2026 · High

High-severity vulnerabilities disclosed in 2026

High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 40 of 42

  • CVE-2026-39437HIGH 7.1

    A reflected cross-site scripting (XSS) vulnerability exists in the Min Max Step Quantity Limits Manager plugin for WooCommerce versions 5.2.2 and earlier. An attacker can craft a malicious link containing JavaScript code that, when clicked by a user, executes arbitrary scripts in the victim's browser within the context of the WooCommerce store. No authentication is required to exploit this vulnerability, making it accessible to any external attacker. The attack relies on user interaction—the victim must click a specially crafted link—but once successful, the malicious script runs with the permissions of the logged-in user, potentially allowing account compromise, session hijacking, or data theft.

  • CVE-2026-39447HIGH 7.1

    A cross-site scripting (XSS) vulnerability exists in Simply Schedule Appointments plugin versions 1.6.10.6 and earlier. An attacker can inject malicious scripts into the plugin without needing to authenticate, allowing them to compromise user browsers when those users interact with affected pages. The vulnerability requires user interaction (such as clicking a link) to trigger, but once activated, it can steal session data, redirect users, deface content, or perform actions on behalf of the victim.

  • CVE-2026-39449HIGH 7.1

    The Contact Form to Any API WordPress plugin contains an unauthenticated cross-site scripting (XSS) vulnerability affecting versions 3.0.3 and earlier. An attacker can inject malicious JavaScript code through the plugin's contact form without requiring authentication. When a user interacts with a compromised form, the malicious script executes in their browser, potentially stealing credentials, session tokens, or sensitive data. The vulnerability is rated HIGH with a CVSS score of 7.1, indicating significant risk to affected installations.

  • CVE-2026-39507HIGH 7.1

    Social Slider Feed, a WordPress plugin, contains an unauthenticated cross-site scripting (XSS) vulnerability affecting versions 2.3.2 and earlier. An attacker can inject malicious scripts that execute in visitors' browsers without needing to authenticate, potentially compromising user sessions, stealing credentials, or redirecting visitors to malicious sites. The vulnerability is triggered through user interaction (clicking a link or viewing a page), making it a practical attack vector against websites using vulnerable versions.

  • CVE-2026-39514HIGH 7.1

    A cross-site scripting (XSS) vulnerability exists in Paid Member Subscriptions plugin versions 2.17.3 and earlier that allows attackers to inject malicious scripts without requiring authentication. An attacker can craft a malicious link or embed script payloads that execute in a victim's browser when they visit an affected page, potentially stealing session data, credentials, or performing actions on behalf of the victim. Because no login is required to trigger the vulnerability, the attack surface is broad.

  • CVE-2026-39597HIGH 7.1

    A stored cross-site scripting (XSS) vulnerability exists in WPZOOM Addons for Elementor plugin versions 1.3.4 and earlier. The vulnerability allows unauthenticated attackers to inject malicious JavaScript code that executes in the browsers of website visitors, potentially stealing session cookies, redirecting users to malicious sites, or performing unauthorized actions on behalf of visitors. No special authentication or complex conditions are required to exploit this vulnerability—an attacker only needs to craft a request containing malicious script and trick a user into viewing the affected page.

  • CVE-2026-39903HIGH 7.1

    Simple Machines Forum (SMF), a popular open-source discussion platform, contains a logic error in its attachment approval system that allows any logged-in user to modify, delete, or approve pending file uploads—even if they lack permission to do so. The flaw stems from a single-character mistake in the permission-checking code that causes the authorization check to fail silently, treating unauthorized users as if they had full moderation rights. This affects SMF 2.1 and 3.0 prior to specific commits. An attacker with basic forum access can exploit this to disrupt moderation workflows, enumerate other users' uploads, delete files, or approve malicious attachments without detection.

  • CVE-2026-40522HIGH 7.1

    FrontAccounting versions before 2.4.20 contain a SQL injection flaw in the Bank Statement report feature. An authenticated user can craft malicious SQL code in the report parameters to bypass normal database queries and extract sensitive information such as usernames, password hashes, and email addresses from the system. The vulnerability allows this data to be embedded into PDF reports. Because the flaw requires user login credentials to exploit, it represents a risk primarily from insiders or compromised accounts rather than unauthenticated internet attacks.

  • CVE-2026-40720HIGH 7.1

    Royal Elementor Addons Pro versions before 1.7.1041 contain an unauthenticated Cross-Site Scripting (XSS) vulnerability. An attacker can inject malicious JavaScript code into web pages viewed by users of sites using the vulnerable plugin, without requiring any authentication or special privileges. When victims visit an affected page, the injected script executes in their browser, potentially stealing credentials, session cookies, or performing unauthorized actions on their behalf.

  • CVE-2026-40732HIGH 7.1

    Notification for Telegram versions 3.5 and earlier contain an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages without requiring authentication. An attacker can craft a malicious link or content that, when clicked by a user, executes arbitrary JavaScript in the victim's browser within the context of the affected application. This can lead to session hijacking, credential theft, or defacement of the notification interface.

  • CVE-2026-40787HIGH 7.1

    Quiz And Survey Master, a WordPress plugin used for creating and managing online quizzes and surveys, contains an unauthenticated Cross-Site Scripting (XSS) vulnerability in versions 11.0.0 and earlier. This means an attacker can inject malicious JavaScript code into a page without needing to log in, which will execute in the browsers of site visitors. If a user clicks a malicious link or visits a compromised page, their session cookies, personal data, or login credentials could be stolen, or they could be redirected to phishing pages.

  • CVE-2026-40791HIGH 7.1

    WP Time Slots Booking Form, a WordPress plugin used for appointment scheduling, contains an unauthenticated cross-site scripting (XSS) vulnerability in versions 1.2.46 and earlier. An attacker can inject malicious JavaScript code that executes in the browsers of site visitors or administrators without requiring authentication. This allows attackers to steal session tokens, redirect users, deface content, or harvest sensitive information through the booking form interface.

  • CVE-2026-40987HIGH 7.1

    A vulnerability in Spring Integration allows a malicious or compromised remote file server (FTP, SFTP, or SMB) to write files anywhere on a client machine's filesystem, bypassing intended directory restrictions. An attacker controlling or compromising the remote server can place arbitrary files with attacker-chosen content on the victim's system, enabling code execution, configuration tampering, or other post-exploitation activities. The vulnerability requires the attacker to either compromise a legitimate server the client connects to or convince a user to connect to an attacker-controlled server, making it a supply-chain and social-engineering risk vector.

  • CVE-2026-41048HIGH 7.1

    qSnapper, a snapshot management tool, has a flaw in how it manages user permissions for different administrative actions. A local user on a system could perform restricted operations—such as restoring snapshots—even if their account was only granted permission to delete them. This happens because the system incorrectly caches authentication decisions across different snapshot functions, allowing a lower-privileged user to bypass intended access controls. The vulnerability requires local access and user interaction to exploit.

  • CVE-2026-41049HIGH 7.1

    A flaw in the qSnapper D-Bus service allows unprivileged local users to hijack authenticated sessions. When a privileged user authenticates to perform an action via D-Bus, the service incorrectly caches that authentication state without proper isolation. A local attacker can then invoke the same D-Bus functions without re-authenticating, effectively using the elevated privileges that were granted to the legitimate user. This is a local privilege escalation vulnerability requiring an existing login session on the affected system.

  • CVE-2026-41122HIGH 7.1

    Dell PowerProtect Data Domain contains a stored cross-site scripting (XSS) vulnerability that allows an unauthenticated attacker to inject malicious code into the application. When legitimate users access the affected system, that injected code executes in their browsers, potentially stealing session tokens, harvesting credentials, or performing actions on their behalf. The vulnerability affects multiple release branches across versions 7.7.1.0 through 8.7, with specific ranges identified for LTS releases.

  • CVE-2026-41845HIGH 7.1

    Spring Framework contains a flaw in its JavaScriptUtils.javaScriptEscape() function that fails to properly escape certain characters. This weakness allows attackers to inject malicious JavaScript code that executes in users' browsers, potentially stealing session data, credentials, or performing actions on behalf of the user. The vulnerability requires user interaction—specifically clicking a malicious link or visiting a compromised page—but does not require authentication. Multiple versions of Spring Framework across the 5.3, 6.1, 6.2, and 7.0 release lines are affected.

  • CVE-2026-42385HIGH 7.1

    Profile Builder Pro versions 3.15.0 and earlier contain an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. Because no authentication is required and user interaction is minimal, attackers can exploit this remotely by crafting a malicious URL or embedding code in seemingly legitimate pages. When a victim visits an affected site running the vulnerable plugin, their browser executes the attacker's script, potentially stealing session cookies, capturing credentials, or performing actions on their behalf.

  • CVE-2026-4259HIGH 7.1

    The ultimate-woocommerce-auction-pro WordPress plugin, in versions through 2.4.5, contains a reflected cross-site scripting (XSS) vulnerability. An attacker can craft a malicious link containing JavaScript code that, when clicked by a site administrator or other privileged user, executes arbitrary code in their browser session. This could allow the attacker to perform administrative actions, steal sensitive data, or modify site content without the user's knowledge.

  • CVE-2026-42653HIGH 7.1

    SliceWP, a WordPress plugin, contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. Unlike reflected XSS attacks that require victims to click a link, stored XSS persists in the application, affecting all users who view the compromised content. An attacker without authentication can exploit this to steal session cookies, redirect users, or perform actions on behalf of site visitors. The vulnerability affects SliceWP versions through 1.2.6.

  • CVE-2026-42654HIGH 7.1

    WP Swings Wallet System for WooCommerce contains a flaw that allows attackers with an existing user account to bypass normal authentication safeguards and exploit the password recovery mechanism. An authenticated attacker could use this vulnerability to take over other user accounts, including administrative ones, without knowing their passwords. The vulnerability affects all versions up to and including 2.7.5.

  • CVE-2026-42678HIGH 7.1

    GiveWP, a popular WordPress donation and fundraising plugin maintained by Liquid Web/StellarWP, contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by site visitors. Unlike traditional XSS flaws, this vulnerability operates at the DOM (Document Object Model) level in the browser, meaning the attack payload is crafted and executed client-side rather than originating from the server. An attacker can trick a user into clicking a malicious link or visiting a compromised page, leading to credential theft, session hijacking, or unauthorized actions taken on behalf of the victim within the vulnerable GiveWP installation.

  • CVE-2026-42681HIGH 7.1

    E2Pdf.Com's e2pdf plugin contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When a user visits a crafted link, the injected code executes in their browser within the context of the affected site, potentially allowing theft of session data, credentials, or sensitive information. The vulnerability affects e2pdf versions up to and including 1.32.14.

  • CVE-2026-42683HIGH 7.1

    VikBooking Hotel Booking Engine & PMS contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. An attacker can craft a malicious link or embed JavaScript in user-controllable input fields; when a victim visits the page or interacts with the compromised element, the script executes in their browser with access to session data and sensitive information. This is a client-side vulnerability requiring user interaction but affecting multiple users through a single compromised page.

  • CVE-2026-42685HIGH 7.1

    Ahmad WP Job Portal versions up to 2.5.1 contain a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. An attacker can craft a specially designed link and trick a user into clicking it, causing the injected code to execute in that user's browser with their privileges. This vulnerability requires user interaction—the victim must click a malicious link—but once triggered, it can be used to steal session tokens, deface content, redirect users to phishing sites, or perform actions on behalf of the victim.

  • CVE-2026-43701HIGH 7.1

    A vulnerability in Apple's Safari web browser and related operating systems allows malicious websites to process restricted web content that should remain sandboxed, potentially exposing sensitive data or enabling unauthorized actions on affected devices. The issue stems from insufficient validation checks when handling web content within the browser's security boundaries. Users who visit a specially crafted malicious website could have their device compromised without additional interaction beyond browsing.

  • CVE-2026-43725HIGH 7.1

    A sandbox escape vulnerability in Apple's Safari browser and related platforms allows malicious websites to execute code outside the intended security boundary. By exploiting improper input validation, an attacker can craft a malicious webpage that, when visited by a user, breaks out of the sandbox protection that normally isolates web content. This could allow the attacker to access restricted system resources or data that should be inaccessible to web content.

  • CVE-2026-44751HIGH 7.1

    An ABAP application server fails to verify user permissions when processing report generation commands. An authenticated attacker can bypass authorization checks to execute reports that overwrite data belonging to other users, effectively gaining unauthorized access to modify information they should not be able to touch. This is a privilege escalation vulnerability accessible to anyone with valid login credentials.

  • CVE-2026-44798HIGH 7.1

    A vulnerability in Nautobot allows authenticated users with GitRepository management permissions to manipulate an internal field (current_head) via the REST API that should not be user-editable. By setting this field to arbitrary values, an attacker could cause Nautobot's local repository clones to checkout outdated commits or become unusable entirely, creating operational disruption and potentially stale or corrupted network automation state. The issue affects versions prior to 2.4.33 and 3.1.2.

  • CVE-2026-45329HIGH 7.1

    CVE-2026-45329 is a memory disclosure vulnerability in Espressif's IoT Development Framework (ESP-IDF) affecting versions 5.5.4 and 6.0. The issue stems from inadequate input validation in secure-service wrapper functions that interface with TEE (Trusted Execution Environment) hardware. An attacker with local access can supply carefully crafted memory pointers to these wrappers, causing the underlying TEE-protected peripherals (such as ECC, SHA, or SPI engines) to read sensitive data from TEE-exclusive memory regions and return it to the untrusted realm. The disclosure occurs through direct byte leakage, computed results, or bit-level oracles, enabling incremental extraction of secrets stored in the TEE.

  • CVE-2026-45437HIGH 7.1

    The Product Filter Widget for Elementor—a popular WordPress page builder plugin—contains an unauthenticated cross-site scripting (XSS) vulnerability in versions 1.0.6 and earlier. An attacker can inject malicious scripts into the widget's filter functionality without requiring authentication, which execute in the browsers of site visitors. The vulnerability is triggered when a user interacts with the affected filter, potentially compromising visitor sessions, stealing credentials, or redirecting users to malicious sites.

  • CVE-2026-45542HIGH 7.1

    A heap buffer overflow vulnerability exists in Espressif's IoT Development Framework (ESP-IDF) affecting the Security Scheme 2 (SRP6a) component used during initial device provisioning and session setup. When a device receives a provisioning request with a specially crafted username field, the security handler copies the user-supplied length into a smaller buffer than intended, corrupting heap memory and potentially causing the device to crash or behave unpredictably. An attacker within network range of the target device can trigger this without authentication.

  • CVE-2026-45649HIGH 7.1

    A flaw in Microsoft Office apps on Android devices allows someone with local access to spoof or impersonate document content without requiring special permissions or user interaction beyond launching the app. An attacker with physical or logical access to the device could manipulate what appears in Word, Excel, or PowerPoint documents, potentially tricking the device owner or others into trusting falsified information. The vulnerability affects the access control layer that should prevent unauthorized modification of displayed document content.

  • CVE-2026-45722HIGH 7.1

    A vulnerability in Nextcloud's Tables app allows authenticated users to inject malicious SQL code through the ORDER BY clause of database queries. While this type of SQL injection is more limited than typical variants—attackers can extract only small amounts of data per request or cause database delays—it still poses a meaningful confidentiality and availability risk. The flaw affects Nextcloud Tables versions 0.9.0 through 0.9.6 and 1.0.0 through 1.0.1. Nextcloud has released patches that organizations should apply promptly.

  • CVE-2026-46130HIGH 7.1

    A bug in the Linux kernel's dm-verity-fec (forward error correction) component can cause it to read data from outside the intended memory buffer. This occurs when parity bytes used to verify disk integrity are split across storage blocks in a specific way. Under certain non-default configurations and low-memory conditions, the code attempts to access more data than is available, leading to potential information disclosure or system instability. The issue only manifests with particular combinations of error correction parameters and buffer allocation scenarios.

  • CVE-2026-46140HIGH 7.1

    A flaw in the Linux kernel's Bluetooth driver (btmtk) fails to verify that incoming firmware responses contain sufficient data before reading from them. If a Bluetooth device sends a truncated or malformed response, the kernel code will read beyond the valid data boundaries, potentially exposing sensitive kernel memory. A local attacker with Bluetooth access could exploit this to leak information or crash the system.

  • CVE-2026-46149HIGH 7.1

    A vulnerability in the Linux kernel's SCSI target subsystem allows a local attacker with low privileges to read sensitive kernel memory and potentially crash the system. The issue occurs in the configfs interface where storage path group membership information is displayed. When a storage fabric's name is unusually long, the kernel writes more data than expected to a temporary buffer, and then copies that overrun data to a user-readable sysfs file. On systems with fortify checks enabled, this causes a kernel panic; on others, it leaks kernel memory to unprivileged users.

  • CVE-2026-46150HIGH 7.1

    A flaw in the Linux kernel's fanotify file monitoring subsystem can allow a local user with minimal privileges to bypass permission checks on file access events. The vulnerability stems from a logic error where the kernel incorrectly returns false for marks belonging to unrelated monitoring groups, causing permission event validation to be skipped. An attacker with local access could exploit this to circumvent intended file access restrictions.

  • CVE-2026-46175HIGH 7.1

    A flaw in the Linux kernel's F2FS (Flash-Friendly File System) garbage collection process can cause the system to incorrectly track file metadata during node block migration. When the garbage collector moves data blocks, it fails to properly clear internal markers that indicate whether data has been explicitly synced by a user. This confusion causes file system consistency checks (fsck) to report false inconsistencies, potentially leading to data integrity warnings or failures. The issue is triggered by specific sequences of file creation, deletion, and garbage collection operations, particularly when the system experiences power loss after garbage collection but before a checkpoint is written.

  • CVE-2026-46190HIGH 7.1

    A memory access flaw exists in the Linux kernel's SPI NOR flash debugging code. When displaying flash chip parameters through the debugfs interface, the kernel incorrectly calculates the size of an internal lookup table, treating the table's byte-size instead of its element count. This can cause the kernel to read memory beyond the intended bounds when processing certain flag values. An unprivileged local user could exploit this to crash the system or potentially leak sensitive kernel memory.

  • CVE-2026-46191HIGH 7.1

    CVE-2026-46191 is a memory access vulnerability in the Linux kernel's framebuffer console (fbcon) subsystem. When the kernel attempts to rotate the console display and the memory reallocation fails, it continues using an undersized font buffer. If a user then prints characters with high numeric codes to the rotated console, the kernel will write beyond the buffer's boundaries, potentially corrupting kernel memory. An attacker with local system access can trigger this by printing specific characters after inducing a console rotation failure.

  • CVE-2026-46199HIGH 7.1

    A flaw in the Linux kernel's AMD GPU video codec (VCN4) driver allows a local attacker to read memory beyond the intended boundaries of a buffer when processing decode messages. An authenticated user with local access can exploit this to access sensitive kernel memory, potentially exposing confidential data or triggering a system crash. The vulnerability requires local access and valid user privileges, limiting its reach but making it a concern for multi-user systems and containerized environments.

  • CVE-2026-46203HIGH 7.1

    A flaw in the Linux kernel's Cadence QuadSPI controller driver can cause the system to access hardware registers without proper power management during driver shutdown. When the driver is unloaded, it attempts to disable the controller without ensuring the hardware is powered up first, potentially causing system instability or data corruption. This is a local issue requiring user-level access to trigger.

  • CVE-2026-46204HIGH 7.1

    A bounds-checking vulnerability exists in the Linux kernel's AMD GPU video codec (VCN4) instruction buffer parser. When the kernel processes instruction buffers from user space, it can read beyond allocated memory if malicious or malformed data is provided. A local attacker with basic user privileges can trigger out-of-bounds reads, potentially exposing sensitive kernel memory or causing a denial of service. The fix involves rewriting the parser to use proper bounds-checking functions.

  • CVE-2026-46218HIGH 7.1

    A vulnerability exists in the Linux kernel's AMD GPU driver where video codec processing code (used for UVD, VCE, and VCN hardware) accesses memory buffers without verifying those buffers are large enough. An attacker with local access could exploit this to read sensitive kernel memory or cause a system crash. The fix adds proper bounds checking before these memory accesses and corrects an integer type to prevent overflow conditions that could bypass the checks.

  • CVE-2026-46230HIGH 7.1

    A boundary-checking flaw in the Linux kernel's AMD GPU video codec driver (VCN3) allows a local user with moderate privileges to read memory beyond allocated buffer boundaries when the driver processes video decoding messages. This out-of-bounds read could expose sensitive kernel memory or crash the system. The vulnerability requires local access and existing user-level permissions to trigger.

  • CVE-2026-46243HIGH 7.1

    A Linux kernel vulnerability allows unprivileged local users to manipulate CIFS (Common Internet File System) authentication credentials by creating spoofed credential requests. The vulnerability exists because the kernel's SMB client accepts cifs.spnego key descriptions that contain sensitive fields—like process ID, user ID, and credential UID—regardless of whether those fields come from the kernel itself or from untrusted userspace. An attacker with local access can forge these fields to impersonate legitimate credential requests, potentially gaining unauthorized access to network resources or intercepting authentication flows. The fix restricts acceptance of cifs.spnego keys only when they originate from the kernel's own credential handler.

  • CVE-2026-46293HIGH 7.1

    A Linux kernel vulnerability exists in the Microchip PolarFire SoC clock controller driver where the software attempts to write data to memory locations outside the bounds of an allocated array during clock output registration. Specifically, when the driver registers the last two clock outputs, it accesses array indices that were never allocated, corrupting adjacent memory. This occurs because the code defines space for two PLLs and their outputs but fails to properly offset the array indices when handling DLL (Delay-Locked Loop) outputs that the driver doesn't actually support. An attacker with local access can exploit this to read sensitive kernel memory or cause a denial of service.

  • CVE-2026-46321HIGH 7.1

    A memory leak vulnerability exists in the Linux kernel's TUN device driver. When a frame shorter than the Ethernet header minimum is rejected, the kernel fails to release allocated memory pages. An attacker with local access to /dev/net/tun and /dev/vhost-net can exploit this by repeatedly sending undersized frames through a vhost-net backend, exhausting system memory and potentially causing the host to crash.

  • CVE-2026-46322HIGH 7.1

    A memory leak exists in the Linux kernel's TUN network device driver. When the kernel attempts to construct a network packet (skb) from XDP program data and that construction fails, it doesn't properly release a memory page that was allocated earlier in the process. This causes a small chunk of memory to leak each time this failure occurs. In batch processing scenarios—common in virtual networking—multiple failures can accumulate, gradually consuming system memory and potentially degrading performance or availability.

  • CVE-2026-46657HIGH 7.1

    Bludit, a content management system, contains a flaw in how it handles user account deactivation. When an administrator disables a user account, the system fails to clear the authentication tokens stored locally. This means a user who previously selected "Remember Me" can continue accessing the system even after their account has been disabled by an administrator. The vulnerability requires the attacker to have had legitimate access before being deactivated, but once disabled, they can maintain that access indefinitely unless the underlying token data is manually cleared.

  • CVE-2026-46914HIGH 7.1

    A flaw in Oracle Solaris 11.4's filesystem component allows an authenticated user on the local system to read sensitive data or crash the operating system. An attacker with standard user privileges can exploit this without needing to interact with the system graphically—it happens automatically through the vulnerable code path. The vulnerability is rated HIGH severity and poses a real risk to organizations running Solaris infrastructure, particularly those handling sensitive data or requiring high availability.

  • CVE-2026-46932HIGH 7.1

    A flaw in Oracle Enterprise Asset Management allows someone with low-level network access to view sensitive data or cause service disruptions. An authenticated user (even with minimal privileges) can send specially crafted HTTP requests to the application to either read confidential information or partially disable the service. The vulnerability affects versions 12.2.3 through 12.2.15 and does not require user interaction—an attacker simply needs valid login credentials and network connectivity to the system.

  • CVE-2026-47120HIGH 7.1

    Nezha Monitoring, a self-hosted monitoring tool, contains an authorization bypass flaw affecting versions 1.4.0 through 2.0.7. A user with RoleMember privileges can trigger cron tasks (scheduled automation jobs) owned by other users without proper permission checks. While the attacker cannot see the tasks' contents or modify them, they can force execution, potentially disrupting monitoring workflows or triggering unintended automated actions. The vulnerability requires authenticated access and has been fixed in version 2.0.8.

  • CVE-2026-47147HIGH 7.1

    CVE-2026-47147 is a memory disclosure vulnerability in Silicon Labs' EmberZNet protocol stack affecting version 9.0.2 and earlier. An attacker who has already joined a Zigbee network can send specially crafted Over-the-Air (OTA) update requests that cause the OTA server to read beyond intended memory boundaries, leaking a limited amount of RAM contents back to the requester. The vulnerability is network-bound, requires prior network authentication, and only impacts devices that implement the OTA Server cluster—significantly narrowing the exposure window compared to broader network attacks.

  • CVE-2026-47150HIGH 7.1

    EmberZNet, Silicon Labs' Zigbee networking stack, contains a flaw in how it processes enrollment messages from the IAS (Intruder Alarm System) Zone cluster. A device already connected to the network can send specially crafted enrollment packets that cause the software to write data beyond the intended boundaries of a state table, crashing the process. The vulnerability is confined to network-adjacent attackers with prior network membership and only affects devices that implement IAS Zone functionality.

  • CVE-2026-47151HIGH 7.1

    CVE-2026-47151 is a memory safety vulnerability in Silicon Labs' EmberZNet v9.0.2 and earlier that allows an authenticated network attacker to corrupt Door Lock cluster state by sending specially crafted schedule messages. An attacker who has already joined the Zigbee network can trigger out-of-bounds memory writes, potentially disabling or malfunctioning door lock scheduling features. The vulnerability is contained to devices implementing the Door Lock cluster and does not permit remote code execution, but it can degrade the availability and integrity of lock functionality.

  • CVE-2026-47214HIGH 7.1

    Docling, a document processing library that converts various file formats and integrates with AI systems, contains a vulnerability in its HTML parser that mishandles URIs and file paths. An attacker can exploit this by crafting a malicious document that, when processed by a user, could leak sensitive information or cause the application to become unavailable. The vulnerability affects versions prior to 2.94.0 and requires user interaction to trigger.

  • CVE-2026-47288HIGH 7.1

    CVE-2026-47288 is a high-severity integer overflow vulnerability in Windows Kerberos authentication that allows an authenticated attacker on an adjacent network to execute arbitrary code with system-level privileges. The flaw resides in how Kerberos handles certain numeric calculations, causing a wraparound condition that can be exploited to bypass security checks and inject malicious code. An attacker must already have valid credentials and network proximity to the target, which limits the immediate blast radius but makes this a serious concern for domain environments where lateral movement is a known threat model.

  • CVE-2026-4776HIGH 7.1

    Mautic, a popular marketing automation platform, contains an SQL injection flaw in its API that allows authenticated users to execute unauthorized database queries. The vulnerability stems from incomplete filtering of nested query parameters in the contact filtering API—an attacker with valid API credentials can craft specially formed requests to bypass safety checks and inject SQL commands directly into database queries. This could lead to unauthorized data access or limited system disruption, though the attacker must already have valid API authentication.

  • CVE-2026-48119HIGH 7.1

    Nezha Monitoring, a self-hosted server and website monitoring tool, contains a vulnerability that allows authenticated agents to falsify monitoring results for services owned by other users. An attacker with valid agent credentials can forge service health data, creating false alerts or hiding actual service problems. The vulnerability affects versions 0.20.0 through 2.0.11 and is resolved in version 2.0.12.

  • CVE-2026-48209HIGH 7.1

    OTRS ticket management systems contain a reflected cross-site scripting (XSS) vulnerability in how they handle user input during ticket operations. An attacker can craft a malicious URL containing JavaScript code and trick an authenticated agent into clicking it. When opened, the script executes within the agent's browser session, potentially allowing the attacker to steal session tokens, modify tickets, or perform actions on behalf of that agent. The attack requires social engineering to deliver the link but does not require the attacker to have direct system access.

  • CVE-2026-48507HIGH 7.1

    Snipe-IT, a popular IT asset and license management system, has a privilege escalation flaw that lets low-privileged users with basic editing permissions lock all administrators out of the system. A user granted only the `users.edit` permission can disable admin accounts by toggling login flags and blocking password reset options, effectively taking control of the instance. The vulnerability affects all versions before 8.6.0 and is fixed in that release.

  • CVE-2026-48569HIGH 7.1

    A flaw in Visual Studio Code's input handling allows a local attacker to circumvent a security mechanism without requiring elevated privileges or special user setup. The attacker must interact with the application through the user interface, but once triggered, the exploit can affect system-wide settings and processes beyond the application's normal scope. This is a local-attack surface issue that could allow an unauthorized actor to modify or access protected features.

  • CVE-2026-48759HIGH 7.1

    TypeBot, a chatbot builder platform, contains an authorization flaw in versions 3.15.2 and earlier that allows authenticated users to modify or delete theme templates belonging to workspaces they don't have access to. The vulnerability stems from incomplete permission checks: while the application verifies that a user belongs to a workspace before processing a request, the underlying database queries fail to confirm the user has authority over the specific theme template being modified or deleted. An attacker with any TypeBot account can exploit this to tamper with or destroy another organization's chatbot themes, potentially disrupting service availability and integrity.

  • CVE-2026-48827HIGH 7.1

    Apache MINA SSHD's sshd-git module contains a path traversal vulnerability that allows SSH-authenticated users to access git repositories and perform git operations (upload-pack, receive-pack, and others) outside the configured git server root directory. An attacker with valid SSH credentials can escape the intended directory boundary and potentially read or modify repositories they should not have access to. This affects only applications explicitly using the sshd-git component; standard SSHD deployments without sshd-git are unaffected.

  • CVE-2026-48839HIGH 7.1

    A cross-site scripting (XSS) vulnerability exists in VeronaLabs WP Statistics plugin versions up to 14.16.6. The flaw allows attackers to inject malicious scripts that execute in a user's browser when they interact with a compromised page. Unlike traditional XSS attacks that rely on server-side injection, this variant operates at the DOM (Document Object Model) level, meaning the vulnerability stems from how the plugin processes user input on the client side. An attacker could craft a malicious link or embed code that, when visited by a site administrator or editor, steals session tokens, modifies page content, or performs actions on their behalf.

  • CVE-2026-48865HIGH 7.1

    ThimPress LearnPress, a popular WordPress learning management plugin, contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. An attacker can craft a malicious URL and trick a user into clicking it, causing the victim's browser to execute arbitrary JavaScript in the context of the LearnPress application. This could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the user.

  • CVE-2026-48867HIGH 7.1

    Quiz and Survey Master, a WordPress plugin, contains an unauthenticated cross-site scripting (XSS) vulnerability affecting versions 11.1.2 and earlier. An attacker can inject malicious scripts into web pages without requiring any authentication, potentially allowing them to steal user credentials, deface content, or redirect visitors to malicious sites. The vulnerability requires user interaction (such as clicking a link) to trigger the attack, but the widespread deployment of this plugin on WordPress sites makes it a notable risk.

  • CVE-2026-48871HIGH 7.1

    A reflected cross-site scripting (XSS) vulnerability exists in MW WP Form plugin versions 5.1.3 and earlier. An attacker can craft a malicious link that, when clicked by a user visiting the site, injects arbitrary JavaScript into the page. The vulnerability requires user interaction—the victim must click the crafted link—but once triggered, the injected script runs with the privileges of the logged-in user, potentially allowing theft of session tokens, sensitive data, or administrative actions.

  • CVE-2026-48966HIGH 7.1

    Funnel Builder by FunnelKit, a WordPress plugin used to create sales and marketing funnels, contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts without authentication. Because it's unauthenticated, anyone visiting an affected site or being directed to a malicious page can trigger the attack. The vulnerability affects versions 3.15.0.2 and earlier.

  • CVE-2026-48997HIGH 7.1

    e107 is a content management system widely used for building websites and managing content. A vulnerability in versions 2.3.5 and earlier allows authenticated users to inject shell commands during the image resizing process. When news articles with attachments are uploaded, the system uses ImageMagick to resize images. The vulnerability exists because the destination filename for the resized image is constructed from the news article title without proper escaping. An attacker can craft a malicious title containing shell metacharacters (like backticks or variable expansion syntax) that will be executed by the underlying shell, potentially giving them control over the server. This only affects installations using specific ImageMagick settings and requires an authenticated account with sufficient permissions.

  • CVE-2026-49055HIGH 7.1

    A reflected cross-site scripting (XSS) vulnerability exists in the Drag and Drop Multiple File Upload plugin for Contact Form 7 up to version 1.3.9.7. An attacker can craft a malicious link containing injected JavaScript that, when clicked by a user, executes in the victim's browser within the context of the vulnerable site. No authentication is required to exploit this flaw, and the attack succeeds through social engineering or phishing. The injected script can steal session tokens, deface content, or redirect users to malicious sites.

  • CVE-2026-49069HIGH 7.1

    WPZOOM Portfolio contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages through reflected input. An attacker can craft a malicious link that, when clicked by a user, executes arbitrary JavaScript in the victim's browser. This affects WPZOOM Portfolio versions up to and including 1.4.21. The vulnerability requires user interaction—the victim must click a malicious link—but once triggered, the attack can compromise session cookies, steal sensitive data, or perform actions on behalf of the user.

  • CVE-2026-49134HIGH 7.1

    CodexBar versions before 0.32.0 contain a local privilege escalation flaw in the CLI installer. An attacker with access to the same system can intercept and modify the installer's temporary files during the installation process, tricking the system into running malicious commands with root-level privileges. This requires the attacker to be on the same machine and to time their interference with an active installation, but once successful, grants complete system control.

  • CVE-2026-49135HIGH 7.1

    CodexBar versions before 0.32.0 have a serious flaw in how they handle temporary files during the app release and notarization process. An attacker with access to the same machine can steal the App Store Connect API credentials or sabotage the build artifacts before they're submitted to Apple. The vulnerability exists because CodexBar writes sensitive files to predictable, fixed locations that any local user can read or manipulate.

  • CVE-2026-49141HIGH 7.1

    WACRM contains an authorization flaw that allows someone with valid login credentials to view and change contact records from other customers. The vulnerability exists in the automation engine and doesn't properly verify that the attacker owns the contact they're modifying. An attacker needs only to know a contact's ID number to change things like names, email addresses, and company information across different customer accounts.

  • CVE-2026-49295HIGH 7.1

    libde265, an open-source H.265 video codec library, contains a flaw where a specially crafted video file can cause the decoder to write data beyond the boundaries of an internal array. This happens during the processing of reference picture sets—a critical step in decoding H.265 video. The vulnerability can lead to application crashes or memory corruption, affecting any system that uses libde265 to decode H.265 video streams. The issue was patched in version 1.0.20.

  • CVE-2026-49338HIGH 7.1

    Gonic is an open-source music streaming server that implements the Subsonic API. Before version 0.21.0, two API endpoints failed to properly check which user is asking for access to playlists. This means any logged-in user—even with limited privileges—could delete playlists belonging to any other user, including administrators, and read the contents of private playlists if they could guess or find the playlist ID. The vulnerability stems from the fact that playlist IDs are predictable (based on user IDs and filenames) and sometimes publicly exposed before being marked private. This breaks the isolation between user accounts that the system is supposed to maintain.

  • CVE-2026-49339HIGH 7.1

    Gonic, a free software Subsonic server implementation, contains a path traversal vulnerability that undermines a previously-patched access control check. An authenticated user can craft a malicious playlist ID containing path traversal sequences to bypass ownership verification, allowing them to read, delete, or probe other users' playlists and arbitrary files on the server. The vulnerability was introduced when the maintainer attempted to fix a related issue by checking playlist ownership—but failed to sanitize the playlist ID parameter itself, leaving the door open to directory traversal attacks. Version 0.21.0 and later contain the fix.

  • CVE-2026-49346HIGH 7.1

    libde265 is a video codec library used to decode H.265 video streams. A flaw in versions before 1.1.0 occurs when processing specially crafted video files with specific dimension and bit-depth properties. The vulnerability allows an attacker to trigger a memory overflow that corrupts the heap, potentially crashing applications or enabling further compromise. An attacker would need to trick a user into opening a malicious video file, but no special privileges are required.

  • CVE-2026-49371HIGH 7.1

    JetBrains TeamCity versions prior to 2026.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the keyword filter feature. An attacker can craft a malicious URL containing unsanitized input that, when visited by a TeamCity user, executes arbitrary JavaScript in the victim's browser within the context of the TeamCity application. This allows session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.

  • CVE-2026-49373HIGH 7.1

    JetBrains TeamCity versions prior to 2026.1 contain a remote code execution vulnerability accessible through the Perforce connection configuration interface. An authenticated user with permissions to modify Perforce settings can execute arbitrary code on the TeamCity server. This requires valid credentials and access to TeamCity's configuration features, but does not require user interaction or special system conditions once access is gained.

  • CVE-2026-49396HIGH 7.1

    Nezha Monitoring, a self-hosted server and website monitoring tool, contains a cross-site request forgery (CSRF) vulnerability that allows attackers to trick users into executing malicious cron commands on connected agents. An attacker can craft a specially designed webpage or email that, when visited by an authenticated Nezha administrator, silently triggers unwanted scheduled tasks on monitored servers. This happens because the application doesn't properly validate requests coming from external sources. The vulnerability affects all versions from 1.0.0 through 2.0.13, and has been resolved in version 2.0.14 and later.

  • CVE-2026-49413HIGH 7.1

    FreeBSD's Linuxulator—a compatibility layer that allows Linux binaries to run on FreeBSD—fails to properly mark when a Linux binary is running with elevated privileges (set-user-ID or set-group-ID). An unprivileged local attacker can exploit this by injecting a malicious shared library into such a binary, tricking it into loading untrusted code with the privileges the binary was meant to have. This is a local privilege escalation vulnerability affecting systems that run Linux binaries on FreeBSD and have set-user-ID or set-group-ID Linux executables installed.

  • CVE-2026-49839HIGH 7.1

    jq is a widely-used command-line tool for processing JSON data. This vulnerability exists in how jq handles very large files when using the `--rawfile` option. When jq reads an oversized file, it is supposed to stop and report an error once the file exceeds the string size limit. However, in versions before 1.8.2, the error handling is incomplete: the tool continues trying to read more data from the file even after detecting it is too large. This causes jq to write data to memory locations it shouldn't access, potentially leading to a crash or allowing an attacker to execute code. An attacker would need to trick a user into running jq on a specially crafted large file.

  • CVE-2026-50146HIGH 7.1

    Astro, a popular web framework, contains a reflected cross-site scripting (XSS) vulnerability in versions before 6.3.3. When components use client-side directives, Astro fails to properly escape slot names before inserting them into HTML attributes. An attacker can exploit this by crafting a malicious slot name that breaks out of the attribute context and injects arbitrary HTML code. The vulnerability occurs during server-side rendering (SSR), meaning the injected content is reflected back to users without proper sanitization, allowing attackers to steal session tokens, redirect users, or perform actions on their behalf.

  • CVE-2026-50181HIGH 7.1

    Langroid is a framework that helps developers build applications powered by large language models (LLMs). Versions before 0.64.0 contain a path traversal vulnerability in the file reading and writing tools. While these tools are meant to restrict file operations to a specified directory, they fail to properly validate file paths. An attacker with access to trigger tool calls can use path traversal sequences like `../` to read sensitive files outside the intended directory or write malicious files in unexpected locations. This is particularly concerning when Langroid applications expose these tools directly to LLM agents or accept user-controlled instructions, as the safety boundary meant to isolate file access can be completely bypassed.

  • CVE-2026-5230HIGH 7.1

    CVE-2026-5230 is a high-severity access control flaw in MIA Technology Inc.'s Pizzy Library that allows authenticated users to bypass authorization checks and access data or functionality they shouldn't have permission to reach. The vulnerability stems from incorrectly configured security levels that fail to properly validate user privileges. Versions 1.0.0.26250 through 1.3.8.26250 are affected; upgrading to 1.3.9.26250 or later resolves the issue.

  • CVE-2026-5233HIGH 7.1

    CVE-2026-5233 is a flaw in MIA Technology Inc.'s Pizzy Library that allows authenticated users to overwhelm the system by making requests at abnormally high frequencies. An attacker with valid credentials can trigger excessive interactions that degrade service availability and may corrupt or modify data in transit. The vulnerability affects versions 1.0.0.26250 through 1.3.8.26250. While it requires authentication to exploit, the damage potential—particularly availability and integrity impacts—makes this a material risk for any system using vulnerable versions.

  • CVE-2026-52719HIGH 7.1

    A flaw in GStreamer's JPEG decoder allows an attacker to craft a malicious JPEG file that, when opened, causes the application to read data outside the bounds of the file buffer. This can crash the application or potentially leak sensitive information from memory. The vulnerability requires user interaction—someone must open the specially crafted file—but requires no special privileges and spreads easily via email, messaging, or web downloads.

  • CVE-2026-52722HIGH 7.1

    GStreamer, a widely-used multimedia framework, contains a flaw in how it processes VMnc video streams—a format used for remote desktop and screen recording. An attacker can craft a malicious VMnc file with artificially large cursor dimensions that causes the decoder to mishandle size calculations. This integer overflow bypasses safety checks meant to prevent reading beyond allocated memory, potentially allowing the attacker to crash the application or extract sensitive data from memory. The attack requires user interaction: a victim must be tricked into opening the malicious file.

  • CVE-2026-52808HIGH 7.1

    Gogs, an open-source Git hosting platform, contains an authorization bypass vulnerability in three API endpoints that handle repository settings and operations. Write-level collaborators—users with limited repository permissions—can exploit these endpoints to disable critical repository features (issue tracker, wiki) or inject malicious URLs that would compromise other users visiting the repository. The vulnerability exists because these endpoints use weaker permission checks than the equivalent web interface, allowing attackers to escalate their effective privileges within a repository. Gogs 0.14.3 and later patch this issue.

  • CVE-2026-52915HIGH 7.1

    A flaw in the Linux kernel's IPv6 hop-by-hop header filtering allows a local attacker with standard user privileges to trigger an out-of-bounds array access. The vulnerability exists because the kernel accepts oversized option lists in netfilter rules without validating that they fit within the fixed 16-element array used to store them. An attacker can craft a malicious firewall rule to cause the kernel to read or write beyond array boundaries, potentially enabling privilege escalation or denial of service.

  • CVE-2026-52917HIGH 7.1

    A race condition exists in the Linux kernel's SCTP (Stream Control Transmission Protocol) diagnostic module that allows a local attacker with low privileges to crash the system or read sensitive kernel memory. The vulnerability arises when the kernel attempts to retrieve SCTP socket diagnostic information while an association is being freed, causing it to read from memory that has already been deallocated or modified. This results in either a denial of service or potential information disclosure.

  • CVE-2026-52942HIGH 7.1

    A flaw in the Linux kernel's netfilter logging subsystem allows a local attacker to read memory beyond allocated buffer boundaries. When the kernel logs network packets, it attempts to dump the MAC (media access control) header without properly verifying that the header information has been set. An attacker with local access can craft and send specially crafted packets through AF_PACKET with QDISC bypass enabled, causing the logging function to read approximately 64 KB past the intended buffer and leak that kernel memory into the system log. This information disclosure could expose sensitive kernel data to unprivileged users.

  • CVE-2026-52953HIGH 7.1

    A flaw in the Linux kernel's IOMMU (Input/Output Memory Management Unit) VT-d driver can crash a system when certain device assignment operations occur, particularly when QEMU virtual machines are terminated. The issue arises from the kernel trying to access memory beyond the bounds of a special internal structure called the 'blocked domain,' causing a protection fault that halts the affected process or system. This is a memory safety issue specific to how the kernel manages I/O device permissions and virtual machine configurations.

  • CVE-2026-52988HIGH 7.1

    A vulnerability exists in the Linux kernel's netfilter subsystem where the nf_tables module does not safely handle concurrent updates to firewall rules. When administrators modify firewall rules while the system is simultaneously retrieving rule information, a race condition can occur that may cause the kernel to crash or allow information disclosure. The issue stems from improper synchronization during the commit phase when new firewall hooks are added to the active rule list.

  • CVE-2026-53040HIGH 7.1

    A flaw in the Linux kernel's OCFS2 filesystem driver can be triggered when a user issues a specific diagnostic request (OCFS2_IOC_INFO with non-coherent mode) against a crafted filesystem. An attacker with local access can supply malformed filesystem metadata that causes the kernel to read memory outside the bounds of a bitmap structure, leading to a use-after-free condition. This can crash the system or potentially allow information disclosure. The vulnerability requires local access and standard user privileges to trigger.

  • CVE-2026-53041HIGH 7.1

    A flaw in how the Linux kernel's OCFS2 filesystem reports extended file attributes (xattrs) can cause a kernel crash when listing these attributes on files that store them in multiple locations. When a file's inline xattrs exactly fill a user's buffer and there are additional xattrs stored in blocks, the kernel incorrectly reports a size that exceeds the buffer and then attempts to write beyond it, triggering a kernel panic. This affects systems using OCFS2 as their filesystem, particularly in Oracle environments and high-availability clusters.