2026 · High
High-severity vulnerabilities disclosed in 2026
High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
1343 published vulnerabilities · page 6 of 14
- CVE-2017-20244HIGH 8.2
The Wow Forms WordPress plugin version 2.1 has a critical flaw that lets attackers steal sensitive information directly from a website's database without needing to log in. By sending specially crafted requests to the plugin's form-handling endpoint, an attacker can inject malicious SQL commands through the form ID parameter, bypassing the plugin's security controls and reading any database content they want—including user credentials, email addresses, and other confidential data.
- CVE-2017-20245HIGH 8.2
The Wow Viral Signups WordPress plugin version 2.1 contains a SQL injection flaw that allows attackers to steal data directly from your website's database without needing to log in. An attacker can craft a malicious request to the WordPress admin-ajax.php endpoint, inject SQL commands into the 'idsignup' parameter, and read sensitive information such as user credentials, email addresses, and other stored data. The vulnerability is trivial to trigger and requires no special privileges.
- CVE-2017-20246HIGH 8.2
The KittyCatfish 2.2 WordPress plugin contains a critical SQL injection flaw that allows anyone on the internet to steal data directly from the affected website's database without needing to log in. An attacker can manipulate a web request parameter to inject malicious SQL commands, then extract sensitive information—usernames, passwords, email addresses, or other stored data—by observing subtle timing differences or boolean responses from the server. No authentication or user interaction is required.
- CVE-2017-20247HIGH 8.2
WordPress sites running the PICA Photo Gallery plugin version 1.0 are vulnerable to SQL injection attacks. An attacker can manipulate the 'aid' parameter in GET requests to execute unauthorized database queries without needing to log in. This allows extraction of sensitive data such as WordPress user credentials and other database contents, posing a direct threat to site integrity and user privacy.
- CVE-2017-20249HIGH 8.2
Apptha Slider Gallery version 1.0 contains a critical SQL injection flaw that lets attackers without any authentication bypass the application and extract sensitive data directly from the database. By crafting malicious requests with poisoned parameters, attackers can pull user credentials and password hashes. The vulnerability requires no user interaction and is trivially easy to exploit over the network.
- CVE-2018-25382HIGH 8.2
Zechat 1.5 contains an SQL injection flaw in its profile.php endpoint that allows attackers to inject malicious SQL commands through the username parameter without authentication. By crafting specially formatted requests, an attacker can extract database structure information and sensitive data directly from the application's backend database.
- CVE-2018-25385HIGH 8.2
E-Registrasi Pencak Silat version 18.10 contains an SQL injection flaw that allows attackers without credentials to retrieve sensitive data from the application's database. By crafting malicious requests to the monitor_nilai.php endpoint, an attacker can inject SQL commands through the id_partai parameter to extract admin credentials, user records, and other protected information. No authentication is required to attempt this attack.
- CVE-2018-25386HIGH 8.2
HaPe PKH 1.1 contains multiple SQL injection flaws in its admin media management interface that allow attackers to inject malicious SQL commands and extract sensitive database information. Unauthenticated attackers can target the village module, while authenticated users can exploit several administrative modules. The vulnerability stems from improper handling of the 'id' parameter, enabling attackers to manipulate database queries and retrieve system-level data such as database credentials, names, and DBMS version details.
- CVE-2018-25389HIGH 8.2
HaPe PKH 1.1 is vulnerable to SQL injection through the 'nama_kelompok' parameter in the lap-anggota-kelompok-pdf.php endpoint. An attacker can send a specially crafted request without authentication to execute arbitrary SQL commands, enabling extraction of sensitive database information using time-based blind techniques. This is a direct-to-database attack that bypasses application logic entirely.
- CVE-2018-25390HIGH 8.2
HaPe PKH 1.1 is vulnerable to SQL injection through its lap-peserta-perdesa-pdf.php endpoint. An attacker can send a specially crafted request containing SQL code in the 'desa' POST parameter to manipulate database queries without authentication. Using time-based blind SQL injection techniques, an adversary can extract sensitive information from the underlying database by observing query response delays.
- CVE-2018-25394HIGH 8.2
Kados R10 GreenBee contains an SQL injection flaw that allows attackers without authentication to read sensitive database information by crafting malicious web requests. The vulnerability exists in a administrative function that fails to properly validate user input, enabling an attacker to embed SQL commands directly into the system's database queries. This could expose usernames, database names, and system version details.
- CVE-2018-25395HIGH 8.2
Kados R10 GreenBee contains a critical SQL injection flaw in its board feature management interface. An attacker without authentication can craft a specially formatted web request targeting the feature update function to inject arbitrary SQL commands directly into the database. This allows the attacker to read sensitive data like database credentials, user information, and system details—potentially exposing the entire database to compromise.
- CVE-2018-25398HIGH 8.2
CVE-2018-25398 is an unauthenticated SQL injection vulnerability in Open ISES Project version 3.30A. An attacker can craft malicious database queries and submit them through the frm_passwd parameter in POST requests to main.php, bypassing authentication entirely. This allows extraction of sensitive database contents—usernames, database names, system versions—without needing valid credentials. The vulnerability is remotely exploitable with no special conditions required.
- CVE-2018-25399HIGH 8.2
Open ISES Project version 3.30A contains an SQL injection flaw in its nearby.php endpoint that lets unauthenticated attackers inject malicious SQL commands through two URL parameters: tick_lat and tick_lng. An attacker can craft a simple GET request to extract sensitive information from the underlying database, such as usernames, database identifiers, and version numbers. No authentication is required, and exploitation is straightforward—making this a high-severity issue for any organization running this software.
- CVE-2018-25400HIGH 8.2
Open ISES Project version 3.30A contains an unauthenticated SQL injection vulnerability in its form submission endpoint. An attacker can craft malicious SQL code and send it through a web request to extract sensitive information from the application's database without needing valid credentials. The vulnerability requires no user interaction and can be exploited over the network, making it a significant remote threat.
- CVE-2018-25401HIGH 8.2
Open ISES Project version 3.30A is vulnerable to SQL injection through an unauthenticated web interface. An attacker can craft malicious database queries and send them via HTTP GET requests to the sever_graph.php endpoint, bypassing authentication entirely. This allows extraction of sensitive database schema and contents without legitimate access.
- CVE-2018-25402HIGH 8.2
Open ISES Project version 3.30A contains an SQL injection vulnerability accessible to unauthenticated attackers over the network. By crafting malicious SQL statements in the p1 parameter of GET requests to inc_types_graph.php, an attacker can query the underlying database directly, potentially exposing schema details, user records, and other sensitive stored data. The vulnerability requires no authentication or user interaction, making it relatively straightforward to exploit.
- CVE-2018-25403HIGH 8.2
A SQL injection vulnerability exists in Open ISES Project version 3.30A that allows attackers without authentication to inject malicious database commands through a web parameter. By crafting specially designed requests to the city_graph.php file, attackers can extract sensitive information from the underlying database, including schema details and other stored data. The vulnerability requires no user interaction and can be exploited over the network.
- CVE-2018-25404HIGH 8.2
Open ISES Project version 3.30A is vulnerable to SQL injection through its add_facnote.php endpoint. An attacker can craft malicious SQL code in the ticket_id parameter and send it via a GET request without needing to authenticate first. This allows the attacker to read sensitive data directly from the database, including version information and other confidential records. The vulnerability requires no special conditions—any internet-connected instance of the software is at risk.
- CVE-2018-25405HIGH 8.2
eNdonesia Portal version 8.7 is vulnerable to multiple SQL injection flaws that allow unauthenticated attackers to extract sensitive data directly from the database. An attacker can manipulate specific web parameters—artid, cid, did, contid, and aboutid in the mod.php file—to inject malicious SQL commands. This bypasses normal authentication and gives direct access to usernames, database credentials, and system version information without requiring any valid user account.
- CVE-2018-25406HIGH 8.2
eNdonesia Portal version 8.7 contains multiple SQL injection flaws that allow attackers without authentication to run arbitrary database commands. By inserting malicious SQL code into specific URL parameters—artid, cid, did, contid, and aboutid—across five different modules (publisher, diskusi, galeri, content, and about), attackers can extract sensitive information like database credentials and system version details. This is a network-based attack requiring no user interaction or prior access.
- CVE-2018-25407HIGH 8.2
eNdonesia Portal version 8.7 contains multiple SQL injection flaws in its mod.php file that allow attackers to inject malicious SQL commands without authentication. By crafting specially formed requests targeting parameters like artid, cid, did, contid, and aboutid across various portal modules (publisher, diskusi, galeri, content, about), an attacker can extract sensitive database information such as usernames, database names, and version details. No user interaction or authentication is required to exploit this vulnerability.
- CVE-2018-25411HIGH 8.2
MGB OpenSource Guestbook version 0.7.0.2 contains a flaw that allows attackers to inject malicious database commands into the application without needing to log in. By sending specially crafted web requests to the email.php file with harmful code embedded in the 'id' parameter, an attacker can read sensitive information directly from the database—including the names of tables and columns that store user data. This vulnerability requires no authentication, making it trivial for an external attacker to exploit.
- CVE-2018-25413HIGH 8.2
AiOPMSD Final version 1.0.0 contains an SQL injection flaw that allows attackers to execute unauthorized database queries without authentication. By crafting malicious SQL statements and sending them through the application's search function (search.php), an attacker can extract sensitive information such as database credentials, usernames, and system details. This is a network-based attack requiring no user interaction or special privileges.
- CVE-2018-25414HIGH 8.2
AiOPMSD Final version 1.0.0 contains a straightforward but serious SQL injection flaw in its actor.php endpoint. An attacker can craft malicious SQL code and send it through the actor parameter via a simple GET request—no authentication required—to execute arbitrary database queries. This allows them to extract sensitive information like database credentials, usernames, and version details directly from the backend database.
- CVE-2018-25415HIGH 8.2
AiOPMSD Final version 1.0.0 contains an unauthenticated SQL injection flaw in its director.php endpoint. An attacker can craft a malicious URL with SQL code injected into the director parameter and send it as a simple GET request—no login required. Once executed, the attacker gains unauthorized access to the database, potentially exposing usernames, database names, system version information, and other sensitive data. The vulnerability is trivial to trigger and requires no special tools or user interaction.
- CVE-2018-25416HIGH 8.2
AiOPMSD Final version 1.0.0 contains a SQL injection flaw that allows anyone on the internet to query the application's database directly without logging in. An attacker can craft malicious requests to the country.php endpoint to extract sensitive information such as usernames, database names, and version numbers. This is a straightforward injection attack—the application fails to sanitize user input before passing it to SQL queries.
- CVE-2018-25417HIGH 8.2
AiOPMSD Final 1.0.0 contains an unauthenticated SQL injection flaw in the quality.php endpoint. An attacker can craft a malicious GET request with a SQL payload in the quality parameter to run arbitrary SQL commands against the backend database, potentially exposing usernames, database identifiers, and version information without requiring any authentication or user interaction.
- CVE-2018-25418HIGH 8.2
AiOPMSD Final version 1.0.0 contains an SQL injection vulnerability in its year parameter that allows attackers to execute arbitrary database queries without authentication. By crafting malicious SQL code and sending it through GET requests to the year.php endpoint, an attacker can extract sensitive information such as usernames, database names, and database version details. The vulnerability requires no user interaction and can be exploited over the network by any unauthenticated actor.
- CVE-2018-25419HIGH 8.2
AiOPMSD Final 1.0.0 suffers from a critical SQL injection flaw in its genre parameter. An attacker can craft a malicious URL to genre.php and extract sensitive data—usernames, database names, version information—without needing to authenticate. The vulnerability is straightforward to exploit over the network and poses a real risk to confidentiality of stored data.
- CVE-2018-25420HIGH 8.2
AiOPMSD Final version 1.0.0 contains an SQL injection flaw that lets attackers query the application's database without needing any credentials. By crafting malicious SQL code into web requests targeting the watch.php endpoint, an attacker can extract sensitive data like user credentials and database structure information. The vulnerability requires no authentication, no special interaction from a victim, and poses a direct threat to data confidentiality.
- CVE-2018-25422HIGH 8.2
MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the id parameter in play.php. Attackers can craft malicious GET requests to extract sensitive data like usernames and other database information without needing authentication.
- CVE-2018-25424HIGH 8.2
Gate Pass Management System version 2.1 contains an SQL injection flaw in its login mechanism that allows attackers to bypass authentication entirely without knowing valid credentials. By crafting malicious SQL code into the login and password fields of the application's login form, an unauthenticated attacker can trick the system into granting access. This is a critical weakness because the login page is typically the first line of defense, and compromising it gives attackers full entry to the application and any data it manages.
- CVE-2018-25425HIGH 8.2
Yot CMS version 3.3.1 contains an unauthenticated SQL injection vulnerability accessible through HTTP GET requests. An attacker can manipulate the 'aid' or 'cid' URL parameters to inject arbitrary SQL commands, potentially exposing sensitive database information without requiring any authentication or user interaction. The vulnerability is network-accessible and relatively straightforward to exploit.
- CVE-2018-25428HIGH 8.2
Paroiciel version 11.20 contains an unauthenticated SQL injection flaw in its trec.php endpoint. An attacker can craft malicious web requests to the tRecIdListe parameter, inject arbitrary SQL commands, and retrieve sensitive database contents like table and column names without needing valid credentials. This is a remote attack that requires no special privileges or user interaction.
- CVE-2018-25433HIGH 8.2
The JE Photo Gallery component for Joomla version 1.1 contains a critical flaw that allows attackers to inject malicious SQL commands without needing credentials. By manipulating a parameter in web requests, attackers can extract sensitive information directly from the database, including user credentials. This vulnerability requires no authentication or user interaction, making it particularly dangerous for websites using this component.
- CVE-2018-25434HIGH 8.2
WP AutoSuggest version 0.24 contains a critical SQL injection flaw that lets attackers bypass authentication entirely and query your WordPress database directly. By sending specially crafted requests to the plugin's autosuggest.php endpoint, an attacker can extract sensitive data—posts, user information, and other database contents—without needing any WordPress account or permissions. This is particularly dangerous because the vulnerability requires no user interaction and is trivial to exploit remotely.
- CVE-2019-25726HIGH 8.2
All in One Video Downloader version 1.2 contains an SQL injection flaw that lets attackers query the application's database without authentication. By crafting malicious requests to the admin interface, adversaries can extract sensitive information like user credentials and database structure details. The vulnerability requires no special access or user interaction—attackers can exploit it remotely over the network.
- CVE-2019-25728HIGH 8.2
Care2x 2.7 contains a flaw that lets attackers bypass authentication entirely and read sensitive database information by modifying a cookie called ck_config. An attacker on the internet can craft a malicious request without any credentials to trick the application into executing unauthorized database queries. The vulnerability affects login pages and module endpoints, making it a straightforward way to extract private data.
- CVE-2019-25730HIGH 8.2
Listing Hub CMS version 1.0 contains a SQL injection flaw that allows attackers without credentials to run arbitrary database commands. By sending specially crafted requests to the pages.php file with malicious values in the id parameter, attackers can extract sensitive information such as database credentials and system version details. The vulnerability requires no authentication or user interaction, making it a straightforward attack vector for anyone with network access to the affected application.
- CVE-2019-25732HIGH 8.2
PHP EI-Tube Script 3 contains a flaw that allows attackers to inject malicious commands into the application's search function without needing any credentials. By crafting specially designed search queries, an attacker can trick the application into executing unauthorized database commands, potentially exposing usernames, passwords, and other sensitive information stored in the database.
- CVE-2019-25745HIGH 8.2
The Google Review Slider WordPress plugin version 6.1 contains a SQL injection flaw that allows attackers to execute unauthorized database queries without needing to log in. By crafting malicious requests targeting the 'tid' parameter, an attacker can gradually extract sensitive data from a WordPress site's database using time-based blind SQL injection—a technique where database response delays confirm whether injected queries are true or false. This vulnerability poses a direct risk to any WordPress installation running the affected plugin version.
- CVE-2021-4478HIGH 8.2
Dräger CC-Vision Basic (versions before 7.5.3) and Dräger CC-Vision E-Cal (versions before 7.2.5.0) are vulnerable to a buffer overflow when processing specially crafted .gdt files. An attacker can create a malicious file that, when opened by a user, causes the application to crash or potentially execute arbitrary code on the system. The vulnerability requires user interaction—someone must open the malicious file—but does not require elevated privileges to trigger.
- CVE-2021-4480HIGH 8.2
Dräger Protector Software before version 6.4.2 has a local privilege escalation flaw rooted in overly permissive file system permissions. An attacker with local access to an affected system can replace critical binaries or loaded modules, then trigger execution with NT SYSTEM privileges—the highest level of access on Windows. This gives an adversary complete control over the host.
- CVE-2021-4481HIGH 8.2
Dräger Protector Software versions prior to 6.4.2 suffer from a local privilege escalation flaw rooted in overly permissive file system permissions. An attacker with local access to an affected system can exploit this weakness to replace system binaries or loaded modules, ultimately executing arbitrary code with the highest privilege level (NT SYSTEM). This is a boots-on-the-ground attack: the attacker must have local file system access, but once they do, they can gain complete system control.
- CVE-2025-69755HIGH 8.2
A vulnerability in the Neterbit NW-431F Router (firmware version NW-431F-20241014-IR03) allows attackers on the network to read sensitive information and run unauthorized commands on the device. An attacker can send specially crafted requests to the router's at_command.asp interface without needing credentials or user interaction, making this a direct and urgent threat to any organization using this model.
- CVE-2026-10622HIGH 8.2
Collibra Agent contains a flaw in how it authenticates users to its REST API. The vulnerability allows someone from the internet to call administrative functions through REST endpoints without providing valid credentials. An attacker can exploit this to gain unauthorized access to sensitive functionality that should be restricted to authenticated administrators.
- CVE-2026-24088HIGH 8.2
CVE-2026-24088 is a cryptographic flaw in Qualcomm wireless and networking chipsets that allows a high-privileged attacker to bypass security controls and load a custom bootloader onto affected devices. The vulnerability stems from improper validation during firmware partition processing, enabling unauthorized modification of the boot sequence. This could allow an attacker with administrative or hardware-level access to inject malicious code that executes before the operating system, potentially taking complete control of the device.
- CVE-2026-24751HIGH 8.2
Kiteworks, a platform used to securely share and manage sensitive business data, contains a reflected cross-site scripting (XSS) vulnerability in its Secure Data Forms feature. An attacker can craft a malicious link that, when clicked by a legitimate user, causes the victim's browser to execute arbitrary JavaScript code within the context of the Kiteworks application. This could allow the attacker to steal session cookies, impersonate the user, or perform unauthorized actions on their behalf. The vulnerability affects all versions of Kiteworks prior to 9.3.0.
- CVE-2026-24752HIGH 8.2
Kiteworks, a private data network platform, contains a reflected cross-site scripting (XSS) flaw in its Secure Data Forms component that could allow an attacker to inject malicious JavaScript. An attacker could craft a deceptive link and trick a user into clicking it, causing the user's browser to execute arbitrary code in the context of their Kiteworks session. This is a social engineering attack vector rather than a direct infrastructure compromise, but the impact can be severe if the victim has administrative or sensitive data access.
- CVE-2026-28299HIGH 8.2
SolarWinds Web Help Desk contains a denial-of-service vulnerability that allows attackers to crash the server by exhausting memory resources. No authentication or user interaction is required—an attacker on the network can trigger this condition remotely, making it straightforward to exploit. While the vulnerability does not expose sensitive data or allow unauthorized changes to the system, the ability to take down your help desk platform creates immediate business disruption.
- CVE-2026-35675HIGH 8.2
phpMyFAQ versions before 4.1.3 contain a critical flaw in their password reset mechanism that completely bypasses authentication checks. An attacker does not need valid credentials or access to a victim's email to reset passwords—they can simply request a password reset for any user account, and the system grants it without verification. This means attackers can take over any account, including administrator accounts, giving them full control of the FAQ system and potentially the underlying server.
- CVE-2026-35676HIGH 8.2
phpMyFAQ versions before 4.1.3 contain a critical flaw that allows anyone on the internet to reset user account passwords without authentication. An attacker can enumerate valid usernames and email addresses, then forcibly change passwords by sending direct API requests. This bypasses normal security controls and immediately locks legitimate users out of their accounts.
- CVE-2026-37234HIGH 8.2
FlexRIC v2.0.0 contains a resource management flaw in how it handles SCTP (Stream Control Transmission Protocol) connections to the RIC (Radio Interface Controller). An attacker can abuse the E42 setup protocol to register multiple application IDs (xapp_ids) over a single connection. When that connection is closed, only the first registered application's resources are cleaned up; the others remain as orphaned entries in system memory. Over time or through repeated connections, this allows an attacker to accumulate stale subscriptions and exhaust available resources, potentially corrupting the internal state of the intelligent application platform (iApp).
- CVE-2026-41010HIGH 8.2
BOSH Director is vulnerable to arbitrary command execution when processing uploaded release tarballs. An attacker with elevated privileges can craft a malicious release manifest that embeds shell metacharacters in a job name. When the system unpacks the tarball, these characters are interpreted by the shell, allowing the attacker to execute arbitrary commands with the privileges of the BOSH Director process. The vulnerability stems from unsafe string interpolation of untrusted input directly into a shell command.
- CVE-2026-41011HIGH 8.2
BOSH (the Cloud Foundry deployment automation framework) contains a shell injection vulnerability in its package validation logic. When a user uploads a release tarball containing a malicious package name, the system executes that name as a shell command without sanitization. An authenticated attacker with upload privileges can inject arbitrary commands that run with BOSH director privileges. The vulnerability exists because validation occurs after the dangerous shell operation, not before.
- CVE-2026-41249HIGH 8.2
CoreShop, a Pimcore-based eCommerce platform, contains a critical flaw in its GitHub Actions workflow configuration that allows attackers to execute arbitrary code on build infrastructure. The vulnerability stems from a workflow that accepts pull requests from untrusted sources but then executes scripts using code from those unverified pull requests. An attacker can simply submit a malicious pull request to trigger code execution on CoreShop's CI/CD runners, potentially compromising the build pipeline, stealing credentials, or injecting malicious code into releases.
- CVE-2026-43624HIGH 8.2
F5-TTS versions up to 1.1.20 contain a path traversal vulnerability in their finetune Gradio interface that lets unauthenticated attackers write files anywhere on the server's filesystem. The flaw stems from inadequate validation of project names before they're used in file system operations. An attacker can bypass the intended directory boundary by supplying absolute paths (like /tmp/EVIL) and create malicious files with arbitrary content in locations the web server can access. No authentication is required to exploit this.
- CVE-2026-44358HIGH 8.2
Espressif's Shared GitHub DangerJS Action, a reusable CI workflow component, contains a privilege escalation vulnerability in versions prior to 1.0.1. When processing pull requests from forks, the action's entrypoint script executes DangerJS from an untrusted search path after copying fork code into the working directory. This allows fork-supplied code to run inside the action container with the permissions of the workflow, rather than the action's own trusted code. An attacker can exploit this by submitting a malicious pull request from a fork, causing arbitrary code execution in the CI/CD environment.
- CVE-2026-44822HIGH 8.2
Microsoft Office Excel contains an out-of-bounds read vulnerability that allows a remote attacker to extract sensitive information from a user's system without authentication or user interaction. The flaw affects multiple Microsoft Office products across different versions and deployment models. An attacker could exploit this by crafting a malicious Excel file or triggering the vulnerability over a network, potentially exposing confidential data.
- CVE-2026-45302HIGH 8.2
parse-nested-form-data is a Node.js library that converts web form submissions into structured JavaScript objects and arrays. Versions before 1.0.1 contain a prototype pollution vulnerability: if an attacker submits a form field with a name like `__proto__` or containing `.__proto__.` anywhere in it, the parser inadvertently modifies JavaScript's Object.prototype. This pollutes the prototype chain for every plain object created in the application afterward, potentially corrupting application logic, exposing sensitive data, or enabling denial of service.
- CVE-2026-45327HIGH 8.2
TinyIce is vulnerable to unauthenticated stream injection on its WebRTC ingest endpoint. An attacker without credentials can inject audio or video streams into a live broadcast, potentially disrupting service, contaminating streams with malicious content, or hijacking active broadcasts. The vulnerability affects versions 0.8.95 through 2.4.1. Patching to version 2.5.0 or later adds mandatory authentication using HTTP Basic Auth or a password query parameter, backed by bcrypt verification and brute-force protection.
- CVE-2026-45476HIGH 8.2
A use-after-free flaw in the Linux MANA network driver used by Microsoft Azure allows a user with high-level system privileges to escape their confined context and gain full control over the system. Because the vulnerability requires the attacker to already have elevated privileges, the immediate attack surface is limited to administrative users or services running with high permissions—but successful exploitation would allow them to achieve complete system compromise.
- CVE-2026-45545HIGH 8.2
Nextcloud Tables contains a SQL injection vulnerability that allows authenticated users with Tables app access to execute SQL queries beyond the intended 20-byte limit. By crafting specially formed input, attackers can bypass this constraint and run arbitrary database commands to steal sensitive information or alter data. The vulnerability affects multiple Nextcloud versions and has been resolved in patched releases.
- CVE-2026-45615HIGH 8.2
CVE-2026-45615 is a memory safety flaw in asn1c, an open-source ASN.1 compiler used to generate code that parses structured data formats. The vulnerability exists in the OER (Octet Encoding Rules) decoder template files generated by asn1c version 1.4 and earlier. When the generated decoder encounters a specially crafted, zero-length OER payload representing a variable-length non-negative integer, it attempts to read the Most Significant Bit without first validating that the payload contains sufficient bytes. This causes a precise one-byte out-of-bounds heap read. Since asn1c-generated parsers are commonly deployed to process untrusted network data—including automotive V2X protocols, 5G telecommunications headers, and X.509 certificates—a remote attacker can trigger this flaw by sending a malicious network message, potentially causing the application to crash or misinterpret critical security-relevant integers.
- CVE-2026-45627HIGH 8.2
Arcane, a Docker container management interface, contains a reflected cross-site scripting (XSS) vulnerability in its unauthenticated logo endpoint. An attacker can craft a malicious URL containing injected CSS or JavaScript that gets reflected into an SVG document served to a logged-in admin user. When the admin visits this link, the injected script executes in the browser with full access to Arcane's origin, including HttpOnly session cookies, potentially leading to complete account compromise. The vulnerability exists because the endpoint does not properly escape user input and the application lacks protective HTTP headers. This issue is resolved in Arcane version 1.19.0.
- CVE-2026-46303HIGH 8.2
A vulnerability exists in the Linux kernel's ISO 9660 filesystem (isofs) Rock Ridge extension handler. When processing a specially crafted ISO image, the kernel fails to validate that continuation extent block numbers fall within the mounted volume's boundaries. An attacker with the ability to mount a malicious ISO—either through unprivileged auto-mounting via udisks2 on a desktop, or through privileged mount access—can cause the kernel to read data from arbitrary blocks on the same device. While memory safety is preserved because out-of-range reads cleanly fail, reads into adjacent filesystems can leak directory metadata through symbolic link text exposed to userspace. This is a validation gap in an existing security check that should have been closed alongside prior CE (continuation extent) fixes.
- CVE-2026-46509HIGH 8.2
The deepobj library contains a prototype pollution vulnerability that allows attackers to manipulate JavaScript object prototypes through specially crafted property paths. When an application uses deepobj to get, set, or delete nested object properties—and exposes the property path to attacker input—an attacker can inject payloads using __proto__, constructor, or prototype keywords to corrupt the prototype chain. This can lead to unexpected behavior, denial of service, or in certain contexts, code execution. The vulnerability was resolved in version 1.0.3.
- CVE-2026-46510HIGH 8.2
form-data-objectizer is a Node.js library that converts HTML form data into JavaScript objects. Versions prior to 1.0.1 contain a prototype pollution vulnerability. An attacker can craft an HTTP form submission with a specially-named field (beginning with __proto__) that causes the library to overwrite Object.prototype—the base template all JavaScript objects inherit from. This single malicious form field corrupts the entire Node.js process, allowing an attacker to inject arbitrary properties into all objects, potentially leading to authentication bypass, data manipulation, or application crashes.
- CVE-2026-47652HIGH 8.2
A memory defect in Windows Hyper-V can allow someone with high-level system access to run malicious code on an affected machine. The flaw resides in how the hypervisor manages heap memory, leaving a window for buffer overflow attacks that bypass normal protections. This is a serious but constrained threat: exploitation requires administrative or hypervisor-level credentials, meaning it's not a remote vulnerability and the attacker must already have substantial control of the system.
- CVE-2026-49491HIGH 8.2
Pixa Bank 2.0 contains an SQL injection flaw that lets attackers without credentials steal sensitive customer data directly from the database. By crafting malicious requests to a specific endpoint, attackers can extract names, email addresses, and phone numbers. The vulnerability requires no authentication, no user interaction, and can be exploited over the network, making it a serious exposure for any organization running this software.
- CVE-2026-50205HIGH 8.2
Acer Connect M6E 5G routers log SMTP authentication passwords and employee identification data in plaintext system logs. Any user or attacker with access to the device's log files can read these credentials and sensitive corporate information without any decryption step. This is a straightforward credential exposure issue that poses immediate risk to email security and employee privacy.
- CVE-2025-53440HIGH 8.1
CVE-2025-53440 is a PHP Local File Inclusion (LFI) vulnerability in Axiomthemes Confidant that allows an attacker to manipulate file path inputs, potentially leading to the inclusion and execution of arbitrary files on the affected server. The vulnerability stems from improper validation of filenames used in PHP include/require statements. An attacker can exploit this over the network without authentication to read sensitive files or execute malicious code, posing a significant risk to websites using vulnerable versions of Confidant.
- CVE-2025-58705HIGH 8.1
CVE-2025-58705 is a PHP Local File Inclusion (LFI) vulnerability in Axiomthemes Crafti through version 1.12. An attacker can exploit improper filename validation in PHP include/require statements to include and execute arbitrary local files on the server. This allows remote code execution without authentication, making it a critical risk for any organization running vulnerable Crafti installations. The vulnerability has a CVSS 3.1 score of 8.1 (HIGH severity) with network accessibility and high impact across confidentiality, integrity, and availability.
- CVE-2025-58707HIGH 8.1
CVE-2025-58707 is a file inclusion vulnerability in Axiomthemes Spin that allows attackers to include and execute arbitrary local files on the server. By manipulating input parameters, an unauthenticated attacker can reference files outside the intended directory, potentially exposing sensitive data or executing malicious code. The vulnerability affects Spin versions up through 1.8 and carries a CVSS score of 8.1, reflecting its severity.
- CVE-2025-58897HIGH 8.1
Axiomthemes Fermentio contains a vulnerability that allows attackers to include and execute arbitrary PHP files from the local server, potentially leading to unauthorized access, data theft, or system compromise. The vulnerability stems from insufficient validation of filenames used in PHP include/require statements, enabling attackers to manipulate file paths without authentication. Versions up to and including 1.5.0 are affected.
- CVE-2025-59874HIGH 8.1
HCL Hive Telco Observability contains a Content Security Policy (CSP) configuration weakness in its Keycloak authentication component. The application is missing critical CSP directives that browsers rely on to prevent injection attacks. This gap creates conditions for attackers to inject malicious scripts or styles if they can trick users into visiting a compromised or attacker-controlled page, potentially compromising session tokens or stealing sensitive observability data.
- CVE-2025-68886HIGH 8.1
A vulnerability in androThemes Cookiteer plugin allows an attacker to include and execute arbitrary local files through improper input handling in PHP include/require statements. While the vulnerability is classified as a Local File Inclusion (LFI) rather than true Remote File Inclusion, the network-accessible nature of web plugins means an unauthenticated attacker can exploit this remotely to read sensitive files or potentially execute code, depending on file availability and server configuration. All versions through 1.4.8 are affected.
- CVE-2025-69369HIGH 8.1
CVE-2025-69369 is a file inclusion vulnerability in Axiomthemes Racquet versions up to 1.12.0 that allows an attacker to manipulate how the application loads files, potentially executing arbitrary code or accessing sensitive data on the server. The flaw stems from insufficient validation of file paths in PHP include/require statements, making it possible to load unintended files from the local filesystem or, in some configurations, from remote sources.
- CVE-2026-10863HIGH 8.1
A vulnerability in MISP's correlations endpoint allowed authenticated users to manipulate how search results were ordered by injecting values into the order parameter. Rather than applying a server-defined sort, the application accepted user input that could be passed unsafely to the database layer. An attacker with valid credentials could exploit this to reorder results in ways the application designers didn't intend, potentially exposing information through creative query construction or gaining visibility into data the endpoint should have restricted.
- CVE-2026-10887HIGH 8.1
A use-after-free flaw in Chrome's Chromoting remote desktop feature on macOS allows attackers to execute arbitrary code by sending specially crafted network traffic. The vulnerability exists in versions prior to 149.0.7827.53 and requires no user interaction—an attacker on the network can trigger the bug remotely, making this a critical threat to any Mac user running an affected Chrome version.
- CVE-2026-10930HIGH 8.1
An out-of-bounds read vulnerability in ANGLE (the graphics translation layer used by Chrome on macOS) allows attackers to read sensitive memory from your system by tricking you into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.53 on Apple macOS. While the attacker cannot directly modify data or take control of your system through this specific vulnerability, they can extract confidential information—including passwords, encryption keys, or other sensitive data stored in memory—and cause Chrome to crash.
- CVE-2026-11011HIGH 8.1
A flaw in Google Chrome's Password Manager allows an attacker who has already compromised the browser's renderer process to sidestep site isolation—a critical security boundary that prevents one website from accessing data belonging to another. By crafting a malicious HTML page, the attacker could potentially access sensitive information across different sites. This vulnerability affects Chrome versions before 149.0.7827.53 and requires the attacker to first gain control of the renderer process, which typically happens through a separate exploit or malicious website.
- CVE-2026-11015HIGH 8.1
A memory reading flaw in Google Chrome's WebGPU component allows attackers to read data outside the intended memory boundaries when a user visits a specially crafted website. The vulnerability requires user interaction (visiting a malicious page) but does not require special privileges, and while the attacker cannot modify data or directly crash the browser, they can extract sensitive information from the process's memory—such as passwords, keys, or other confidential data stored there.
- CVE-2026-11111HIGH 8.1
A memory reading vulnerability exists in Chrome's graphics engine (ANGLE) that allows attackers to access out-of-bounds data on a victim's system. An attacker could craft a malicious webpage that, when visited, leaks sensitive information from the browser's memory without modifying or corrupting system data. This affects Chrome versions prior to 149.0.7827.53. The vulnerability requires user interaction—a person must visit the malicious page—but once there, the attacker gains read access to protected memory regions.
- CVE-2026-11169HIGH 8.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how they process XML files that allows attackers to inject malicious scripts or HTML content into a webpage, even when normal security protections should prevent it. An attacker would need to trick a user into opening a specially crafted XML file, but once successful, the injected code can execute with the same privileges as the user, potentially stealing data or taking other harmful actions. The vulnerability affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-11170HIGH 8.1
Google Chrome on Linux contains a vulnerability in its Chromoting feature (the remote desktop capability) that allows an attacker on the network to gain administrative privileges on your system without needing to interact with you. The vulnerability exists in Chrome versions before 149.0.7827.53. While the Chromium project rates this as medium severity, the actual impact—unauthenticated remote privilege escalation—warrants a CVSS score of 8.1 (HIGH), reflecting the seriousness for Linux desktop environments where Chromoting might be enabled.
- CVE-2026-11185HIGH 8.1
A use-after-free flaw in the V8 JavaScript engine affects Google Chrome versions before 149.0.7827.53. The vulnerability requires an attacker to trick a user into installing a malicious Chrome extension, which can then execute arbitrary code within the browser's sandbox. While the Chromium project rated this as Medium severity, the CVSS score of 8.1 reflects the high potential impact on confidentiality and integrity. This is a memory safety issue that leverages social engineering to gain code execution capabilities.
- CVE-2026-11224HIGH 8.1
A use-after-free vulnerability in Google Chrome's Chromoting remote desktop feature on Linux systems can allow an attacker to execute arbitrary code on a victim's machine through specially crafted network traffic. The attacker does not need any special privileges or user interaction beyond network access. This is a critical flaw in the remote desktop protocol handling that leaves systems open to full code execution compromise.
- CVE-2026-11231HIGH 8.1
Google Chrome on macOS contains a flaw in its Safe Browsing feature that could allow an attacker to run malicious code on a user's computer. The vulnerability requires user interaction—specifically, the user must open or interact with a malicious file. While Chromium's security team classified the underlying issue as low severity, the CVSS score of 8.1 reflects the real-world impact: an attacker gaining code execution on the system. This affects Chrome versions prior to 149.0.7827.53 on macOS.
- CVE-2026-11416HIGH 8.1
MoviePilot, a media download application, has a critical flaw in how it handles files downloaded from cloud storage services like AliPan, U115, and Rclone. When a file is downloaded, the application takes the filename provided by the cloud service and directly uses it to determine where to save the file locally. An attacker who compromises or manipulates the cloud storage metadata can craft a filename containing path traversal sequences (like ../) to trick MoviePilot into writing files outside the intended download directory. This could allow overwriting sensitive application files, configuration files, or plugins, potentially compromising the entire system.
- CVE-2026-11643HIGH 8.1
A use-after-free vulnerability exists in Google Chrome's Proxy component that could allow attackers to execute arbitrary code on victim machines through specially crafted network traffic. The flaw affects Chrome versions prior to 149.0.7827.103 and has been rated as Critical by the Chromium security team. While no active exploitation has been confirmed in the wild, the vulnerability's remote nature and code execution potential make it a significant threat requiring prompt patching.
- CVE-2026-11689HIGH 8.1
A vulnerability in Google Chrome versions before 149.0.7827.103 allows an attacker who has already compromised Chrome's renderer process to break through site isolation—Chrome's security boundary that keeps websites from accessing each other's data. An attacker would need to trick a user into visiting a malicious webpage after the renderer is already compromised, but if successful, they could read or modify sensitive information across different websites.
- CVE-2026-11693HIGH 8.1
Google Chrome versions before 149.0.7827.103 contain a flaw in how plugins are handled that allows a remote attacker to break through Chrome's site isolation security boundary. Site isolation is Chrome's defense mechanism that keeps different websites in separate processes to prevent one compromised site from accessing data from another. An attacker who has already compromised the renderer process—the part of Chrome that executes web pages—can craft a malicious HTML page to bypass this isolation, potentially gaining unauthorized access to sensitive data from other open websites or sessions.
- CVE-2026-24065HIGH 8.1
Waves Central for macOS contains a vulnerability that allows a local attacker to gain root-level access through a race condition in how the application validates connections. The vulnerable software trusts connections based on process IDs, which the operating system can reuse for different applications. An attacker can exploit the timing gap between when a connection is requested and when the validation occurs, tricking the privileged helper service into executing commands with administrator rights. This affects versions 13.0.9 through 16.5.5, and the issue is resolved in version 16.6.2.
- CVE-2026-35076HIGH 8.1
A vulnerability in MBS Solutions gateway and protocol-conversion products allows authenticated users to delete files from the affected system without proper authorization. The flaw exists in the 'bac-scanresult' method, which fails to validate user-supplied input adequately. An attacker who has legitimate credentials can exploit this to remove critical files, potentially disrupting system operations or causing data loss.
- CVE-2026-35077HIGH 8.1
A vulnerability in MBS Solutions gateway products allows authenticated users to delete files they shouldn't have access to. An attacker with valid user credentials can exploit the ugw-delete-file method to remove arbitrary files from affected systems by bypassing input validation controls. This is especially concerning in industrial automation environments where these gateways often handle critical protocol conversions and data flows.
- CVE-2026-35078HIGH 8.1
A vulnerability in MBS Solutions gateway products allows authenticated users to delete files from affected systems without proper authorization. An attacker with valid user credentials can exploit the ugw-logstop method to remove arbitrary files, potentially disrupting system operations or destroying evidence. This is classified as a high-severity flaw because it requires only standard user access and can cause significant damage to system integrity and availability.
- CVE-2026-35079HIGH 8.1
CVE-2026-35079 is a file deletion vulnerability in MBS Solutions' Universal Gateway firmware and related gateway products. An attacker who already has valid user credentials can exploit the ugw-restore method to delete arbitrary files on the device. Because the vulnerability requires existing user access, the risk depends heavily on your organization's internal security posture and whether these devices are exposed to untrusted users.
- CVE-2026-35080HIGH 8.1
A flaw in MBS Solutions gateway firmware allows authenticated users to delete files they shouldn't have access to. An attacker with valid login credentials can exploit the ugw-restoreinfo method to remove arbitrary files from affected devices, potentially disrupting operations or destroying critical system data. The vulnerability requires existing user privileges but poses a serious risk to the integrity and availability of gateway-based infrastructure.