2026 · High

High-severity vulnerabilities disclosed in 2026

High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 14 of 42

  • CVE-2026-28299HIGH 8.2

    SolarWinds Web Help Desk contains a denial-of-service vulnerability that allows attackers to crash the server by exhausting memory resources. No authentication or user interaction is required—an attacker on the network can trigger this condition remotely, making it straightforward to exploit. While the vulnerability does not expose sensitive data or allow unauthorized changes to the system, the ability to take down your help desk platform creates immediate business disruption.

  • CVE-2026-29009HIGH 8.2

    U-Boot, the widely-used bootloader for embedded systems, contains a buffer overflow vulnerability in its NFS (Network File System) implementation when NFS support is enabled. A malicious or compromised NFS server can trigger the vulnerability by sending specially crafted file symlink responses that exceed the bootloader's internal buffer capacity. This causes memory corruption that can affect critical NFS configuration variables, potentially allowing an attacker to disrupt or manipulate the boot process. The vulnerability requires network access to an NFS server that the target device trusts, making it relevant primarily in environments where U-Boot devices boot from untrusted or compromised network sources.

  • CVE-2026-29519HIGH 8.2

    Lucee CFML Server contains a flaw in how it processes URLs that allows attackers to inject malicious code into web pages viewed by users. By crafting a specially designed link and tricking someone into clicking it, an attacker can run JavaScript code in the victim's browser—potentially stealing login credentials or gaining unauthorized access to Lucee's admin panel. This affects multiple recent versions of Lucee and does not require the attacker to have any authentication.

  • CVE-2026-30802HIGH 8.2

    RTI Connext Micro, a real-time middleware platform used in distributed systems, contains a flaw that allows an attacker to read beyond the intended boundaries of a memory buffer. An unauthenticated attacker on the network can exploit this without user interaction to leak sensitive data from the application's memory or crash the service. The vulnerability affects Connext Micro versions from 4.0.0 up to (but not including) 4.3.0, and from 2.4.5 up to (but not including) 2.4.x where a patched version exists.

  • CVE-2026-35274HIGH 8.2

    A vulnerability in Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 allows attackers to gain unauthorized access to sensitive data over the network without needing valid credentials. The flaw affects the Deployment Package component and can be exploited by simply sending HTTP requests from the internet. Attackers can read confidential information and modify certain data within the system, though they cannot disrupt availability. This is a network-accessible authentication bypass with meaningful data exposure and integrity risks.

  • CVE-2026-35288HIGH 8.2

    Oracle PeopleSoft Enterprise PT PeopleTools contains a privilege escalation vulnerability in its Deployment Package component that allows a high-privileged local attacker to take complete control of the system. The flaw affects versions 8.61 and 8.62, and because PeopleTools is a critical deployment and configuration tool used across PeopleSoft environments, a successful compromise can cascade to impact other connected systems and data. The vulnerability requires the attacker to already have high-level access to the infrastructure where PeopleTools runs, which narrows the immediate threat surface but represents significant risk in environments where privileged access is less tightly controlled.

  • CVE-2026-35675HIGH 8.2

    phpMyFAQ versions before 4.1.3 contain a critical flaw in their password reset mechanism that completely bypasses authentication checks. An attacker does not need valid credentials or access to a victim's email to reset passwords—they can simply request a password reset for any user account, and the system grants it without verification. This means attackers can take over any account, including administrator accounts, giving them full control of the FAQ system and potentially the underlying server.

  • CVE-2026-35676HIGH 8.2

    phpMyFAQ versions before 4.1.3 contain a critical flaw that allows anyone on the internet to reset user account passwords without authentication. An attacker can enumerate valid usernames and email addresses, then forcibly change passwords by sending direct API requests. This bypasses normal security controls and immediately locks legitimate users out of their accounts.

  • CVE-2026-37234HIGH 8.2

    FlexRIC v2.0.0 contains a resource management flaw in how it handles SCTP (Stream Control Transmission Protocol) connections to the RIC (Radio Interface Controller). An attacker can abuse the E42 setup protocol to register multiple application IDs (xapp_ids) over a single connection. When that connection is closed, only the first registered application's resources are cleaned up; the others remain as orphaned entries in system memory. Over time or through repeated connections, this allows an attacker to accumulate stale subscriptions and exhaust available resources, potentially corrupting the internal state of the intelligent application platform (iApp).

  • CVE-2026-40994HIGH 8.2

    Spring Web Services contains a configuration flaw in its WS-Security interceptor that disables Basic Security Profile (BSP) compliance checks on incoming SOAP messages. This allows requests that violate WS-Security protocol rules to be accepted and processed, bypassing integrity and authenticity validations that should be enforced at the protocol layer. An unauthenticated attacker on the network can craft malformed WS-Security headers to bypass message validation controls.

  • CVE-2026-40998HIGH 8.2

    Spring Web Services contains a vulnerability in how it processes XML documents when evaluating XPath expressions. When an application uses the Jaxp13XPathTemplate component to search through untrusted XML data, the code bypasses Spring's security hardening and instead uses Java's default, permissive XML parser. This allows attackers to embed malicious XML directives (XXE attacks) within the data being searched, potentially exposing sensitive files or data that the application can access. The vulnerability affects multiple versions across Spring Web Services 3.1, 4.0, 4.1, and 5.0 product lines.

  • CVE-2026-41010HIGH 8.2

    BOSH Director is vulnerable to arbitrary command execution when processing uploaded release tarballs. An attacker with elevated privileges can craft a malicious release manifest that embeds shell metacharacters in a job name. When the system unpacks the tarball, these characters are interpreted by the shell, allowing the attacker to execute arbitrary commands with the privileges of the BOSH Director process. The vulnerability stems from unsafe string interpolation of untrusted input directly into a shell command.

  • CVE-2026-41011HIGH 8.2

    BOSH (the Cloud Foundry deployment automation framework) contains a shell injection vulnerability in its package validation logic. When a user uploads a release tarball containing a malicious package name, the system executes that name as a shell command without sanitization. An authenticated attacker with upload privileges can inject arbitrary commands that run with BOSH director privileges. The vulnerability exists because validation occurs after the dangerous shell operation, not before.

  • CVE-2026-41249HIGH 8.2

    CoreShop, a Pimcore-based eCommerce platform, contains a critical flaw in its GitHub Actions workflow configuration that allows attackers to execute arbitrary code on build infrastructure. The vulnerability stems from a workflow that accepts pull requests from untrusted sources but then executes scripts using code from those unverified pull requests. An attacker can simply submit a malicious pull request to trigger code execution on CoreShop's CI/CD runners, potentially compromising the build pipeline, stealing credentials, or injecting malicious code into releases.

  • CVE-2026-4256HIGH 8.2

    PassGate, a product from PEAKUP Technology Inc., contains an LDAP injection vulnerability that allows attackers to manipulate LDAP queries without authentication. An attacker can craft malicious input to bypass authentication, extract sensitive directory data, or modify LDAP operations. The vulnerability affects all versions through 30042026 and requires no user interaction—a remote attacker can exploit it directly over the network.

  • CVE-2026-42664HIGH 8.2

    A security flaw in Motive Commerce Search for WooCommerce (versions 1.38.2 and earlier) allows unauthenticated attackers to bypass access controls on the AI product search feature. This means someone without login credentials can perform actions they shouldn't be able to—specifically modifying data and disrupting service availability. The vulnerability requires no user interaction and can be exploited over the network, making it a significant risk for e-commerce sites relying on this plugin.

  • CVE-2026-43624HIGH 8.2

    F5-TTS versions up to 1.1.20 contain a path traversal vulnerability in their finetune Gradio interface that lets unauthenticated attackers write files anywhere on the server's filesystem. The flaw stems from inadequate validation of project names before they're used in file system operations. An attacker can bypass the intended directory boundary by supplying absolute paths (like /tmp/EVIL) and create malicious files with arbitrary content in locations the web server can access. No authentication is required to exploit this.

  • CVE-2026-44016HIGH 8.2

    Docling is a document processing library that handles multiple file formats and integrates with AI systems. Versions 2.82.0 through 2.90.x contain a flaw in the HTML rendering feature (an optional capability that must be explicitly enabled). When processing untrusted HTML documents, the Playwright-based renderer can execute arbitrary JavaScript code and make unrestricted network requests, potentially exposing internal services or exfiltrating sensitive data. The vulnerability requires user interaction—specifically, processing a malicious HTML file—but once triggered, can lead to complete compromise of the rendering environment. The fix is available in version 2.91.0.

  • CVE-2026-44358HIGH 8.2

    Espressif's Shared GitHub DangerJS Action, a reusable CI workflow component, contains a privilege escalation vulnerability in versions prior to 1.0.1. When processing pull requests from forks, the action's entrypoint script executes DangerJS from an untrusted search path after copying fork code into the working directory. This allows fork-supplied code to run inside the action container with the permissions of the workflow, rather than the action's own trusted code. An attacker can exploit this by submitting a malicious pull request from a fork, causing arbitrary code execution in the CI/CD environment.

  • CVE-2026-44705HIGH 8.2

    The tmp package for Node.js, used to create temporary files and directories, has a path traversal flaw in versions before 0.2.6. If an application passes user-supplied input to tmp's prefix, postfix, or dir options without validation, an attacker can use path traversal sequences like '../' to write files outside the intended temporary directory. This means an attacker can potentially place malicious files in arbitrary locations on the system where the Node.js process has write permissions, which could lead to code execution, configuration tampering, or denial of service depending on what gets written and where.

  • CVE-2026-44787HIGH 8.2

    A vulnerability in Discourse's user registration process allows newly created accounts to bypass group membership restrictions and gain unauthorized access to whisper groups—a feature used to restrict message visibility to group members. An attacker can exploit this during signup by manually setting a group ID parameter, gaining the same message-filtering privileges as legitimate group members without any approval or validation. This affects Discourse instances that have the whispers_allowed_groups feature configured.

  • CVE-2026-44822HIGH 8.2

    Microsoft Office Excel contains an out-of-bounds read vulnerability that allows a remote attacker to extract sensitive information from a user's system without authentication or user interaction. The flaw affects multiple Microsoft Office products across different versions and deployment models. An attacker could exploit this by crafting a malicious Excel file or triggering the vulnerability over a network, potentially exposing confidential data.

  • CVE-2026-44937HIGH 8.2

    SUSE Rancher Fleet versions 0.15.x, 0.14.x, 0.13.x, and 0.12.x contain a webhook authentication bypass that allows unauthenticated attackers to forge webhook requests. An attacker can exploit this to disrupt services (denial of service) or downgrade package repositories on the same system, potentially exposing infrastructure to older, vulnerable software versions. The vulnerability requires network access but no user interaction or privileges.

  • CVE-2026-45302HIGH 8.2

    parse-nested-form-data is a Node.js library that converts web form submissions into structured JavaScript objects and arrays. Versions before 1.0.1 contain a prototype pollution vulnerability: if an attacker submits a form field with a name like `__proto__` or containing `.__proto__.` anywhere in it, the parser inadvertently modifies JavaScript's Object.prototype. This pollutes the prototype chain for every plain object created in the application afterward, potentially corrupting application logic, exposing sensitive data, or enabling denial of service.

  • CVE-2026-45327HIGH 8.2

    TinyIce is vulnerable to unauthenticated stream injection on its WebRTC ingest endpoint. An attacker without credentials can inject audio or video streams into a live broadcast, potentially disrupting service, contaminating streams with malicious content, or hijacking active broadcasts. The vulnerability affects versions 0.8.95 through 2.4.1. Patching to version 2.5.0 or later adds mandatory authentication using HTTP Basic Auth or a password query parameter, backed by bcrypt verification and brute-force protection.

  • CVE-2026-45476HIGH 8.2

    A use-after-free flaw in the Linux MANA network driver used by Microsoft Azure allows a user with high-level system privileges to escape their confined context and gain full control over the system. Because the vulnerability requires the attacker to already have elevated privileges, the immediate attack surface is limited to administrative users or services running with high permissions—but successful exploitation would allow them to achieve complete system compromise.

  • CVE-2026-45545HIGH 8.2

    Nextcloud Tables contains a SQL injection vulnerability that allows authenticated users with Tables app access to execute SQL queries beyond the intended 20-byte limit. By crafting specially formed input, attackers can bypass this constraint and run arbitrary database commands to steal sensitive information or alter data. The vulnerability affects multiple Nextcloud versions and has been resolved in patched releases.

  • CVE-2026-45615HIGH 8.2

    CVE-2026-45615 is a memory safety flaw in asn1c, an open-source ASN.1 compiler used to generate code that parses structured data formats. The vulnerability exists in the OER (Octet Encoding Rules) decoder template files generated by asn1c version 1.4 and earlier. When the generated decoder encounters a specially crafted, zero-length OER payload representing a variable-length non-negative integer, it attempts to read the Most Significant Bit without first validating that the payload contains sufficient bytes. This causes a precise one-byte out-of-bounds heap read. Since asn1c-generated parsers are commonly deployed to process untrusted network data—including automotive V2X protocols, 5G telecommunications headers, and X.509 certificates—a remote attacker can trigger this flaw by sending a malicious network message, potentially causing the application to crash or misinterpret critical security-relevant integers.

  • CVE-2026-45627HIGH 8.2

    Arcane, a Docker container management interface, contains a reflected cross-site scripting (XSS) vulnerability in its unauthenticated logo endpoint. An attacker can craft a malicious URL containing injected CSS or JavaScript that gets reflected into an SVG document served to a logged-in admin user. When the admin visits this link, the injected script executes in the browser with full access to Arcane's origin, including HttpOnly session cookies, potentially leading to complete account compromise. The vulnerability exists because the endpoint does not properly escape user input and the application lacks protective HTTP headers. This issue is resolved in Arcane version 1.19.0.

  • CVE-2026-46303HIGH 8.2

    A vulnerability exists in the Linux kernel's ISO 9660 filesystem (isofs) Rock Ridge extension handler. When processing a specially crafted ISO image, the kernel fails to validate that continuation extent block numbers fall within the mounted volume's boundaries. An attacker with the ability to mount a malicious ISO—either through unprivileged auto-mounting via udisks2 on a desktop, or through privileged mount access—can cause the kernel to read data from arbitrary blocks on the same device. While memory safety is preserved because out-of-range reads cleanly fail, reads into adjacent filesystems can leak directory metadata through symbolic link text exposed to userspace. This is a validation gap in an existing security check that should have been closed alongside prior CE (continuation extent) fixes.

  • CVE-2026-46509HIGH 8.2

    The deepobj library contains a prototype pollution vulnerability that allows attackers to manipulate JavaScript object prototypes through specially crafted property paths. When an application uses deepobj to get, set, or delete nested object properties—and exposes the property path to attacker input—an attacker can inject payloads using __proto__, constructor, or prototype keywords to corrupt the prototype chain. This can lead to unexpected behavior, denial of service, or in certain contexts, code execution. The vulnerability was resolved in version 1.0.3.

  • CVE-2026-46510HIGH 8.2

    form-data-objectizer is a Node.js library that converts HTML form data into JavaScript objects. Versions prior to 1.0.1 contain a prototype pollution vulnerability. An attacker can craft an HTTP form submission with a specially-named field (beginning with __proto__) that causes the library to overwrite Object.prototype—the base template all JavaScript objects inherit from. This single malicious form field corrupts the entire Node.js process, allowing an attacker to inject arbitrary properties into all objects, potentially leading to authentication bypass, data manipulation, or application crashes.

  • CVE-2026-46591HIGH 8.2

    Apache Camel's Neo4j integration contains a query injection flaw that lets attackers manipulate database queries by crafting malicious property names in match operations. Although previous patches blocked injection through property values, the property names themselves are still inserted directly into Cypher queries without escaping. If your application routes untrusted data—such as JSON request bodies or headers—into the Neo4j producer's match configuration, an attacker can inject arbitrary Cypher syntax to read, modify, or delete any data in your Neo4j database. The vulnerability exists in Camel versions from 4.10.0 through 4.20.x, with patches available in 4.14.8 (LTS), 4.18.3, and 4.21.0+.

  • CVE-2026-46806HIGH 8.2

    A flaw in Oracle WebCenter Content version 14.1.2.0.0 allows unauthenticated attackers to gain unauthorized access to sensitive data or modify content through the network. The vulnerability exploits trust in HTTPS connections and relies on tricking a user into clicking a malicious link or visiting a crafted page. While the vulnerability exists in WebCenter Content, successful exploitation can affect other connected Oracle systems. The attacker does not need valid credentials, but the attack requires user interaction—typically clicking a link sent via email or social engineering.

  • CVE-2026-46865HIGH 8.2

    Oracle Enterprise Manager Base Platform contains a privilege escalation vulnerability in its Extensibility Framework that allows a high-privileged local user to gain complete control over the platform. The flaw affects versions 13.5 and 24.1, and successful exploitation can lead to full system compromise. Because Enterprise Manager often serves as a central management hub, an attack could cascade to compromise other managed infrastructure and systems.

  • CVE-2026-46866HIGH 8.2

    A remotely exploitable vulnerability exists in Oracle Enterprise Manager Base Platform versions 13.5 and 24.1 that allows attackers without credentials to cause service outages or corrupt data. An attacker with network access can send specially crafted HTTPS requests to trigger either a denial-of-service condition or unauthorized modifications to Enterprise Manager data. No user interaction is required, and the attack can be repeated reliably. This is a high-severity issue that directly impacts service availability and data integrity.

  • CVE-2026-47652HIGH 8.2

    A memory defect in Windows Hyper-V can allow someone with high-level system access to run malicious code on an affected machine. The flaw resides in how the hypervisor manages heap memory, leaving a window for buffer overflow attacks that bypass normal protections. This is a serious but constrained threat: exploitation requires administrative or hypervisor-level credentials, meaning it's not a remote vulnerability and the attacker must already have substantial control of the system.

  • CVE-2026-48109HIGH 8.2

    MessagePack for C# contains a flaw in its optional LZ4 decompression feature that allows attackers to craft specially designed messages triggering buffer over-reads. When a vulnerable application receives and decompresses one of these malicious payloads, it can crash with an AccessViolationException, knocking the service offline. In some cases, the over-read may leak small amounts of adjacent memory before the crash occurs. Applications using MessagePack's Lz4Block or Lz4BlockArray compression modes are at risk if they process untrusted or network-sourced MessagePack data.

  • CVE-2026-48764HIGH 8.2

    TypeBot versions before 3.17.2 contain a DNS rebinding vulnerability in their server-side request validation. When a user configures a bot to fetch HTTP content or execute server-side scripts, TypeBot checks whether the target URL points to a forbidden internal address. However, the check happens once at validation time, while the actual connection occurs later using a fresh DNS lookup. An attacker can exploit this timing gap by pointing a bot to a malicious domain that first resolves to an approved IP during validation, then resolves to an internal service (like cloud metadata endpoints or private admin panels) when the bot makes the real request. This allows bypassing the security guard and accessing sensitive internal systems.

  • CVE-2026-48780HIGH 8.2

    Forem, an open-source community platform, contains a flaw in how it validates email addresses when enforcing domain-level access controls. An attacker can craft a specially formatted email address that bypasses the allowlist or denylist rules protecting invite-only deployments, potentially gaining unauthorized access to restricted communities. The vulnerability has been fixed in the codebase as of commit a2ab6d4.

  • CVE-2026-48788HIGH 8.2

    Remark42, a self-hosted comment engine, contains a Cross-Site Scripting (XSS) vulnerability in versions 1.6.0 through 1.15.0 that allows attackers to inject malicious JavaScript into victims' browsers. The vulnerability stems from inconsistent validation in Remark42's image proxy feature. When an attacker hosts a URL that claims to be an image (via Content-Type header) but actually contains HTML or JavaScript, the proxy accepts and re-serves it from Remark42's own origin, tricking browsers into executing the malicious code. Critically, no Remark42 account is required to exploit this—an attacker simply needs to trick a user into clicking a link pointing to their malicious content.

  • CVE-2026-49065HIGH 8.2

    A critical security flaw has been identified in the Hippoo Mobile App for WooCommerce through version 1.9.5 that allows attackers to bypass authentication entirely and access sensitive information without credentials. An attacker can make requests directly to the app's backend without providing any login credentials, exposing customer data and potentially modifying content. This vulnerability requires no user interaction and can be exploited over the network from anywhere, making it a serious risk for any e-commerce operation using this app.

  • CVE-2026-49260HIGH 8.2

    PhpWeasyPrint is a widely-used PHP library that generates PDF files from web pages or HTML content. A critical flaw in versions before 2.5.1 allows attackers with elevated privileges on a server to inject arbitrary shell commands by manipulating the WeasyPrint binary path. The vulnerability exists because the code incorrectly validates the binary path—it quotes the path, then checks if the quoted version exists as a file (which it never will), bypassing the safety check entirely. This means the unvalidated path flows directly into system command execution, giving an attacker a direct pathway to run malicious commands. The issue stems from a design flaw the library inherited from a similar codebase that was previously patched elsewhere.

  • CVE-2026-49491HIGH 8.2

    Pixa Bank 2.0 contains an SQL injection flaw that lets attackers without credentials steal sensitive customer data directly from the database. By crafting malicious requests to a specific endpoint, attackers can extract names, email addresses, and phone numbers. The vulnerability requires no authentication, no user interaction, and can be exploited over the network, making it a serious exposure for any organization running this software.

  • CVE-2026-49759HIGH 8.2

    A stack-based buffer overflow exists in Erlang OTP's SCTP handling code that allows an unauthenticated attacker to crash the BEAM virtual machine. The vulnerability lives in how the inet_drv component processes SCTP ERROR chunks—specifically, it writes data into a fixed-size array without validating how many cause codes are being written. An attacker who can reach an open SCTP port can send a specially crafted ERROR chunk that overflows this buffer, terminating the entire Erlang VM process. While the nature of the overflow limits the attacker to causing a denial of service (they cannot reliably execute code), the impact to availability is severe. There is also a minor risk of memory disclosure, though any leaked data would already be accessible to users running the VM.

  • CVE-2026-49982HIGH 8.2

    The tmp Node.js library, versions up to 0.2.6, contains a path traversal vulnerability that allows attackers to create files or directories outside the intended temporary directory. The vulnerability exists because the library's path validation only checks string inputs for the '..' substring, but fails to properly validate non-string inputs like Arrays, Buffers, and objects. When these objects are converted to strings during file creation, they can contain path traversal sequences that bypass the check. An attacker can exploit this by sending malicious data through application parameters (such as JSON fields or query strings) that get passed to tmp functions, potentially creating files or directories anywhere on the system with the privileges of the running process.

  • CVE-2026-50087HIGH 8.2

    Aqara's IAM/SSO gateway (gw-builder.aqara.com) allows a web attacker to make unauthorized requests on behalf of an authenticated user visiting a malicious site. The gateway's cross-origin policy is too permissive, enabling an attacker to steal sensitive user data or make unwanted changes to account settings without the user's knowledge. An attacker cannot directly access the system—they rely on tricking a user into clicking a link or visiting a crafted webpage while logged into the Aqara gateway.

  • CVE-2026-50088HIGH 8.2

    The Aqara Developer Portal and its associated test environments allow web pages from untrusted domains to make authenticated requests on behalf of users. This cross-origin vulnerability means an attacker could craft a malicious webpage that, when visited by a developer logged into Aqara's portal, silently retrieves sensitive information or makes unwanted changes. The vulnerability requires user interaction (visiting a malicious site) but can expose confidential data and modify account settings.

  • CVE-2026-50168HIGH 8.2

    Angular Server-Side Rendering (SSR) applications running on Node.js are vulnerable to Server-Side Request Forgery (SSRF) attacks when they enforce host allowlists to restrict backend requests. An attacker can craft a malformed URL with a double port (e.g., http://evil.com:80:80/path) that bypasses the allowlist validation but is still accepted by the underlying DOM parser, allowing the attacker to redirect server-side requests to arbitrary external endpoints. This affects versions prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

  • CVE-2026-50194HIGH 8.2

    Steeltoe, an open-source framework for building cloud-native .NET applications, contains a critical flaw in how it validates access to administrative management endpoints when those endpoints are configured to listen on a separate port. Instead of checking the actual network port a request arrives on, the vulnerable versions check only the Host HTTP header—which an attacker can freely manipulate. This means an attacker on the network can bypass port-based access controls and reach sensitive administrative functions that should be restricted. The vulnerability affects Steeltoe versions 3.2.2 through 3.3.0 and version 4.1.0.

  • CVE-2026-50205HIGH 8.2

    Acer Connect M6E 5G routers log SMTP authentication passwords and employee identification data in plaintext system logs. Any user or attacker with access to the device's log files can read these credentials and sensitive corporate information without any decryption step. This is a straightforward credential exposure issue that poses immediate risk to email security and employee privacy.

  • CVE-2026-50637HIGH 8.2

    Metrics::Any::Adapter::Statsd, a Perl library for sending metrics to StatsD servers, fails to sanitize metric names and values before transmission. An attacker can inject additional metrics into a single StatsD packet by embedding newlines and special control characters (colons, pipes) in metric data. This allows manipulation of monitoring data without authentication, potentially causing false alerts, hiding real issues, or poisoning observability systems that other services depend on. The vulnerability affects all versions before 0.04, which introduced input validation to block problematic characters.

  • CVE-2026-52783HIGH 8.2

    OpenProject's file storage connector for OneDrive and SharePoint has a critical weakness: it stores authentication tokens in plain text where attackers can read them. When OpenProject syncs with Microsoft cloud storage, it obtains special access tokens that prove the application's identity to Microsoft. Instead of protecting these tokens with encryption, OpenProject saves them unencrypted in its cache layer—a temporary data store that can be accessed by anyone who gains network or system access to the server running OpenProject. An attacker with legitimate access to the cache backend (or who can reach it over the network) can retrieve these tokens and impersonate OpenProject to Microsoft's systems, potentially gaining unauthorized access to sensitive files stored in OneDrive or SharePoint across your organization.

  • CVE-2026-52859HIGH 8.2

    Vim, a widely-used command-line text editor, contains a buffer overflow vulnerability in how it handles terminal output. When Vim displays terminal content with certain Unicode combining characters (accents, diacritics, etc.), a flaw in the snapshot function fails to safely copy the data, potentially reading past allocated memory. An attacker can craft terminal output that triggers this with just a few bytes, causing Vim to crash without requiring any user interaction or scripting. The vulnerability affects Vim versions prior to 9.2.0565.

  • CVE-2026-52868HIGH 8.2

    An unauthenticated attacker can bypass access controls to read worklist records that should remain isolated to specific departments or clinical areas. In healthcare deployments with multiple separate organizational units (AEs), an attacker could potentially cross data boundaries and access sensitive patient information belonging to other departments. No authentication is required, and exploitation is straightforward over the network.

  • CVE-2026-53268HIGH 8.2

    A flaw in the Linux kernel's netfilter IRC connection tracking module can cause the system to read memory beyond intended boundaries. When the module attempts to parse IRC protocol data and encounters a parsing failure after matching a command string, it fails to exit cleanly and instead tries to match additional commands, leading to out-of-bounds memory access. This can result in information disclosure or system crashes on affected Linux systems running the vulnerable netfilter code.

  • CVE-2026-53657HIGH 8.2

    Lima is a tool that lets macOS users run Linux virtual machines for container workloads. Prior to version 2.1.3, when Lima is configured with the qemu driver and the guest agent is enabled, a local user inside the VM could gain root-level access by exploiting an unsecured socket file. This socket—located at /run/lima-guestagent.sock—allows arbitrary command execution because it provides access to privileged system services like D-Bus that typically require elevated permissions.

  • CVE-2026-53721HIGH 8.2

    Nuxt, a popular Vue.js web framework, contains a middleware bypass vulnerability caused by inconsistent case-sensitivity handling between its router and route-rule matcher. An attacker can craft requests with different letter casing to bypass security middleware that should be protecting sensitive routes, potentially exposing functionality that was intended to be restricted. This affects Nuxt versions 3.11.0 through 3.21.6 and 4.0.0 through 4.4.6. Patches are available in versions 3.21.7 and 4.4.7.

  • CVE-2026-53906HIGH 8.2

    MCO (MyComplianceOffice) contains a vulnerability in its file handling system that allows attackers to write files to unintended locations on the server and discover sensitive path information through error messages. The flaw stems from inadequate validation of filenames during data export and upload operations. An attacker with network access can exploit this without authentication to alter file placement or gather reconnaissance data about the server's directory structure.

  • CVE-2026-54184HIGH 8.2

    Clean Login versions 1.15 and earlier contain an Insecure Direct Object Reference (IDOR) vulnerability that allows attackers to bypass authentication and access or modify user data without permission. An attacker can directly reference internal objects—such as user accounts or sensitive records—by manipulating request parameters, potentially affecting availability and integrity of stored information. No authentication is required to exploit this flaw.

  • CVE-2026-54271HIGH 8.2

    protobufjs-cli, a command-line tool for generating JavaScript code from Protocol Buffer schemas, contains a code injection vulnerability that allows attackers to embed malicious code into generated JavaScript files. The flaw is a bypass of an earlier partial fix (CVE-2026-44295) that failed to fully sanitize unsafe names when processing JSON-formatted schema descriptors. If an attacker can supply or modify the JSON input fed to the pbjs static code generator, they can inject code that executes when the generated file is imported or used. The vulnerability does not affect the common workflow of parsing .proto files directly. Versions prior to 1.3.2 and 2.5.0 are vulnerable.

  • CVE-2026-54351HIGH 8.2

    Budibase versions before 3.39.9 contain a vulnerability in their webhook trigger system that allows an authenticated attacker to hijack automations. By crafting a malicious webhook POST request with a specially modified body, an attacker can trick the system into executing an automation under a different application context than intended. This grants the attacker unauthorized access to read and modify data in the victim's workspace database. The flaw stems from the webhook endpoint accepting and passing unvalidated user input directly into automation parameters without proper access controls.

  • CVE-2026-54412HIGH 8.2

    A critical flaw in LiamBindle MQTT-C library versions through 1.1.6 allows remote attackers to crash MQTT clients and potentially leak sensitive memory. An attacker controlling or able to intercept traffic from an MQTT broker can send a specially crafted message that causes the client application to crash or expose data from adjacent memory regions. The vulnerability requires no authentication and can be triggered with a single malicious packet.

  • CVE-2026-54413HIGH 8.2

    A critical flaw in the driftregion iso14229 UDS (Unified Diagnostic Services) library versions through 0.9.0 allows an attacker to crash a diagnostic server and potentially read sensitive memory by sending a specially crafted single-byte request over automotive or industrial networks. The vulnerability exploits a missing validation check in the security access handler, causing the library to attempt reading far more data than is actually present in the input buffer. This affects vehicles, industrial controllers, and IoT devices that rely on this UDS implementation for diagnostic communication.

  • CVE-2026-54423HIGH 8.2

    OpenStack Ironic versions before 37.0.1 contain a privilege escalation flaw in the IPMI management interface. Users with deployment permissions can execute arbitrary IPMI commands directly on managed nodes, circumventing Ironic's built-in access controls. This allows a malicious operator to take unauthorized actions on bare-metal infrastructure without triggering normal authorization checks.

  • CVE-2026-55188HIGH 8.2

    RustFS, a Rust-based distributed object storage system, has an authorization bypass flaw affecting versions 1.0.0-alpha.1 through 1.0.0-beta.8. An authenticated user—even one with minimal or no permissions—can query the bucket replication API to retrieve remote replication target configurations, including stored access credentials. This credential disclosure poses a direct risk to organizations relying on RustFS for sensitive data, as attackers gaining foothold access could pivot to compromise downstream replication infrastructure. The fix is available in version 1.0.0-beta.9 and later.

  • CVE-2026-55202HIGH 8.2

    Tinyproxy, a lightweight HTTP proxy software, contains a flaw in how it validates incoming requests to identify its built-in statistics page. An attacker on the network can craft a request with a specially crafted Host header to bypass security checks and access the proxy's internal statistics page without authentication. The attacker can also manipulate port information to trick the proxy into mishandling transparent proxy connections, potentially allowing requests to be routed incorrectly and bypassing access controls. This affects Tinyproxy versions up to and including 1.11.3.

  • CVE-2026-55428HIGH 8.2

    Coder, a platform for provisioning remote development environments via Terraform, contains a validation gap that allows authenticated agents to inject arbitrary IP ranges into the WireGuard tunnel configuration of other agents. An attacker with valid credentials can manipulate the `AllowedIPs` field to route network traffic through their controlled agent, potentially intercepting or redirecting communications intended for legitimate development environments. This is a cross-tenant risk in multi-user deployments where agents from different organizations or teams share a tailnet coordinator.

  • CVE-2026-55641HIGH 8.2

    9Router, an AI router designed to optimize and reduce costs for large language model requests, contains a critical authentication bypass vulnerability in versions before 0.5.2. The vulnerability stems from the application trusting the HTTP Host header—a value supplied by the client—to determine whether a request originates locally. An attacker can spoof this header by claiming to be localhost, bypassing API key authentication entirely. Once authenticated bypass is achieved, attackers gain access to the LLM proxy and can make requests using the router's stored provider credentials, potentially consuming API quota or accessing sensitive upstream services. Additionally, the searxng search provider feature can be exploited to make the server perform requests to internal infrastructure or cloud metadata endpoints, enabling information disclosure or further lateral movement.

  • CVE-2026-55667HIGH 8.2

    File Browser, a multi-tenant file management system, contains a critical authorization bypass vulnerability in versions prior to 2.63.16. An authenticated user with only basic file creation permissions can delete arbitrary files outside their assigned scope—including other tenants' data and the application's own database—by exploiting a symlink following flaw in the failed-upload cleanup routine. The vulnerability exists because the RemoveAll operation skips symlink validation that other file operations enforce, allowing a low-privilege user to chain directory escape and deletion in a single attack.

  • CVE-2026-56104HIGH 8.2

    Chainlit versions before 2.10.1 have a session hijacking flaw that lets attackers with basic user access hijack authenticated sessions without the victim's knowledge. An attacker can steal a valid session ID and use it to impersonate a victim during WebSocket reconnection, gaining access to their data and the ability to run restricted tools. This requires the attacker to have some level of access to the system initially, but no additional authentication is needed once they have a session ID.

  • CVE-2026-56245HIGH 8.2

    Supabase Capgo versions before 12.128.2 contain a flaw that lets anyone call a specific API function without proving who they are. An attacker can use this to create fake billing records for any organization, which could lead to inflated costs, resource quotas being consumed, or one tenant's usage being charged to another. The vulnerability requires no special privileges or user interaction—just a network connection and knowledge of the function name.

  • CVE-2026-56324HIGH 8.2

    Capgo versions prior to 12.128.2 contain a vulnerability that bypasses rate limits on the channel_self endpoint. An attacker can exploit this by repeatedly changing a device identifier (device_id) to send numerous requests in quick succession—effectively circumventing the API's built-in protections against abuse. This allows them to flood the database with entries and exhaust resources, potentially degrading or disrupting service availability.

  • CVE-2026-56351HIGH 8.2

    n8n, a workflow automation platform, has a SQL injection vulnerability affecting its database query nodes (MySQL, PostgreSQL, and SQL Server). An authenticated user with permission to create workflows can craft malicious table or column names within node configuration to execute arbitrary SQL commands against connected databases. This bypasses normal database access controls and allows an attacker to read, modify, or delete data. The vulnerability requires an authenticated account and specific node configuration privileges, but poses a significant risk to organizations relying on n8n for sensitive data operations.

  • CVE-2026-56785HIGH 8.2

    FlatPress, a lightweight blogging platform, contains a stored cross-site scripting (XSS) vulnerability in its comment and contact forms. Attackers can inject malicious scripts through name, email, or URL fields that are then displayed to other users—including administrators—without being properly sanitized. When visitors view these forms or comments, the injected scripts execute in their browsers, potentially allowing attackers to steal session tokens, redirect users to phishing sites, or perform actions on behalf of administrators.

  • CVE-2026-57235HIGH 8.2

    Nokogiri, a widely-used Ruby library for parsing XML and HTML, contains an out-of-bounds read vulnerability in its NodeSet indexing method. When code calls the [] or slice method with a large negative index, the library's bounds check fails due to 32-bit truncation, allowing the operation to access memory outside the intended data structure. On standard Ruby (CRuby), this typically crashes the application; on JRuby, it silently returns incorrect data. The flaw affects all versions prior to 1.19.4.

  • CVE-2026-57236HIGH 8.2

    Nokogiri, a widely-used Ruby library for parsing XML and HTML, contains a use-after-free vulnerability in its document encoding handler. When you attempt to set an invalid encoding on a document—such as passing a non-string value or a string with null bytes—the library frees the old encoding string but fails to properly initialize a replacement. Subsequent reads of the document's encoding then access already-freed memory, potentially causing the Ruby process to crash or leaking sensitive data from freed memory regions into application strings. The issue affects only the CRuby implementation using libxml2; JRuby users are unaffected. Nokogiri 1.19.4 and later resolve this defect.

  • CVE-2026-57239HIGH 8.2

    A vulnerability in Foxit PDF Editor, Foxit PDF Reader, and Microsoft Windows allows low-privilege users to execute arbitrary code with system-level privileges. The flaw stems from these applications executing user-controlled files without proper validation, enabling attackers to escalate their privileges to NT AUTHORITY\SYSTEM. An attacker needs local access and user interaction to trigger the vulnerability, but once exploited, gains complete control over the affected system.

  • CVE-2026-57655HIGH 8.2

    Child Theme Wizard, a WordPress plugin used by developers to create custom child themes, contains an unauthenticated cross-site request forgery vulnerability affecting versions 1.4 and earlier. An attacker can trick an authenticated WordPress admin into performing unintended actions—such as modifying plugin settings, creating malicious child themes, or altering site configuration—without the admin's knowledge or consent. The attack requires no special technical skill beyond crafting a malicious link or webpage and tricking an admin into visiting it while logged into WordPress.

  • CVE-2026-58525HIGH 8.2

    Microsoft Edge (Chromium-based) contains a flaw that allows attackers to bypass a security feature through network-based attack vectors. An attacker can exploit this weakness to gain unauthorized access to protected functionality, potentially compromising user confidentiality. The vulnerability requires user interaction to trigger, but once activated, impacts extend beyond the individual browser instance.

  • CVE-2026-59195HIGH 8.2

    pnpm, a widely-used Node.js package manager, contains a path traversal vulnerability in how it processes lockfile configuration dependencies. When a developer runs pnpm install on a project with a malicious pnpm-lock.yaml file, an attacker can craft dependency names that bypass directory restrictions and create symlinks outside the intended node_modules/.pnpm-config location. This allows an attacker to write files to arbitrary locations on the developer's system, potentially overwriting critical files or injecting malicious code into the project. The vulnerability requires user interaction (running pnpm install), but affects development environments across multiple operating systems.

  • CVE-2026-59731HIGH 8.2

    Astro 6.4.7 has a path traversal vulnerability in how it authorizes access to protected routes. The issue arises because Astro stops decoding URL paths after reaching a certain limit during authorization checks, but then performs additional decoding during route matching. An attacker can craft a specially encoded URL that bypasses authorization controls and accesses restricted content. This is fixed in Astro 6.4.8.

  • CVE-2026-59802HIGH 8.2

    PasswordPusher versions before 2.8.1 contain a validation flaw that allows attackers to embed malicious JavaScript code disguised as data URIs within password-sharing links. When a victim clicks one of these malicious links, the JavaScript executes in their browser under PasswordPusher's trusted domain, enabling credential theft and phishing attacks. The vulnerability is straightforward to exploit and requires only that a user click a specially crafted link—no complex setup or special conditions are needed.

  • CVE-2026-59822HIGH 8.2

    LiteLLM, an AI Gateway proxy for unified LLM API access, contained an authentication bypass in its MCP Streamable HTTP endpoint. Attackers could craft a fake Authorization header to trigger a fallback mechanism that replaced proper API key validation with an empty authentication object, allowing unauthorized access to MCP tooling. This issue affects versions prior to 1.84.0 and has been patched.

  • CVE-2026-8377HIGH 8.2

    Armiya Information Technologies' Access Control System (GKS) contains a missing authorization flaw that allows unauthenticated attackers to extract sensitive data from shared resource locations. An attacker can remotely exploit this vulnerability without any special privileges or user interaction, gaining unauthorized access to confidential information stored in common system areas. The vulnerability affects GKS versions prior to Version 2.

  • CVE-2023-45796HIGH 8.1

    A stored cross-site scripting (XSS) flaw exists in Pilz PASvisu and PMI industrial control software that allows a low-privileged attacker without authentication to inject malicious code into the system. Once stored, this code executes when other users access affected data, enabling manipulation of process data and disruption of operations. The vulnerability requires low complexity to exploit and carries significant operational risk in manufacturing and automation environments.

  • CVE-2025-36359HIGH 8.1

    IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 contain a session management flaw that fails to invalidate user session IDs once they expire. This allows an authenticated attacker who gains access to an expired session token to impersonate another user without needing their credentials. The vulnerability requires initial authentication access but poses a serious lateral movement and privilege escalation risk within DevOps environments where automation tools often have broad system permissions.

  • CVE-2025-45422HIGH 8.1

    A Proximus b-box v8c.725A router contains a flaw that allows authenticated users to modify port forwarding rules beyond their intended scope. An attacker with valid credentials—such as a compromised admin account or an insider—can reconfigure port forwarding to redirect network traffic, enabling unauthorized access to services or lateral movement within a network. This is not a remotely-exploitable flaw from the internet; you must already have user-level access to the device.

  • CVE-2025-53440HIGH 8.1

    CVE-2025-53440 is a PHP Local File Inclusion (LFI) vulnerability in Axiomthemes Confidant that allows an attacker to manipulate file path inputs, potentially leading to the inclusion and execution of arbitrary files on the affected server. The vulnerability stems from improper validation of filenames used in PHP include/require statements. An attacker can exploit this over the network without authentication to read sensitive files or execute malicious code, posing a significant risk to websites using vulnerable versions of Confidant.

  • CVE-2025-58705HIGH 8.1

    CVE-2025-58705 is a PHP Local File Inclusion (LFI) vulnerability in Axiomthemes Crafti through version 1.12. An attacker can exploit improper filename validation in PHP include/require statements to include and execute arbitrary local files on the server. This allows remote code execution without authentication, making it a critical risk for any organization running vulnerable Crafti installations. The vulnerability has a CVSS 3.1 score of 8.1 (HIGH severity) with network accessibility and high impact across confidentiality, integrity, and availability.

  • CVE-2025-58707HIGH 8.1

    CVE-2025-58707 is a file inclusion vulnerability in Axiomthemes Spin that allows attackers to include and execute arbitrary local files on the server. By manipulating input parameters, an unauthenticated attacker can reference files outside the intended directory, potentially exposing sensitive data or executing malicious code. The vulnerability affects Spin versions up through 1.8 and carries a CVSS score of 8.1, reflecting its severity.

  • CVE-2025-58897HIGH 8.1

    Axiomthemes Fermentio contains a vulnerability that allows attackers to include and execute arbitrary PHP files from the local server, potentially leading to unauthorized access, data theft, or system compromise. The vulnerability stems from insufficient validation of filenames used in PHP include/require statements, enabling attackers to manipulate file paths without authentication. Versions up to and including 1.5.0 are affected.

  • CVE-2025-59874HIGH 8.1

    HCL Hive Telco Observability contains a Content Security Policy (CSP) configuration weakness in its Keycloak authentication component. The application is missing critical CSP directives that browsers rely on to prevent injection attacks. This gap creates conditions for attackers to inject malicious scripts or styles if they can trick users into visiting a compromised or attacker-controlled page, potentially compromising session tokens or stealing sensitive observability data.

  • CVE-2025-66336HIGH 8.1

    Apache Doris MCP Server has a SQL injection vulnerability in how it handles metadata queries. When a user provides a database name, that name gets directly inserted into a SQL query without proper safeguards. An attacker with valid credentials—or without any credentials if authentication is turned off—can exploit this to run unauthorized SQL commands and access data from databases they shouldn't be able to reach. The vendor recommends upgrading to version 0.6.1 or later to fix the problem.

  • CVE-2025-68886HIGH 8.1

    A vulnerability in androThemes Cookiteer plugin allows an attacker to include and execute arbitrary local files through improper input handling in PHP include/require statements. While the vulnerability is classified as a Local File Inclusion (LFI) rather than true Remote File Inclusion, the network-accessible nature of web plugins means an unauthenticated attacker can exploit this remotely to read sensitive files or potentially execute code, depending on file availability and server configuration. All versions through 1.4.8 are affected.

  • CVE-2025-69115HIGH 8.1

    A critical weakness exists in the LuxMed WordPress theme (versions 1.2.2 and earlier) that allows attackers to retrieve sensitive files from affected websites without needing to authenticate. An attacker can craft a specially formed web request to access files like configuration databases, private documents, or other sensitive data stored on the server. This type of attack doesn't require special credentials or user interaction, making it a practical threat for any organization running this theme.

  • CVE-2025-69369HIGH 8.1

    CVE-2025-69369 is a file inclusion vulnerability in Axiomthemes Racquet versions up to 1.12.0 that allows an attacker to manipulate how the application loads files, potentially executing arbitrary code or accessing sensitive data on the server. The flaw stems from insufficient validation of file paths in PHP include/require statements, making it possible to load unintended files from the local filesystem or, in some configurations, from remote sources.

  • CVE-2025-71335HIGH 8.1

    Flowise, a workflow automation platform, contains a critical session management flaw affecting versions 3.0.7 and earlier. When a user changes their password, the application fails to terminate existing login sessions or invalidate previously issued session tokens. This means an attacker with an active session—whether obtained through a stolen token or an unattended logged-in device—retains full access to that user's account even after the legitimate user has rotated their credentials. The attacker can continue operating as the authenticated user without any disruption, completely defeating the protective intent of a password change.

  • CVE-2025-71339HIGH 8.1

    Picklescan is a Python security tool designed to scan pickle files for malicious content before they're loaded. A flaw in versions before 0.0.33 allows attackers to bypass this protection by using a specific Python gadget chain involving numpy's f2py module. An attacker can craft a malicious pickle file that appears safe to Picklescan but executes arbitrary code when the file is actually loaded, defeating the tool's core purpose of preventing pickle-based code execution attacks.

  • CVE-2025-71340HIGH 8.1

    Picklescan is a security tool designed to detect malicious code embedded in pickle files—Python's serialization format commonly used for saving machine learning models and other objects. Versions 0.0.26 and earlier have a detection gap: they fail to catch a specific evasion technique where attackers hide arbitrary code execution within the `__reduce__` method by invoking `idlelib.pyshell.ModifiedInterpreter.runcode`. When a compromised pickle file is loaded into memory, this hidden code executes silently, giving attackers a pathway to inject malicious logic into supply chains that distribute pre-trained PyTorch models or other Python-based artifacts. The vulnerability is patched in version 0.0.30.