects three different key storage implementations.
- CVE-2026-46612HIGH 8.8
Fission, an open-source serverless framework for Kubernetes, has a critical authentication gap in its storage service. Before version 1.23.0, any workload running in the same Kubernetes cluster can access, download, upload, or delete function archives without any credentials or permission checks. This means a compromised pod or malicious insider could steal code from other teams, inject malicious functions, or disrupt service availability.
- CVE-2026-46656HIGH 8.8
Bludit, a content management system, has a critical flaw in how it manages user sessions. When an administrator deletes a user account from the database, the system fails to invalidate that user's active login sessions. This means a deleted user can continue accessing the CMS with full privileges as if their account still existed—a "ghost session" vulnerability. The flaw affects all Bludit versions before 3.22.0 and is fixed in that release.
- CVE-2026-46746HIGH 8.8
SINEC INS, a Siemens industrial networking application, contains a command injection vulnerability in its file upload functionality. An authenticated user can craft malicious directory names that bypass input validation, plant shell commands, and trigger their execution when the application later retrieves directory listings. The attacker gains command execution at the privilege level of the service account, potentially compromising the entire system. All versions before 1.0 SP2 Update 6 are affected.
- CVE-2026-46748HIGH 8.8
CVE-2026-46748 affects Siemens SINEC INS installations running versions prior to V1.0 SP2 Update 6. A binary within the system has been granted excessive Linux kernel capabilities (specifically cap_dac_override), which allows it to bypass normal file permission checks. A local attacker who gains access to the system can exploit this to read, modify, or delete any file and escalate privileges to root, gaining complete control of the host. This is a serious flaw in privilege isolation that compounds the risk of any initial compromise.
- CVE-2026-46780HIGH 8.8
A flaw in Oracle WebCenter Content: Imaging allows someone with a low-level user account to take complete control of the imaging system over the network. The vulnerability requires only basic network access and valid login credentials—no special interaction or social engineering is needed. Once exploited, an attacker gains full read, write, and administrative capabilities, effectively compromising the entire imaging application.
- CVE-2026-46826HIGH 8.8
CVE-2026-46826 is a high-severity vulnerability in Oracle Payroll (part of Oracle E-Business Suite) that allows attackers with valid user credentials to gain complete control over the payroll system via the network. The vulnerability affects versions 12.2.3 through 12.2.15 and stems from insufficient access control mechanisms. An attacker needs only a low-privileged account to exploit it remotely—no special tools or user interaction required—making it a material threat to organizations relying on Oracle payroll processing.
- CVE-2026-46827HIGH 8.8
CVE-2026-46827 is a high-severity vulnerability in Oracle E-Business Suite's Payroll module that allows a low-privileged network attacker to gain full control over the payroll system. An authenticated user with minimal permissions can exploit this flaw remotely via HTTP to read sensitive data, modify payroll records, or disrupt service availability. This represents a complete compromise of the affected payroll component.
- CVE-2026-46837HIGH 8.8
A vulnerability exists in Oracle Flow Manufacturing (part of Oracle E-Business Suite) that allows a low-privileged user with network access to gain complete control over the affected system. An attacker who already has valid credentials can exploit a flaw in the security component via SQL to read, modify, or delete data—or disrupt system operations entirely. The vulnerability affects Oracle E-Business Suite versions 12.2.9 through 12.2.15.
- CVE-2026-46864HIGH 8.8
A flaw in Oracle Enterprise Manager Base Platform's Agent Next Gen component allows attackers with low-level network access to take over the entire management platform. An authenticated user with SSH access can exploit this issue to gain full control, compromising confidentiality, integrity, and availability of your Enterprise Manager environment. Versions 13.5 and 24.1 are affected. This is a high-severity issue that requires prompt attention.
- CVE-2026-46885HIGH 8.8
A vulnerability exists in Oracle Siebel CRM's integration component (EAI) that allows a low-privilege user with network access to take complete control of the affected system. The flaw is straightforward to exploit and requires only standard HTTP access—no complex attack setup needed. An attacker who already has basic user credentials can escalate to full compromise, affecting data confidentiality, system integrity, and availability. Versions 17.0 through 26.5 are vulnerable.
- CVE-2026-46886HIGH 8.8
A high-severity vulnerability in Oracle Siebel CRM's Marketing application allows attackers with basic user credentials to gain complete control over the system without requiring user interaction. The flaw affects all currently supported versions (17.0 through 26.5) and is accessible over standard HTTP network connections. Successful exploitation results in full compromise—attackers can read sensitive data, modify records, and disrupt marketing operations.
- CVE-2026-46903HIGH 8.8
A vulnerability in Oracle JD Edwards EnterpriseOne Tools allows a user with basic network access and low-level system privileges to gain complete control over the application. The flaw resides in the business logic security layer and can be exploited without user interaction or complex attack setup. An attacker leveraging this vulnerability could read sensitive financial data, modify business records, or disrupt operations.
- CVE-2026-46916HIGH 8.8
A high-severity flaw in Oracle's Process Manufacturing Product Development component (part of E-Business Suite) allows authenticated users with low-level network access to gain full control over the affected system. An attacker who has obtained basic credentials can exploit this over the network to read sensitive data, modify critical information, and disrupt operations without requiring user interaction. Versions 12.2.3 through 12.2.15 are vulnerable.
- CVE-2026-46921HIGH 8.8
A high-severity vulnerability exists in Oracle Siebel CRM Cloud Manager that allows a low-privileged attacker with network access to take over the entire application. The flaw affects Siebel CRM versions 17.0 through 26.5 and requires only standard HTTP access—no user interaction or elevated privileges needed beyond basic network authentication. Attackers exploiting this could gain full control over confidentiality, integrity, and availability of the system.
- CVE-2026-46926HIGH 8.8
Oracle Siebel CRM Cloud Applications contains a privilege escalation flaw in the Siebel Cloud Manager component that allows a low-privileged local user to gain complete control over the CRM system. An attacker already logged into the infrastructure where Siebel runs can exploit this vulnerability without further user interaction to compromise confidentiality, integrity, and availability of the application and potentially adjacent systems.
- CVE-2026-46928HIGH 8.8
A vulnerability in Oracle Spares Management, part of Oracle E-Business Suite, allows users with standard network access and basic system credentials to gain complete control over the application. An attacker with low-level privileges can exploit this flaw remotely via HTTPS to read sensitive data, modify records, and disrupt operations. The vulnerability affects versions 12.2.3 through 12.2.15.
- CVE-2026-46929HIGH 8.8
CVE-2026-46929 is a high-severity vulnerability in Oracle's Cost Management component within Oracle E-Business Suite (versions 12.2.3 through 12.2.15). An attacker with a low-level user account and network access can exploit this flaw via HTTP to gain complete control over the Cost Management system. The vulnerability requires no user interaction, making it straightforward to exploit. Successful exploitation allows attackers to read sensitive data, modify cost planning information, and disrupt system availability.
- CVE-2026-46931HIGH 8.8
A flaw in Oracle Enterprise Asset Management (part of Oracle E-Business Suite) allows someone with low-level access to the system to gain complete control over it through the network. The attacker needs basic user credentials to exploit this, and no additional interaction is required. Once successful, they can read, modify, or destroy data, or take the system offline. This affects versions 12.2.6 through 12.2.15.
- CVE-2026-46937HIGH 8.8
A vulnerability in Oracle iSetup (a configuration and setup component of Oracle E-Business Suite) allows an authenticated user with basic network access to take control of the iSetup application. The flaw affects versions 12.2.3 through 12.2.15. Because the vulnerability requires low-level credentials but no user interaction, it presents significant risk in environments where contractor, vendor, or junior staff accounts exist—anyone with a valid login can trigger the compromise without special tools or social engineering.
- CVE-2026-46940HIGH 8.8
CVE-2026-46940 is a critical vulnerability in Oracle Cost Management, a component of Oracle E-Business Suite. An attacker with a low-level user account and network access can exploit this flaw to take over the entire Cost Management system. The vulnerability is network-accessible, does not require user interaction, and can compromise confidentiality, integrity, and availability of the affected system. Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should treat this as an urgent security matter.
- CVE-2026-46942HIGH 8.8
A vulnerability in Oracle's Process Manufacturing Process Planning component allows attackers with low-level network access to take over the system. The flaw affects versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite module and requires an attacker to have valid user credentials, but no special privileges or user interaction. Once exploited, an attacker gains complete control over the affected application, compromising all data confidentiality, system integrity, and availability.
- CVE-2026-46947HIGH 8.8
Oracle Advanced Outbound Telephony, a component within Oracle E-Business Suite versions 12.2.3 through 12.2.15, contains a network-accessible vulnerability that allows authenticated users with low-level privileges to gain unauthorized control over the system. An attacker with valid credentials can exploit this flaw remotely via HTTP without user interaction, leading to complete system compromise—affecting confidentiality, integrity, and availability of the telephony system.
- CVE-2026-46950HIGH 8.8
Oracle Advanced Outbound Telephony, a component within Oracle E-Business Suite, contains a vulnerability that allows an authenticated attacker with basic user privileges to remotely compromise the system over HTTP. The flaw is straightforward to exploit and grants attackers complete control—the ability to read sensitive data, modify configurations, and disrupt service availability. Organizations running affected versions (12.2.3 through 12.2.15) should treat this as a priority remediation target.
- CVE-2026-46951HIGH 8.8
A vulnerability in Oracle Quality, part of Oracle E-Business Suite, allows an authenticated attacker to gain complete control over the Oracle Quality system. The attacker only needs basic user-level network access via HTTP to trigger the flaw. Once exploited, an attacker can read, modify, or delete sensitive data and disrupt quality operations. The vulnerability affects Oracle Quality versions 12.2.3 through 12.2.15.
- CVE-2026-46952HIGH 8.8
A vulnerability in Oracle Quality, part of Oracle E-Business Suite, allows users with basic system access to take complete control of the application via network requests. The flaw affects Oracle Quality versions 12.2.3 through 12.2.15 and requires only low-level credentials to exploit—no special tricks or user interaction needed. Successful exploitation grants an attacker the ability to read, modify, and delete data, or disable the system entirely.
- CVE-2026-46961HIGH 8.8
A critical vulnerability in Oracle Project Portfolio Analysis allows authenticated users with basic network access to gain full control over the application. An attacker with a low-privilege account can exploit this flaw to read, modify, or delete sensitive project data and disrupt service availability. The vulnerability affects multiple versions of the product (12.2.3 through 12.2.15) and requires only HTTP connectivity—no special conditions or user interaction needed once the attacker gains initial access credentials.
- CVE-2026-46962HIGH 8.8
A vulnerability in Oracle Project Portfolio Analysis (part of Oracle E-Business Suite) allows someone with basic network access and low-level user credentials to take complete control of the system. The flaw affects versions 12.2.3 through 12.2.15 and requires only a standard user account and HTTP access—no special techniques needed. Once exploited, an attacker gains the ability to read sensitive data, modify information, and disrupt operations.
- CVE-2026-46965HIGH 8.8
A critical vulnerability in Oracle Universal Work Queue—a component of Oracle E-Business Suite—allows a low-privileged user with network access to take complete control of the Work Provider Site Level Administration functions. The attacker needs only basic network connectivity and low-level credentials; no special interaction or advanced attack techniques are required. Once exploited, an attacker can read, modify, and delete data, as well as disrupt system availability.
- CVE-2026-46967HIGH 8.8
A flaw in Oracle's Public Sector Financials (International) module, part of E-Business Suite, allows an authenticated attacker with basic network access to gain complete control over the application. The vulnerability exists in how the system handles user permissions and can be exploited without requiring user interaction. Attackers could read sensitive data, modify records, or disrupt service availability.
- CVE-2026-46972HIGH 8.8
A flaw in Oracle's Outsourced Manufacturing for Discrete Industries module (versions 12.2.3 through 12.2.15) allows attackers who have basic user-level network access to fully compromise the system. An attacker with low-privilege credentials can exploit this vulnerability over HTTP to gain complete control over the application, potentially reading, modifying, or destroying sensitive manufacturing data. The vulnerability requires only standard network connectivity and user credentials to trigger—no social engineering or complex exploitation steps are needed.
- CVE-2026-46973HIGH 8.8
A vulnerability in Oracle's Outsourced Manufacturing for Discrete Industries (part of E-Business Suite) allows attackers with basic user credentials to gain complete control over the system via the network. The flaw affects all versions from 12.2.3 through 12.2.15 and poses a severe risk because an attacker with low-level access can bypass controls to read, modify, or delete critical manufacturing data.
- CVE-2026-47125HIGH 8.8
Arcane, a Docker container management interface, has a critical flaw in how it protects global environment variables. Any logged-in user—not just administrators—can modify system-wide configuration values that affect every containerized project. An attacker could inject malicious registry URLs, database credentials, or other secrets into these shared variables, poisoning deployments across the entire system. The vulnerability exists in versions prior to 1.19.2 and requires only basic authentication to exploit.
- CVE-2026-47162HIGH 8.8
Vim, the popular open-source text editor, contains a code injection vulnerability in its netrw file browser plugin. When you browse directories in Vim, it saves a history of the paths you've visited to a file called .netrwhist. An attacker can craft a malicious directory name containing special characters that, when saved to this history file, breaks out of the intended string format and tricks Vim into executing arbitrary commands the next time you open the editor. This could allow an attacker to run malicious code on your system if you cd into or browse a directory with a carefully crafted name. The vulnerability is fixed in Vim version 9.2.0495 and later.
- CVE-2026-47289HIGH 8.8
A heap-based buffer overflow vulnerability exists in Remote Desktop Client that could allow an attacker to run malicious code on a user's computer over the network. The flaw requires user interaction (such as connecting to a malicious RDP server or opening a crafted file) but does not require any authentication. If exploited, an attacker could gain full control of the affected system.
- CVE-2026-47342HIGH 8.8
Apache OFBiz contains a privilege escalation flaw that allows authenticated users with limited system access to gain elevated privileges. An attacker who already has basic login credentials can exploit this vulnerability to perform administrative actions without proper authorization. The issue affects all versions prior to 24.09.07. Organizations running vulnerable OFBiz instances should prioritize patching to prevent unauthorized privilege elevation.
- CVE-2026-47645HIGH 8.8
CVE-2026-47645 is a critical flaw in Microsoft 365 Copilot's Business Chat feature that allows attackers to trick users into visiting malicious websites by crafting deceptive links. When exploited, this open redirect vulnerability can enable an attacker to escalate their privileges within the targeted organization. The attack requires user interaction—specifically, a victim must click a malicious link—but no special access or complex conditions are needed to craft the exploit, making it a significant risk for organizations relying on Copilot for business communications.
- CVE-2026-47653HIGH 8.8
A use-after-free vulnerability in Microsoft's Remote Desktop Client allows an attacker to execute arbitrary code on a victim's computer over the network. The attacker does not need valid credentials, but the user must interact with the application (such as clicking a link or opening a file) for the attack to succeed. This is a serious flaw affecting many versions of Windows 10, Windows 11, and Windows Server editions.
- CVE-2026-47828HIGH 8.8
The BOSH CLI, used to deploy and manage BOSH Directors on infrastructure, fails to validate TLS certificates when uploading sensitive data during environment creation and deletion. An attacker on the network can intercept these connections, steal the basic authentication credentials, and harvest bootstrap secrets that provide immediate administrative access to the BOSH Director. This is a critical supply-chain risk because the compromised credentials enable root-level code execution on newly provisioned systems.
- CVE-2026-47830HIGH 8.8
A permissions flaw in BOSH Windows stemcell builder allows authenticated users with limited privileges to replace critical system executables (the BOSH agent service wrapper or the BOSH agent itself) with malicious versions. When the affected service restarts or the system reboots, these replaced files execute with full system privileges (NT AUTHORITY\SYSTEM), giving an attacker complete control of the host. This is a local privilege escalation vulnerability that affects BOSH-Windows-stemcell-builder versions before v2019.98.
- CVE-2026-47932HIGH 8.8
Adobe ColdFusion versions 2023.19, 2025.8 and earlier contain a path traversal vulnerability that allows attackers to bypass security controls and access files outside their intended boundaries. An attacker must trick a user into opening a malicious file to exploit this flaw, making it a user-interaction-dependent attack. Once exploited, an attacker gains unauthorized access to sensitive data, can modify files, or disrupt system availability—with the ability to impact other systems or users connected to the vulnerable ColdFusion instance.
- CVE-2026-48017HIGH 8.8
DbGate, a cross-platform database management tool, contains a critical code injection vulnerability in versions 7.1.8 and earlier. An authenticated user—even one with minimal permissions—can inject malicious JavaScript code through the POST /runners/load-reader endpoint that executes server-side with full Node.js process privileges. This bypasses DbGate's sandbox protections and allows an attacker to run arbitrary commands, access files, steal database credentials stored in DbGate, and potentially gain root access to the host system, particularly in containerized deployments. The vulnerability requires an attacker to have basic authentication credentials but no special roles or elevated permissions.
- CVE-2026-48095HIGH 8.8
7-Zip, the widely used file compression utility, contains a critical flaw in how it handles NTFS compressed disk images. When a specially crafted image is opened—even with an innocuous file extension—the application miscalculates memory buffer sizes, leading to a situation where attackers can write massive amounts of data into a tiny allocated space. This memory corruption can overwrite the application's internal control structures, giving attackers the ability to execute arbitrary code on the affected system. Versions 26.00 and earlier are vulnerable; version 26.01 and later have been patched.
- CVE-2026-48307HIGH 8.8
Adobe ColdFusion versions 2025.9, 2023.20, and earlier contain a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When a user clicks a specially crafted link, the injected script executes in their browser with their privileges, potentially enabling attackers to steal session tokens, modify page content, or perform unauthorized actions on their behalf. The vulnerability has a high CVSS score of 8.8, reflecting the potential for significant impact across confidentiality, integrity, and availability.
- CVE-2026-48557HIGH 8.8
Spatie's Laravel Media Library, a widely-used file management plugin for Laravel applications, has a vulnerability in its file upload filtering that allows authenticated attackers to upload files with names like shell.php.jpg that appear safe but retain executable code. Versions before 11.23.0 fail to properly block dangerous file extensions, and under specific Apache server configurations, these uploads can be executed as PHP scripts, potentially giving attackers full control of the application.
- CVE-2026-48704HIGH 8.8
Warp, an AI-assisted development environment, contains a vulnerability that allows malicious Markdown documents or project files to deceive users into executing local files on their system. When a user clicks what appears to be an innocent link in Markdown rendered within Warp, the application may pass the underlying local file path to the operating system's default file handler—potentially launching executables or other dangerous file types rather than safely displaying them. An attacker could craft a project or document with hidden links that exploit this behavior, leading to arbitrary code execution if the user is tricked into clicking. The vulnerability affects versions from October 2023 through early May 2026 and is resolved in the May 6, 2026 stable release.
- CVE-2026-48715HIGH 8.8
A buffer overflow vulnerability exists in radvdump, a diagnostic utility included with the IPv6 router advertisement daemon (radvd). When radvdump processes specially crafted IPv6 router advertisement packets, it can write far more data than its internal buffer can hold, potentially allowing an attacker on the local network to execute arbitrary code. The main radvd daemon itself is not vulnerable. Versions of radvd prior to 2.21 are affected.
- CVE-2026-48720HIGH 8.8
Warp, an AI-assisted terminal and development environment, contains a critical file-handling vulnerability that allows attackers to write arbitrary files to a user's system by embedding specially crafted terminal escape sequences in command output. When a user runs a command that contains a malicious OSC 1337 File payload, Warp will silently decode and save the payload as a local file without prompting the user for confirmation. This affects versions from March 2025 through early May 2026, and has been patched in version 0.2026.05.06.15.42.stable_01.
- CVE-2026-48732HIGH 8.8
Warp, a development environment that enables agent-assisted coding workflows, contains a command injection vulnerability in its SSH handling mechanism. When Warp connects to remote hosts via SSH to gather metadata, it constructs helper commands using the remote working directory path. An attacker who controls a repository name, directory structure, or host configuration can inject malicious shell commands into that path. When Warp builds its helper command, those injected commands execute on the remote host with the privileges of the authenticated SSH session—effectively giving the attacker code execution as the victim user. The vulnerability affects Warp versions from March 2023 through early May 2026 and is resolved in version 0.2026.05.06.15.42.stable_01.
- CVE-2026-48793HIGH 8.8
Jellyfin, a self-hosted media server, contains a vulnerability in how it processes subtitle files before sending them to FFmpeg for conversion. An attacker who can upload or place a malicious subtitle file in a Jellyfin media library can inject commands into the FFmpeg process, potentially reading sensitive files from the server or overwriting files. The vulnerability is particularly dangerous because it doesn't require authentication—anyone with network access can trigger it. Jellyfin versions prior to 10.11.10 are affected.
- CVE-2026-48948HIGH 8.8
A Joomla vulnerability allows authenticated users to bypass access controls and download contact card (vcard) exports for contacts they should not be able to access. An attacker with a user account can exploit this to retrieve sensitive contact information that has been restricted by administrators, potentially exposing personal data, organizational structures, or confidential contact details.
- CVE-2026-48958HIGH 8.8
A vulnerability in Joomla's webservices functionality allows authenticated users to bypass access controls and create custom fields they shouldn't have permission to modify. An attacker with valid user credentials can exploit this to inject unauthorized fields into the system, potentially altering application behavior or exfiltrating sensitive information. The flaw stems from improper validation of user permissions before allowing field creation through the API.
- CVE-2026-49062HIGH 8.8
A flaw in WP Engine's Faust.Js framework allows an attacker with login credentials to bypass authentication controls and exploit the password recovery mechanism. An authenticated user can manipulate the password recovery process to gain unauthorized access or escalate privileges, effectively circumventing normal authentication barriers. This is particularly dangerous because the attack requires only basic login access—not admin rights—yet yields full system compromise potential.
- CVE-2026-49111HIGH 8.8
ThemeGrill's Masteriyo LMS contains a privilege escalation flaw where user roles and permissions are incorrectly assigned. An authenticated attacker can exploit this to gain elevated privileges within the learning management system, potentially accessing or modifying content and settings they should not be able to reach. The vulnerability affects all versions through 2.2.0.
- CVE-2026-49143HIGH 8.8
BrowserStack Runner versions up to 0.9.5 contain a critical remote code execution flaw in its /_log HTTP handler. An unauthenticated attacker on the local network can send specially crafted JSON requests to execute arbitrary code on the server without providing credentials. The vulnerability stems from unsafe use of Node.js sandbox features combined with eval(), which allows attackers to break out of the sandbox and gain full system access.
- CVE-2026-49157HIGH 8.8
Apache ActiveMQ contains a permissions misconfiguration in its Jolokia interface that allows low-privilege web users to perform high-level broker management operations. Specifically, non-admin accounts can execute commands like addQueue and removeQueue that should be restricted to administrators only. This violates the principle of least privilege and can lead to unauthorized service disruption or configuration tampering. Affected versions are ActiveMQ 5.x before 5.19.7 and 6.x before 6.2.6.
- CVE-2026-49190HIGH 8.8
A flaw in Acer Connect M6E 5G firmware fails to properly enforce access controls when processing internal system instructions, allowing authenticated users to install unauthorized applications or execute arbitrary commands on the device. The vulnerability requires valid login credentials but provides no other barriers once an attacker gains initial access.
- CVE-2026-49194HIGH 8.8
A debugging function called SCREEN_CLICK(5053) in certain Acer Connect M6E 5G devices allows an authenticated user to bypass the normal login process and gain direct access to an interactive shell. This circumvents device security controls and could enable an attacker with valid credentials to take full control of the device without standard authentication checks.
- CVE-2026-49195HIGH 8.8
A debug service running on Acer Predator Connect W6X devices exposes a command interface on port 9000 without requiring any authentication. Any device with network access to an affected device can send arbitrary commands to this service, potentially taking complete control of the device. This is a local network vulnerability, meaning the attacker must be on the same network segment as the target.
- CVE-2026-49241HIGH 8.8
The Angular Language Service VS Code Extension allows developers to write Angular code with advanced IDE features like autocomplete and error checking. A critical flaw in versions before 21.2.4 lets an attacker hide malicious code in a project repository that automatically executes when a developer opens that folder in VS Code. The attack works by placing a fake TypeScript library file in the repository and configuring VS Code settings to point to it—the extension loads and runs this fake library without asking permission or checking if the workspace is trusted. An attacker only needs to commit the malicious code to a repository (like on GitHub) and wait for developers to clone and open it.
- CVE-2026-49247HIGH 8.8
Jellyfin, a self-hosted media server, has a path traversal vulnerability in its client logging feature that allows any logged-in non-admin user to write files to arbitrary locations on the server. An attacker can craft malicious log uploads with specially crafted names containing directory-escape sequences (../) to place files anywhere the Jellyfin process has write access, enabling potential code execution, data corruption, or service disruption. The issue affects versions 10.9.0 through 10.11.9 and is resolved in 10.11.10.
- CVE-2026-49298HIGH 8.8
Apache Airflow's KubernetesExecutor has a credential exposure bug where JWT tokens used by worker pods to authenticate against the Execution API are inadvertently visible in Kubernetes pod specifications. An attacker with read-only access to the Airflow namespace in Kubernetes (a common access level) can retrieve these tokens from standard `kubectl describe pod` commands and then use them to execute privileged API operations—such as triggering DAG runs, clearing runs, or modifying Variables, Connections, and XComs—without needing direct task execution privileges. This vulnerability only affects deployments using the KubernetesExecutor. The fix requires upgrading both the airflow-providers-cncf-kubernetes package (if not already done per CVE-2026-27173) and the core apache-airflow package to close complementary attack surfaces.
- CVE-2026-4944HIGH 8.8
vLLM version 0.14.1 contains a critical vulnerability in its model loading mechanism that forces remote code execution to be enabled, regardless of user security settings. Specifically, two model implementation files (NemotronVL and KimiK25) have hardcoded parameters that override a user's explicit decision to disable remote code execution. An attacker can exploit this by hosting a malicious model on HuggingFace and triggering code execution on systems that load these specific models, even when administrators thought they had disabled this risky feature.
- CVE-2026-49443HIGH 8.8
A critical authentication flaw in authentik—an open-source identity provider—allows attackers to hijack user accounts across the platform. If an attacker has the ability to modify a source connection (such as an external authentication provider) and controls an account in one of those sources, they can log in as any other user in the system. This is a privilege escalation vulnerability requiring two preconditions: administrative access to source configuration and an existing account in a connected source. The flaw affects authentik versions prior to 2025.12.6, 2026.2.4, and 2026.5.1.
- CVE-2026-49492HIGH 8.8
Markdown Preview Enhanced, a popular tool for rendering markdown documents with enhanced features, contains a critical flaw in how it handles external content. When you preview a markdown file, the extension can be tricked into executing system commands hidden within the document—specifically through diagram filenames, imported file paths, and LaTeX code attributes. On Windows systems, an attacker can craft a malicious markdown file that runs arbitrary operating system commands the moment you open it for preview. This happens because the tool passes unsanitized user input directly to the system shell without proper validation. The vulnerability was fixed in version 0.8.28 by changing how these inputs are processed and adding validation checks.
- CVE-2026-49493HIGH 8.8
Markdown Preview Enhanced versions before 0.8.28 contain a critical flaw in how they process bitfield code blocks embedded in markdown documents. When a user opens or exports a markdown file containing a malicious bitfield block, the application executes arbitrary code with the privileges of the user running the preview. An attacker can craft a seemingly innocent markdown document that, when rendered, runs malicious commands on the victim's system. This is a code injection vulnerability triggered by user interaction with a document.
- CVE-2026-49498HIGH 8.8
Ghidra versions 11.0 through 12.0 contain a SQL injection flaw in the password-change functionality of its PostgreSQL database integration. An authenticated user can manipulate their username to inject malicious SQL commands, ultimately gaining superuser access to the entire PostgreSQL database. This is a post-authentication attack that requires valid credentials but can lead to complete database compromise.
- CVE-2026-49959HIGH 8.8
Hermes WebUI versions before 0.51.311 contain a vulnerability that allows authenticated users to run arbitrary commands on the server. An attacker with valid login credentials can inject malicious configuration into a Git repository's settings file (.git/config) that gets executed when the application performs Git operations like status checks or fetches. This is particularly dangerous because Git has multiple mechanisms for running external commands—including file monitors, credential handlers, and SSH wrappers—all of which can be weaponized through configuration poisoning.
- CVE-2026-50016HIGH 8.8
pnpm, a widely-used Node.js package manager, contains a path traversal vulnerability affecting versions before 10.34.0 and 11.4.0. A malicious package published to a registry can craft dependency alias metadata containing directory traversal sequences (like '../'). When you run `pnpm install --ignore-scripts`, pnpm treats this alias as a filesystem path without proper validation, allowing the attacker's package to create symlinks that overwrite legitimate files and directories in your project with links pointing to the attacker's package folders. This means an attacker can potentially replace critical project files with their controlled content, even when you explicitly disable script execution during installation.
- CVE-2026-50178HIGH 8.8
The Angular Language Service extension for VS Code allows developers to write and debug Angular templates more effectively. However, the extension's server component doesn't properly clean up malicious code hidden in documentation comments (JSDoc) before displaying them as helpful tooltips. An attacker who controls a project file or sneaks malicious code into an npm package can embed a hidden command that runs when a developer hovers over and clicks a tooltip. This gives the attacker the ability to execute arbitrary commands on the developer's machine. The vulnerability is fixed in version 21.2.4.
- CVE-2026-50223HIGH 8.8
Apache OFBiz contains a code injection vulnerability that allows users with limited permissions to inject malicious template code and execute arbitrary commands on affected servers. An authenticated attacker with Content or DataResource editing privileges can exploit this weakness to gain full control over the system. The vulnerability affects all OFBiz versions prior to 24.09.07 and requires immediate patching.
- CVE-2026-50635HIGH 8.8
LimeSurvey has a password-reset vulnerability that lets attackers take over user accounts without needing valid credentials. When a user requests a password reset, LimeSurvey emails them a link to set a new password. The problem: the application builds that link using whatever hostname the attacker sends in their request, without validating it against a whitelist. By default, LimeSurvey doesn't enforce any allowlist at all. An attacker can submit a forgotten-password request for any known username, supply a spoofed hostname they control, and receive an email containing a valid password-reset token pointed at their malicious domain. When the legitimate user clicks the link or when email security tools scan it, the token gets exposed to the attacker, who can then use it to reset the actual account password and gain access.
- CVE-2026-50636HIGH 8.8
LimeSurvey's RemoteControl API contains a SQL injection vulnerability in two methods used to manage survey participant invitations. An authenticated attacker with permission to update survey tokens can craft a malicious input array that breaks out of the intended SQL query and execute arbitrary database commands. Because LimeSurvey's database configuration allows stacked queries, an attacker can not only read sensitive data—such as administrator password hashes, survey responses, and user session records—but also modify or delete any data in the database, including taking over administrator accounts. This attack requires the RemoteControl interface to be explicitly enabled (not the default configuration) and authenticated API access.
- CVE-2026-50733HIGH 8.8
Markdown Preview Enhanced, a popular markdown editor extension, contains a critical flaw in how it renders WaveDrom diagrams—a type of digital waveform visualization. Versions before 0.8.28 use JavaScript's eval() function to process diagram code, which means maliciously crafted markdown files can trick the software into executing arbitrary code on your machine. An attacker only needs to get you to open or export a booby-trapped markdown document; no interaction beyond that is required. The vulnerability works across all rendering modes: live preview, presentation slides, and HTML export. A patch is available that replaces the unsafe eval() with proper JSON parsing, eliminating the risk.
- CVE-2026-50741HIGH 8.8
CVE-2026-50741 is a critical security weakness in Revive Adserver that allows authenticated users to bypass a previous security patch (CVE-2026-34916). An attacker with valid login credentials can exploit this vulnerability in two ways: by submitting a specially crafted but technically valid plugin identifier, or by leveraging the XML-RPC API method `ox.setChannelTargeting`. Both approaches circumvent the intended restrictions and grant unauthorized access to sensitive functions. The vulnerability requires authentication but presents a severe risk because authenticated users—including lower-privileged accounts or compromised credentials—can achieve high-impact outcomes.
- CVE-2026-50884HIGH 8.8
A privilege escalation vulnerability exists in statping-ng version 0.93.0 where a logged-in user can gain unauthorized Administrator-level access due to improper access control checks. An attacker with basic user credentials can exploit this flaw to bypass intended permission restrictions and access sensitive application components that should be restricted to administrators only.
- CVE-2026-5136HIGH 8.8
Foreman, a popular infrastructure management platform, contains a privilege escalation flaw that allows authenticated users with basic user group management permissions to elevate themselves to administrator status. The vulnerability exists because the system fails to verify that a user has permission to assign the roles they're attempting to grant. An attacker with modest initial access can attach high-privilege roles to a user group, add themselves to that group, and gain full administrative control of the Foreman instance.
- CVE-2026-5228HIGH 8.8
WriteUp Mobile App versions 1.3.0 through 04062026 contain an access control flaw that allows authenticated users to perform actions they should not have permission to execute. An attacker with legitimate credentials can bypass the application's authorization checks to access or modify restricted functionality. This is a post-authentication vulnerability—the attacker must have a valid account, but once logged in, the broken permission system fails to prevent unauthorized operations.
- CVE-2026-5242HIGH 8.8
MIA Technology Inc.'s Pizzy Library contains a code injection vulnerability stemming from improper handling of formula elements in CSV files. An authenticated attacker can exploit this to execute arbitrary code within the application's context. The vulnerability affects versions 1.0.0.26250 through 1.3.8.26250, with version 1.3.9.26250 and later providing the fix.
- CVE-2026-52720HIGH 8.8
GStreamer's RFB (VNC client) library contains a heap buffer overflow flaw in how it validates incoming rectangle dimensions from a VNC server. Instead of checking each dimension separately, the code only verifies the total area, allowing an attacker-controlled server to send a rectangle that overflows the framebuffer memory. A user tricked into connecting to a malicious VNC server could experience a crash or, more seriously, arbitrary code execution on their system.
- CVE-2026-52751HIGH 8.8
Ghidra, the NSA's open-source reverse-engineering toolkit, contains a critical flaw in how it handles project files shared over its network protocol. When you open a malicious project file (identified by a ghidra:// link), the application deserializes untrusted data without proper validation. An attacker can exploit this to run arbitrary commands on your machine with the privileges of your Ghidra process. The vulnerability affects all versions before 12.1 and requires only that a user click to open a file—no special authentication or configuration is needed.
- CVE-2026-52754HIGH 8.8
Ghidra versions before 12.1 contain a critical authentication flaw that allows any legitimate user to impersonate other users. An attacker with a valid certificate can bypass the signature verification step and assume the identity of colleagues, administrators, or other users. This breaks the core security model of certificate-based authentication and enables privilege escalation, unauthorized data access, and control of shared reverse engineering databases.
- CVE-2026-52758HIGH 8.8
Ghidra, the NSA's reverse-engineering toolkit, contains a SQL injection flaw in its BSim (Binary Similarity) feature before version 12.1. An attacker with network access and valid credentials can craft malicious queries through BSim's network protocol to inject SQL commands directly into the underlying PostgreSQL database. This allows reading sensitive data, modifying existing records, or destroying data outright. The vulnerability requires authentication, but the impact if exploited is severe.
- CVE-2026-52784HIGH 8.8
OpenProject versions before 17.3.3 and 17.4.1 contain a Cross-Site Request Forgery (CSRF) vulnerability that allows an authenticated attacker to change a user's admin status without their knowledge or consent. The vulnerability exists in the user management endpoint and can be exploited through a malicious webpage or email that tricks an administrator into performing unintended actions. This is a serious privilege escalation risk in multi-user environments.
- CVE-2026-52800HIGH 8.8
Gogs, a self-hosted Git service, contains a cross-site request forgery (CSRF) vulnerability in organization team management that allows an attacker to add themselves as an owner of an organization without explicit user consent. An attacker can craft a malicious link that, when clicked by a logged-in organization owner, silently grants the attacker owner-level privileges. This attack requires no special access or technical skill from the attacker—only social engineering to trick a victim into clicking a link. The vulnerability affects all versions prior to 0.14.3.
- CVE-2026-52911HIGH 8.8
A flaw in the Linux kernel's ksmbd SMB server implementation allows an authenticated attacker to bypass session isolation controls. When a client initiates a session binding operation, a flag remains set on the connection, causing the session lookup mechanism to return sessions that should not be accessible to that connection. An attacker with valid credentials could leverage this to access or manipulate sessions they should not be authorized to reach, potentially gaining unauthorized access to shared resources or escalating privileges within the SMB session context.
- CVE-2026-52918HIGH 8.8
A synchronization bug in the Linux kernel's Bluetooth subsystem allows a race condition between socket polling and socket cleanup. When the kernel checks for incoming Bluetooth connections, it walks through a queue of pending connections without proper locking. Meanwhile, a child socket being destroyed can unlink itself from that same queue and release its reference count. If these operations happen simultaneously, the kernel can use freed memory, leading to potential system instability or worse. This is a long-standing flaw that traces back to the original Bluetooth implementation in the kernel.
- CVE-2026-52934HIGH 8.8
A memory corruption vulnerability exists in the Linux kernel's B.A.T.M.A.N. (Better Approach To Mobile Ad-hoc Networking) advanced routing protocol implementation. When the kernel builds network packets containing TVLV (Type–Length–Value) container data, it calculates the required buffer size using a 16-bit counter that can overflow. If enough TVLV containers are registered, the size calculation wraps around to a small number, causing the kernel to allocate insufficient memory. The code then writes the actual packet data beyond the buffer boundary, corrupting kernel memory. An attacker on the local network can trigger this by crafting packets or registering malicious TVLV containers, potentially gaining kernel-level privileges.
- CVE-2026-52952HIGH 8.8
A flaw in the Linux kernel's IOMMU (Input/Output Memory Management Unit) subsystem can cause a use-after-free condition when multiple devices in the same group undergo concurrent domain attachment operations during device recovery. The vulnerability arises from overly strict rejection of domain attachments while a device is resetting, which prevents necessary cleanup operations from completing and leaves dangling pointers to freed memory. A local attacker with sufficient privileges can exploit this to cause a kernel crash or potentially execute arbitrary code.
- CVE-2026-52968HIGH 8.8
A memory access error in the Linux kernel's KVM hypervisor implementation for IBM System z (s390) PCI device handling allows a local privileged user to read or modify kernel memory outside intended boundaries. The bug stems from incorrect pointer arithmetic that scales offsets twice when accessing internal device management tables, causing the kernel to read from or write to the wrong memory location when handling PCI device interrupts. This can crash the system or potentially allow privilege escalation on affected virtualization hosts.