By year

Vulnerabilities disclosed in 2026

CVEs published in 2026 with SEC.co analysis.

4824 published vulnerabilities · page 47 of 49

  • CVE-2019-25723MEDIUM 4.0

    Dräger Perseus A500 ventilators running software versions 2.00 through 2.02 are vulnerable to a denial-of-service attack. An attacker on the network can send malformed data through the Medibus medical interface to crash the device's processor, forcing a warm restart. During this restart—which lasts several seconds—ventilation pressure drops to ambient level, temporarily interrupting therapy delivery before the device recovers. This is a network-accessible vulnerability with no authentication required, making it a genuine concern for clinical environments.

  • CVE-2019-25734MEDIUM 4.0

    Contact Form by WD version 1.13.1 has a security flaw that combines two weaknesses: a cross-site request forgery (CSRF) vulnerability and local file inclusion (LFI). An unauthenticated attacker can craft a malicious web form that, when visited by an admin, tricks the admin's browser into loading arbitrary files from the server using directory traversal sequences. This bypasses the normal authentication checks on certain WordPress AJAX actions, potentially exposing sensitive files.

  • CVE-2021-4479MEDIUM 4.0

    Dräger Atlan A350 patient monitoring devices running firmware versions 1.00 through 1.01 are vulnerable to a denial-of-service attack delivered through the Medibus network interface. An attacker can send malformed data packets that the device fails to validate properly, causing the internal processor to become overloaded. Over several hours, this degradation manifests as loss of data transmission capability, delays in displaying vital sign curves, and discrepancies between measured airway pressure and displayed values—conditions that could compromise clinical decision-making in critical care settings.

  • CVE-2026-10099MEDIUM 4.0

    XX-Net V5.16.6 has a flaw in how it processes WebSocket communications that causes data corruption. When a client sends WebSocket frames without proper masking, the server incorrectly interprets the first 4 bytes of the message as a mask key (even when masking wasn't used), then mangles the rest of the data by applying the wrong decryption. This results in corrupted data being processed by the application. The vulnerability affects local attack scenarios and has medium severity.

  • CVE-2026-10998MEDIUM 4.0

    CVE-2026-10998 is a memory safety issue in Google Chrome's media handling code that allows an attacker positioned on the same local network to read data from memory locations they shouldn't have access to. The vulnerability exists in Chrome versions before 149.0.7827.53. An attacker would need to send specially crafted network traffic to trigger an out-of-bounds read, which could potentially expose sensitive information resident in the browser's memory. This is a local-network-only threat, meaning the attacker must be on your network segment to exploit it.

  • CVE-2026-28581MEDIUM 4.0

    A logic error in Android's call processing code allows an application to initiate emergency calls without proper authorization checks. The vulnerability stems from inadequate validation in the CallIntentProcessor when determining the initiating user, potentially enabling an app to trigger emergency dialing functionality that should be restricted. No user interaction is required for exploitation, and the issue affects multiple Android versions.

  • CVE-2026-41714MEDIUM 4.0

    Spring AMQP applications that connect to RabbitMQ brokers using AMQPS URIs without explicitly enabling SSL validation are vulnerable to man-in-the-middle attacks. While the connection appears encrypted, the application skips critical TLS certificate and hostname verification steps, allowing an attacker to intercept credentials and sensitive message data. This occurs when developers configure RabbitConnectionFactoryBean with an amqps:// URI but omit the setUseSSL(true) call, creating a false sense of security.

  • CVE-2026-45536MEDIUM 4.0

    Netty, a widely-used Java network framework, has a file descriptor leak in its Unix domain socket implementation when handling multi-fd messages. When a peer sends a crafted control message carrying multiple file descriptors via SCM_RIGHTS, Netty's receiver allocates a fixed buffer that happens to fit the kernel's response exactly. The code then performs a validation check that fails due to the unexpected message format, causing the installed file descriptors to never be closed. Applications using DomainSocketChannel with FILE_DESCRIPTORS read mode—a non-default opt-in feature—can leak two file descriptors per malicious message received from a peer on the same host. This degrades availability by exhausting the process's file descriptor limit.

  • CVE-2026-46559MEDIUM 4.0

    ImageMagick, a widely used open-source image editing tool, contains a flaw in how it validates JP2 (JPEG 2000) image files. When processing certain malformed JP2 files, the software writes a single byte of data beyond the boundaries of an allocated memory region. While limited to overwriting one byte, this heap buffer overflow could cause the application to crash or, in specific configurations, enable an attacker to influence program behavior. The issue affects ImageMagick versions before 6.9.13-48 and 7.1.2-23.

  • CVE-2026-53464MEDIUM 4.0

    ImageMagick versions before 7.1.2-25 leak a small amount of memory when the wand option parser receives invalid input. An attacker with local access could trigger this repeatedly to consume system memory and degrade performance or cause denial of service. The issue is low-impact but present in all affected versions.

  • CVE-2026-30963LOW 3.9

    Capsule is a Kubernetes framework that uses webhooks to prevent tenant administrators from hijacking namespaces—essentially taking control of cluster resources they shouldn't own. The framework checks most update requests, but it misses two specific APIs (namespace/status and namespace/finalize subresources) that can also change namespace ownership markers. Before version 0.13.0, a tenant admin with permission to use these subresources could bypass the webhook protection and seize a namespace. Version 0.13.0 patches this gap by ensuring the webhook intercepts both subresource types.

  • CVE-2026-45642LOW 3.9

    CVE-2026-45642 affects Microsoft's Azure Attestation and Device Health Attestation services, which are used to verify the integrity and trustworthiness of devices and systems. The vulnerability stems from inadequate validation of user-supplied input, allowing an attacker who already has physical access and elevated privileges on a target system to spoof attestation results. This means an attacker could make a compromised or malicious device appear legitimate to systems that rely on attestation checks. The attack requires both physical proximity to the device and administrative-level access, significantly limiting real-world exposure.

  • CVE-2025-12656LOW 3.8

    The WPvivid Backup & Migration plugin for WordPress contains a vulnerability that allows administrators to inadvertently (or maliciously) delete arbitrary directories from the server. The flaw lies in insufficient validation of file paths when canceling a staging site, meaning an authenticated admin could specify any folder path and have it removed. This is restricted to high-privilege accounts, but the impact—permanent data loss—is serious for affected organizations.

  • CVE-2026-10299LOW 3.8

    CVE-2026-10299 is a resource identifier control vulnerability in code-projects Online Hospital Management System version 1.0. An authenticated attacker with high-level privileges can manipulate the 'delid' parameter in the viewdoctortimings.php file to cause unintended modifications or deletion of data. While the flaw requires administrative or high-privilege access and carries a low CVSS score, the availability of public exploit code warrants attention in environments running this system.

  • CVE-2026-40510LOW 3.8

    OpenSC, a widely-used open-source smart card library, contains a stack buffer overflow flaw in how it processes the Key History Object from PIV (Personal Identity Verification) cards. An attacker with physical access to a system could craft a malicious smart card or USB device that returns an oversized URL field—exceeding 118 bytes—triggering memory corruption. This vulnerability requires the attacker to be physically present at the machine and involves user interaction, limiting its reach but posing a real concern in environments where untrusted hardware may be connected.

  • CVE-2026-40528LOW 3.8

    OpenSC, a widely-used open-source library for working with smart cards and cryptographic tokens, contains a buffer overflow vulnerability in its profile configuration parser. When OpenSC's pkcs15-init tool processes a maliciously crafted configuration file, it can be tricked into copying more data than a buffer can hold, corrupting memory. An attacker would need local access to supply the malicious file and convince a user to run the initialization tool, but successful exploitation could allow memory corruption and potential code execution.

  • CVE-2026-45683LOW 3.8

    OpenTelemetry eBPF Instrumentation versions prior to 0.9.0 contain a memory disclosure vulnerability in the Java TLS monitoring probe. The vulnerability stems from incorrect kernel memory access calls that allow a local attacker to read sensitive kernel memory and exfiltrate it through the instrumentation telemetry pipeline. This is a localized information disclosure risk that requires local process-level access to exploit.

  • CVE-2026-53809LOW 3.8

    OpenClaw versions prior to 2026.4.25 contain a policy bypass flaw that weakens access controls for bundled development tools. When an attacker has local access to a system running the embedded runner feature, they can use provider aliases (alternative names for tool repositories) to bypass intended restrictions on which tools they're allowed to use. The vulnerability is context-specific—it only affects configurations where this feature is explicitly enabled—but it does allow unauthorized tool selection outside policy boundaries.

  • CVE-2026-56212LOW 3.8

    Capgo versions before 12.128.2 contain a flaw in how they enforce two-factor authentication policies. A team or organization administrator can mandate that all team members use two-factor authentication, but the system doesn't check whether the administrator themselves has 2FA enabled first. This creates a gap where security policy enforcement becomes inconsistent and opens the door to administrative misuse—an admin could lock team members out of their accounts by enforcing a security requirement they haven't met themselves.

  • CVE-2026-6816LOW 3.8

    Drupal's TFA Basic Plugins module contains a flaw that allows administrators with user management permissions to access or create recovery codes intended for other users. This bypasses the expected access controls around two-factor authentication recovery mechanisms. The vulnerability is restricted to versions 7.x-1.0 through 7.x-1.2, and exploitation requires administrative privileges, limiting its immediate threat to environments where admin accounts are already compromised or where trust boundaries have been violated.

  • CVE-2025-52609LOW 3.7

    HCL iControl is missing HTTP security headers that would instruct modern web browsers to block cross-site scripting (XSS) attacks. Without these headers—such as Content-Security-Policy or X-XSS-Protection—the application relies on older browser XSS filters that are inconsistently implemented and increasingly deprecated. An attacker could craft malicious input that, when processed by iControl, gets reflected in responses without proper sanitization, potentially allowing script execution in users' browsers.

  • CVE-2026-10169LOW 3.7

    A weakness in the password recovery feature of OUSL-GROUP-BrinaryBrains School Student Management System allows an attacker to manipulate the email parameter in the forgot password function, potentially leading to unauthorized password resets or account takeover. The vulnerability exists in the Login.php controller's ajax_forgot_password endpoint. While exploitable remotely, the attack requires specific conditions and is considered of low severity. Exploit code is publicly available, increasing risk of opportunistic attacks.

  • CVE-2026-10216LOW 3.7

    A vulnerability has been discovered in unitedbyai droidclaw version 0.5.3 and earlier that weakens authentication security on the claim endpoint. The flaw allows attackers to bypass rate limiting or account lockout protections during login attempts, potentially enabling brute-force attacks to guess user credentials. While a public exploit exists, the attack requires specific conditions and technical skill to execute successfully. The vendor has been notified but has not yet released a fix.

  • CVE-2026-10300LOW 3.7

    SGLang version 0.5.10.post1 contains a vulnerability in its inference HTTP endpoint that can be triggered by manipulating the lora_path argument. When an attacker provides a specially crafted lora_path value, the system reaches an assertion condition that causes the service to become unavailable. This is a remote vulnerability requiring network access, though the attack is complex to execute and not trivial to exploit in practice.

  • CVE-2026-10636LOW 3.7

    Zephyr's IPv4 IGMP implementation contains a use-after-free vulnerability in its packet handling logic. After sending an IGMP message, the code attempts to read network interface information from a packet that may have already been freed and returned to memory pools by the network driver or stack. This can happen because the packet's last reference is released during transmission, but the code still tries to access it afterward. The issue is reachable by sending IGMP membership queries to the multicast address 224.0.0.1, or through local multicast operations, without requiring authentication. The practical result is typically unpredictable system behavior, potential crashes, or corruption of network statistics counters.

  • CVE-2026-11525LOW 3.7

    Undici, a Node.js HTTP client library, incorrectly parses the SameSite attribute in Set-Cookie headers. Instead of validating that the attribute is exactly 'Strict', 'Lax', or 'None' as the HTTP specification requires, undici accepts any value containing one of those words as a substring and silently converts it to the closest match. This means a server sending a malformed cookie like 'SameSite=NoneOfYourBusiness' will be treated as 'None'—the least restrictive setting—potentially weakening the security properties applications expect from SameSite enforcement.

  • CVE-2026-11555LOW 3.7

    A privilege escalation vulnerability exists in D-Link's DGS-1100-08PD switch running firmware version 1.00.006. The issue resides in how the web interface processes the /etc/boa.conf configuration file, potentially allowing an attacker to modify system settings in ways that bypass normal access restrictions. While a public exploit exists, successful exploitation requires significant technical skill and specific conditions to align. The impact is limited to integrity violations—an attacker cannot read sensitive data or crash the device, only make unauthorized configuration changes.

  • CVE-2026-11956LOW 3.7

    A flaw in TwiN gatus 5.36.0's OIDC session cookie handler can result in session cookies being created without the secure attribute. This means cookies could be transmitted over unencrypted HTTP connections, exposing them to interception. An attacker would need to manipulate the application's session management flow, a process requiring significant technical effort and complex conditions to exploit. While not currently listed on CISA's Known Exploited Vulnerabilities catalog, the issue warrants attention for any deployment handling sensitive authentication flows.

  • CVE-2026-24761LOW 3.7

    CVE-2026-24761 is an authorization flaw in Kiteworks Secure Data Forms that allows authenticated users to view metadata belonging to other users. Because the system doesn't properly verify who owns a resource before allowing access, a legitimate user can craft requests to retrieve information about files and documents they shouldn't see. The vulnerability requires an attacker to already have valid credentials and involves a higher complexity of exploitation, which limits its risk profile. This affects Kiteworks versions before 9.3.0.

  • CVE-2026-41000LOW 3.7

    Spring Web Services has a flaw in how it manages replay protection for SOAP messages. When security administrators configure protection against replay attacks—where an attacker re-uses old, valid authentication tokens or timestamps—the system doesn't always enforce those protections correctly. An attacker could potentially replay old username tokens, timestamps, or certain SAML assertions to bypass authentication, even though the operator believed replay protection was active. This is a configuration gap: the replay cache exists but isn't consistently connected to the validation logic that needs it.

  • CVE-2026-41694LOW 3.7

    Spring Security's SAML module decrypts encrypted SAML messages without first verifying they contain a valid digital signature. An attacker can craft malicious SAML responses or logout messages, send them to a vulnerable application, and observe how the application behaves when decrypting attacker-controlled data. By analyzing these responses, an attacker could potentially extract encryption keys or other sensitive information that the application decrypts. This is a low-severity issue because exploitation requires specific conditions and yields limited information exposure.

  • CVE-2026-41848LOW 3.7

    Spring Framework's AntPathMatcher component is susceptible to a Regular Expression Denial of Service (ReDoS) attack. If an attacker can control or influence URL path patterns processed by the matcher, they can craft a malicious pattern that causes excessive CPU consumption, potentially degrading application performance or availability. This vulnerability affects multiple actively supported versions of Spring Framework spanning several release lines.

  • CVE-2026-41852LOW 3.7

    Spring Expression Language (SpEL) in VMware Spring Framework contains a flaw that allows attackers to invoke arbitrary methods with zero arguments even in contexts designed to restrict or prevent such actions. An attacker with network access could exploit this to trigger unintended application logic, potentially leading to denial of service or information disclosure depending on available methods and application design. This affects multiple versions across the 5.3, 6.1, 6.2, and 7.0 release branches.

  • CVE-2026-42768LOW 3.7

    OpenSSL's CMS and S/MIME decryption functions contain a flaw that allows attackers to exploit error messages or decryption output to gradually recover encrypted data or forge signatures. The vulnerability exists in two forms: when no recipient certificate is provided, an attacker can craft a message with multiple encryption layers to probe for valid padding patterns; when a certificate is provided but doesn't match, OpenSSL substitutes a random key, which an attacker can use to compare results and refine attacks. The practical risk is low because exploiting it requires the victim's application to expose detailed error codes or decryption results to an untrusted attacker, a scenario OpenSSL's developers consider very unlikely in real-world deployments.

  • CVE-2026-42770LOW 3.7

    A weakness in OpenSSL's handling of X9.42 Diffie-Hellman key exchanges allows a malicious peer to forge domain parameters in a way that bypasses security validation. Specifically, when checking that a peer's public key belongs to the correct mathematical subgroup, OpenSSL uses the peer's own parameters instead of verifying against the local key's parameters. An attacker can exploit this to gradually recover fragments of a victim's private key through repeated key exchange attempts, ultimately reconstructing the entire key via mathematical combination. However, the practical risk is limited to specific scenarios: principally Certificate Management Protocol (CMP) deployments where a Certification Authority or Registration Authority maintains long-lived X9.42 DHX keys, and custom enterprise or government applications using static DHX keys in interactive protocols.

  • CVE-2026-44489LOW 3.7

    Axios, a widely-used HTTP client library for JavaScript, contains a prototype pollution vulnerability in its configuration merging logic. When a developer uses Axios with a proxy configuration, an attacker can pollute the Object.prototype to inject fake username and password values. These polluted values are then automatically included in Proxy-Authorization headers sent with every proxied HTTP request, potentially leaking attacker-controlled credentials or disrupting authentication. The vulnerability affects Axios versions 1.15.2 through 1.15.x and is resolved in version 1.16.0.

  • CVE-2026-44546LOW 3.7

    Daphne, a popular ASGI server for Django applications, contains a header parsing vulnerability that allows attackers to inject additional HTTP headers into requests under specific conditions. The issue arises from a mismatch in how Daphne and the underlying WebSocket library (autobahn) interpret certain whitespace characters as line separators. By crafting requests with specific byte sequences in header values, an attacker can inject headers that the application receives, potentially leading to security bypasses depending on application logic. Daphne versions before 4.2.2 are affected. The vulnerability has a low CVSS score (3.7) and requires specific conditions to exploit, but organizations running affected versions should still apply the patch.

  • CVE-2026-44743LOW 3.7

    CVE-2026-44743 is a low-severity information disclosure vulnerability in SAP Business Objects that allows unauthorized attackers to leak sensitive data through a specific application endpoint. The vulnerability requires specific conditions to be exploitable and does not affect system integrity or availability—only the confidentiality of information is at risk.

  • CVE-2026-48011LOW 3.7

    Shopware, a popular open-source e-commerce platform, contains a timing-based vulnerability that allows an attacker to discover the usernames of administrator accounts without authentication. By measuring response times during login attempts, an attacker can infer whether a given username belongs to an administrator by observing slight differences in how the system processes valid versus invalid accounts. This is a low-severity issue because it only leaks usernames—not passwords—and requires network access and careful measurement to exploit.

  • CVE-2026-48524LOW 3.7

    PyJWT, a widely-used Python library for handling JSON Web Tokens (JWTs), contains a weakness in how it fetches public signing keys. When a JWT arrives with an unfamiliar key identifier (kid), the library will make a fresh HTTP request to retrieve the correct signing key—without any protection against repeated requests for the same unknown identifier. An attacker can exploit this by sending JWTs with different fake kid values, forcing the library to make outbound requests for each one. While the actual impact depends on whether the signing-key endpoint has its own rate limiting or becomes saturated, the vulnerability allows an attacker to potentially cause a denial-of-service condition through request amplification. This issue is resolved in PyJWT 2.13.0 and later.

  • CVE-2026-48709LOW 3.7

    OliveTin is a web application that lets users execute predefined shell commands through a browser interface. Versions up to 3000.0.0 contain a flaw where one specific API endpoint (ValidateArgumentType) skips authentication checks that all other endpoints perform. When the application is configured to require login for guest users—a stricter security posture—this endpoint remains openly accessible to anyone on the network, allowing attackers to discover which shell commands are available and learn their argument requirements without needing credentials.

  • CVE-2026-48931LOW 3.7

    Node.js has a flaw in how its HTTP Agent handles client-server communication. The vulnerability allows a client to incorrectly accept a server response that arrives before the client has actually sent its request. While the window for exploitation is narrow and requires specific timing conditions, it represents a logic error in the HTTP protocol implementation that could lead to subtle application behavior issues. This affects the three currently supported Node.js release lines.

  • CVE-2026-53537LOW 3.7

    Python-Multipart before version 0.0.30 contains a header parsing vulnerability that could allow an attacker to bypass security controls. The library uses email message parsing for Content-Disposition and Content-Type headers, which automatically decodes RFC 2231/5987 extended parameter syntax (like filename*=). This decoding is not supposed to happen in multipart form data per the relevant RFC standard. An attacker can craft a specially formatted header that gets decoded differently by the vulnerable library than by upstream security tools (WAFs, proxies), potentially smuggling through a different field name or filename than inspectors expect. The risk is relatively low because successful exploitation requires specific conditions and produces only minor integrity issues, not data exposure or system unavailability.

  • CVE-2026-53538LOW 3.7

    Python-Multipart versions before 0.0.30 contain a parser differential vulnerability in how they handle form-encoded data. The library treats semicolons (;) as field separators in form submissions, while modern standards—including web browsers and Python's built-in URL parser—only recognize ampersands (&) as separators. An attacker can exploit this mismatch to inject additional form fields that bypass security inspections performed by upstream components, such as web application firewalls or input validators. The attacker doesn't need special privileges or user interaction, though the attack requires specific conditions to trigger successfully.

  • CVE-2026-53540LOW 3.7

    Python-Multipart, a streaming multipart parser library, contains a vulnerability in how it handles the Content-Length header when parsing form submissions. Before version 0.0.31, the parser fails to validate whether the Content-Length value is valid. An attacker who can send a request with a negative Content-Length header can force the parser to read the entire request body into memory at once, rather than processing it in manageable chunks. This memory exhaustion condition can cause the application to become unresponsive or crash.

  • CVE-2026-53607LOW 3.7

    ApostropheCMS contains a server-side request forgery (SSRF) vulnerability in its file-serving feature. When the 'prettyUrls' option is enabled—a legitimate SEO feature for cleaner file URLs—the system incorrectly trusts the HTTP Host header sent by clients. An attacker can exploit this to make the ApostropheCMS server fetch content from arbitrary hosts on your internal network, potentially revealing information about your network topology and any verbose error messages from internal systems. The vulnerability is present in ApostropheCMS versions 4.30.0 and earlier. While the attacker cannot directly steal file contents across different instances, they can perform network reconnaissance and potentially trigger information disclosure from misconfigured internal services.

  • CVE-2026-53837LOW 3.7

    OpenClaw versions before 2026.5.6 contain a flaw in how they handle Mattermost event processing that allows attackers to bypass direct message (DM) policy restrictions. The vulnerability exists because the application fails to properly check channel type metadata when processing incoming events. An attacker can craft malicious Mattermost events that omit channel type information, causing the application to incorrectly process content that should have been restricted. While the potential impact is limited, this represents an integrity issue that could allow policy circumvention.

  • CVE-2026-5419LOW 3.7

    A timing vulnerability has been discovered in GnuTLS, a widely-used encryption library. When the library decrypts data protected with PKCS#7 padding, the padding verification process takes different amounts of time depending on the content of the padding bytes. An attacker with network access could measure these timing differences to infer information about the padding, potentially revealing details about encrypted messages. This is a subtle flaw that requires precise network-level observation to exploit, making it a low-risk issue in most environments, but one that sophisticated attackers targeting high-value communications might attempt.

  • CVE-2026-54282LOW 3.7

    Starlette versions prior to 1.3.0 contain a flaw in how they reconstruct the request URL from incoming HTTP requests. When a malicious HTTP request contains a path that doesn't start with a forward slash (such as @google.com), the URL parsing logic gets confused about where the authority (hostname) section ends and treats attacker-supplied content as the hostname. Applications that trust the reconstructed request.url.hostname value instead of validating the actual Host header can be tricked into accepting requests as if they came from a different domain. An attacker could exploit this to bypass hostname-based access controls or mislead applications in authentication decisions.

  • CVE-2026-55654LOW 3.7

    OpenSSH contains a memory safety bug in its GSSAPI authentication handler that can crash the SSH service. When processing Kerberos-based authentication, a missing safety check allows the code to read beyond allocated memory, causing the authentication process to fail and temporarily disable SSH access. This only affects deployments using GSSAPI/Kerberos authentication and requires specific network conditions to trigger.

  • CVE-2026-6976LOW 3.7

    GitLab has patched a vulnerability affecting versions 15.9 through 19.0.1 that allowed authenticated developers to manipulate file names in merge requests, potentially hiding code changes from reviewers. The issue requires a developer-level account and specific interaction steps, making it a low-severity concern primarily relevant to organizations where code review integrity is a priority or where insider risk is elevated.

  • CVE-2026-10766LOW 3.6

    MLRun versions up to 1.12.0-rc3 contain a weakness in how they hash dataframes. The vulnerable function in mlrun/utils/helpers.py uses cryptographic methods that are considered inadequate for security purposes. An attacker with local access to a system running MLRun could potentially manipulate or forge data integrity checks, though doing so requires significant technical effort and local privileges. The vulnerability is not currently listed as actively exploited in the wild, but proof-of-concept details have been publicly disclosed.

  • CVE-2026-10775LOW 3.6

    CVE-2026-10775 is a denial-of-service vulnerability in SGLang's cache handling mechanism. An attacker with local system access and user-level privileges can trigger a crash or service interruption by exploiting the data_hash function in the cache handler. The attack requires specific knowledge of the system's cache internals, making it moderately difficult to execute, though proof-of-concept code has been publicly disclosed.

  • CVE-2026-10800LOW 3.6

    PaddlePaddle FastDeploy versions up to 2.4.1 contain a weakness in how the MultimodalHasher component generates hashes for multimodal features. An attacker with local system access and user-level privileges could manipulate the hash_features function to use cryptographically weak hashing, potentially allowing them to forge or predict hash values. This is a low-severity issue that requires both local access and significant technical effort to exploit.

  • CVE-2026-10801LOW 3.6

    A weakness in how ModelScope's ms-swift library (versions up to 4.2.0) hashes cached PIL images creates a local integrity risk. An attacker with local system access and user-level privileges could manipulate image cache validation, potentially leading to cache poisoning or image substitution. The vulnerability requires significant technical effort to exploit and poses limited immediate threat in most environments, but should be addressed before deployment in sensitive workflows.

  • CVE-2026-10803LOW 3.6

    MLflow versions up to 3.10.0 contain a cryptographic weakness in the Dataset Digest Computation module. The vulnerability uses an insufficiently strong hash function for dataset digest operations, which could allow an attacker with local system access and user-level privileges to tamper with dataset integrity checks or trigger application errors. Exploitation requires significant technical effort and local presence on the affected machine.

  • CVE-2026-10804LOW 3.6

    Streamlit versions up to 1.53.0 contain a weak cryptographic hashing vulnerability in its palette handler component. An attacker with local system access and authenticated user privileges can manipulate the hashing function to produce predictable or non-unique hash values, potentially allowing them to bypass integrity checks or cause minor application disruptions. The attack is complex and requires deep knowledge of the affected code path, making opportunistic exploitation unlikely. However, the vulnerability is not currently tracked as an active threat on CISA's Known Exploited Vulnerabilities catalog.

  • CVE-2026-10812LOW 3.6

    GPTCache versions up to 0.1.44 contain a weakness in how it hashes image data used for cache key generation. An attacker with local access to a system running vulnerable GPTCache can manipulate image input parameters to exploit weak cryptographic hashing, potentially causing data integrity issues. The attack requires elevated complexity to execute and is not considered an immediate threat to most deployments, but organizations using GPTCache for image processing should monitor for patches.

  • CVE-2026-10813LOW 3.6

    LMCache versions up to 0.4.6 contain a cryptographic weakness in the KV Cache Handler component, specifically in how it converts hash values to integers. An attacker with local system access could manipulate this weak hash function to potentially compromise data integrity or availability. However, exploiting this requires significant technical complexity and local access privileges, limiting its practical risk in most environments.

  • CVE-2026-11329LOW 3.6

    CVE-2026-11329 is a low-severity weakness in ONNX MLIR's node cache handler that uses weak cryptographic hashing in the hash key generation function. The vulnerability requires local access and elevated privileges to exploit, making it a restricted-scope risk. An attacker with local user permissions could manipulate the hash mechanism to cause minor integrity issues or availability disruptions, but the attack is difficult to execute in practice and does not compromise confidentiality.

  • CVE-2026-11330LOW 3.6

    A cryptographic weakness has been discovered in thedotmack claude-mem versions up to 11.0.1. The Observation Content Hash Handler component uses an insufficiently strong hashing algorithm when processing observation data, which could allow a local attacker with user-level access to manipulate or forge content hashes under specific conditions. This is a localized vulnerability with limited practical exploitability but should be remediated in environments where hash integrity is critical.

  • CVE-2026-41974LOW 3.6

    CVE-2026-41974 is a permission control flaw in a service notification system that could be exploited to impact system availability. The vulnerability requires local access and user interaction to trigger, but does not require elevated privileges. The attack surface is confined to the notification subsystem, and successful exploitation would degrade service performance or cause temporary unavailability rather than expose sensitive data or grant unauthorized access.

  • CVE-2026-45380LOW 3.6

    bit7z is a C++ library used for archive compression and extraction. Before version 4.0.12, it contained a one-byte error in how it handles symlinks when extracting 7z archives on non-Windows systems. An attacker could craft a malicious archive that creates a symlink pointing outside the intended extraction directory. Once that symlink exists, subsequent files from the same archive could be written to arbitrary locations on the system, potentially overwriting important files or placing malicious content where it will be executed.

  • CVE-2026-50568LOW 3.6

    Fission, an open-source serverless framework for Kubernetes, contained a path validation flaw that could allow a tenant with local access to read or write files outside an intended safe directory. The vulnerability stems from a lexical string comparison that doesn't respect directory boundaries—for example, a directory named '/packages-extra' would incorrectly pass validation meant for '/packages'. An attacker who can pre-create or control a sibling directory in the shared storage volume could exploit this to access sensitive files. This affects versions prior to 1.25.0 and has been patched.

  • CVE-2022-48575LOW 3.5

    CVE-2022-48575 is a local bypass vulnerability in macOS that allows someone with physical access to a Mac to circumvent the Login Window security prompt. The issue stems from inconsistent state handling in the authentication system—essentially, the login screen may fail to properly enforce its security state in certain conditions, potentially allowing unauthorized access. Apple has patched this in macOS Monterey 12.4 and later.

  • CVE-2025-15619LOW 3.5

    HCL Connections has a broken access control flaw that creates a narrow but real window for unauthorized viewing of sensitive data. An authenticated attacker can, under specific conditions and with user interaction, bypass intended access restrictions and view information they shouldn't be able to access. The vulnerability is not network-exploitable without valid login credentials, and the exposure is limited to a single defined scenario rather than widespread data exposure.

  • CVE-2026-0129LOW 3.5

    A missing bounds check in Android's RTCP (Real-time Transport Control Protocol) Bye packet decoder can expose sensitive information to an authenticated attacker. The vulnerability requires user interaction to trigger and affects only confidentiality; no system crash or modification is possible. This is a low-severity information disclosure issue that primarily concerns privacy of real-time communications data.

  • CVE-2026-0130LOW 3.5

    CVE-2026-0130 is a low-severity vulnerability affecting Google Android that allows an attacker to read sensitive data from device memory through a malformed network packet. The flaw exists in the RtcpChunk decoder, which fails to properly validate buffer boundaries before reading data. An attacker must trick a user into accepting or opening a specially crafted media stream or communication session to trigger the vulnerability. Successful exploitation results in disclosure of locally stored information but does not enable device compromise, privilege escalation, or data modification.

  • CVE-2026-10228LOW 3.5

    A cross-site scripting (XSS) vulnerability exists in the raisulislamg4 student_management_system_by_php project. The flaw resides in the admission_form_check.php file, where user input passed through the Message parameter is not properly sanitized before being reflected in the web response. An authenticated attacker can craft malicious input that, when viewed by another user, executes arbitrary JavaScript in their browser. The vulnerability requires user interaction (clicking a malicious link) and affects only the integrity of data, not confidentiality or availability. Public exploit details are available, though the CVSS 3.5 score reflects the relatively constrained attack scenario requiring authentication and browser-based execution.

  • CVE-2026-10234LOW 3.5

    Mettle sendportal versions up to 3.0.1 contain a cross-site scripting (XSS) vulnerability in the Campaign Handler component. An authenticated attacker can inject malicious scripts through the content parameter in the /webview/ endpoint, potentially allowing them to steal session cookies, perform actions on behalf of users, or redirect users to malicious sites. The vulnerability requires user interaction to be effective and does not grant direct administrative access. Exploit code is publicly available, elevating practical risk despite the low CVSS score.

  • CVE-2026-10244LOW 3.5

    SourceCodester Pharmacy Sales and Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in the medicine name creation function. An authenticated user can inject malicious script code through the medicine_name parameter, which executes in the context of other users' browsers. The vulnerability requires user interaction (clicking a link or visiting a page) to trigger, and an attacker must have valid login credentials to exploit it. Public exploits are now available.

  • CVE-2026-10245LOW 3.5

    SourceCodester Pharmacy Sales and Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in its supplier creation functionality. An authenticated user can inject malicious code through the company name field when creating a supplier record. This code executes in the browsers of other users who view the supplier information, potentially allowing attackers to steal session tokens, redirect users to malicious sites, or perform unauthorized actions on their behalf. Public exploits for this vulnerability are already available.

  • CVE-2026-10246LOW 3.5

    A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An authenticated user can inject malicious scripts through the medicine presentation creation function, which are then executed in the browsers of other users who view that data. The attack requires user interaction and does not grant elevated privileges, but can be used to steal session tokens, redirect users, or perform actions on their behalf within the application.

  • CVE-2026-10247LOW 3.5

    A cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An authenticated attacker can inject malicious scripts through the generic_name parameter in the create_generic_name function, which the application will then execute in users' browsers. This could allow the attacker to steal session cookies, hijack user accounts, or manipulate pharmacy data. The vulnerability requires user interaction to trigger and an authenticated account to exploit, limiting its immediate impact, but public exploit code is now available.

  • CVE-2026-10264LOW 3.5

    CVE-2026-10264 is a path traversal vulnerability in lharries whatsapp-mcp version 0.0.1, located in the SendMessageRequest function of the Send API Endpoint. An attacker with local access and user privileges can manipulate the mediaPath argument to traverse the file system and read sensitive files, though exploitation impact is limited to information disclosure. The vulnerability has been publicly disclosed.

  • CVE-2026-10567LOW 3.5

    A stored cross-site scripting (XSS) vulnerability exists in 1Panel-dev CordysCRM versions up to 1.4.1. An authenticated attacker can inject malicious JavaScript into the Description field of the ModuleFormController, which will execute in the browsers of other users who view the affected module form. The vulnerability requires user interaction (viewing the crafted form) to trigger, and does not grant the attacker direct access to sensitive data or system functions. Upgrading to version 1.7.0 resolves the issue.

  • CVE-2026-11511LOW 3.5

    Bolt CMS versions up to 3.7.5 contain a vulnerability in how it handles HTML attributes within text fields. An authenticated attacker can manipulate the 'style' argument to inject arbitrary HTML code, potentially affecting the visual presentation or behavior of a web page. The vulnerability requires user interaction (a user must view the injected content) and authentication, limiting its immediate risk. However, because Bolt CMS is no longer actively maintained, affected organizations should plan transitions away from this platform.

  • CVE-2026-11520LOW 3.5

    SourceCodester Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in the header.php file that allows authenticated users to inject malicious scripts through multiple parameters. An attacker with valid credentials can craft a specially crafted request to inject JavaScript that executes in the browsers of other users, potentially stealing session data or performing unauthorized actions on their behalf. Public exploit code is available, increasing the practical risk despite the low CVSS score.

  • CVE-2026-11534LOW 3.5

    A cross-site scripting (XSS) vulnerability exists in imvks786's student_management_system application. The flaw allows attackers to inject malicious scripts through the name, address, or fname parameters in the /add.php file. An attacker with authenticated access can craft a malicious request that, when clicked by another user, executes arbitrary JavaScript in that user's browser. The vulnerability is publicly known, and the development team has been notified but has not yet responded with a patch.

  • CVE-2026-12047LOW 3.5

    pgAdmin 4's cloud deployment wizard contains an HTML injection vulnerability in its AWS, Azure, and Google Cloud credential-verification endpoints. When pgAdmin receives an error message from a cloud provider's API (such as a rejected AWS access key), it forwards that error text directly into the web interface without removing HTML tags. An authenticated attacker can craft a malicious credential submission containing HTML/iframe code; when the cloud provider rejects it and echoes back the attacker's input in its error message, pgAdmin displays that message in the wizard—parsing it as HTML. This allows the attacker to inject an iframe pointing to a malicious site, redirecting the victim's browser away from pgAdmin. The vulnerability requires the attacker to be an authenticated pgAdmin user and requires user interaction (submitting the malicious credential). Redirecting another user would require an additional cross-site request-forgery vector.

  • CVE-2026-12129LOW 3.5

    CodeAstro Human Resource Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its Dashboard Interface. An attacker with login credentials can inject malicious scripts through the todo_data parameter in the /dashboard/add_tod endpoint. When another authenticated user views the affected page, the injected script executes in their browser, potentially allowing credential theft, session hijacking, or unauthorized actions performed on their behalf. The vulnerability requires user interaction—specifically, a victim must visit a page containing the malicious payload—and can only be exploited by someone with valid system access.

  • CVE-2026-12130LOW 3.5

    CVE-2026-12130 is a reflected cross-site scripting (XSS) vulnerability in CodeAstro Human Resource Management System version 1.0. An authenticated user can inject malicious scripts through the 'protitle' parameter on the Projects Management Page, which are then executed in the browsers of other users who view the injected content. The vulnerability requires user interaction (a victim must click a crafted link) and does not grant an attacker elevated privileges or direct data access, which limits its severity. However, it can be used to steal session cookies, redirect users, or perform actions on behalf of authenticated users within the HR system.

  • CVE-2026-12812LOW 3.5

    Radware Cyber Controller versions up to 10.11.0 contain an HTML injection vulnerability in the HTML Report Generation component. An authenticated attacker can inject malicious HTML code that will be rendered in reports viewed by other users. While the vulnerability requires an existing login and user interaction to exploit, the public disclosure and lack of vendor response increase risk. The flaw allows manipulation of report content and appearance but does not enable direct data theft or system crashes.

  • CVE-2026-35068LOW 3.5

    Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection vulnerability that allows a low-privileged attacker with network access to the same segment to query the database directly and extract sensitive information. While the attacker needs valid credentials and local network access, the flaw bypasses input validation on database commands, potentially exposing configuration data, credentials, or operational metrics stored in PowerFlex deployments.

  • CVE-2026-45159LOW 3.5

    Nextcloud's end-to-end encrypted file drop feature contained a logic flaw that allowed a user with drop-link access to place files into other encrypted folders owned by the share recipient—without being able to read or modify existing files. The vulnerability affects multiple version lines and has been patched across all active branches.

  • CVE-2026-45266LOW 3.5

    A flaw in Nextcloud allows any authenticated user to remotely mute other participants' microphones during calls, but only when the deployment lacks a High-performance Backend configuration. This is a low-severity integrity issue that affects call participants' ability to communicate via audio.

  • CVE-2026-48190LOW 3.5

    OTRS has a permission-handling flaw in its External Interface and ConfigItem List module that allows authenticated customers to access Configuration Item (CI) information they shouldn't be able to see. The vulnerability only manifests when both CMDB is enabled and CustomerGroupSupport is configured, meaning organizations using default or simpler OTRS setups may not be affected. An attacker would need valid customer credentials and user interaction to exploit this issue.

  • CVE-2026-48191LOW 3.5

    A permissions bug in OTRS and STORM-powered OTRS allows authenticated users to discover metadata about configuration items (CIs), SLA levels, and services—such as how many are affected—without having actual access to view or modify them. An attacker needs valid login credentials and must interact with the Document Search Article Meta Filters modules to extract this information. While the exposure is limited to metadata disclosure rather than data access, it can provide reconnaissance value to an insider threat or compromised account holder.

  • CVE-2026-48288LOW 3.5

    Adobe Experience Manager contains a flaw in how it validates user input that can allow a logged-in attacker to bypass certain security controls and gain unauthorized write permissions. The attacker must trick a victim into visiting a malicious link or interacting with a compromised page, making this a lower-risk issue in practice. Affected versions include 6.5.24, LTS SP1, 2026.04 and earlier.

  • CVE-2026-48289LOW 3.5

    Adobe Experience Manager contains a vulnerability in how it validates user input that could allow a low-privileged attacker to bypass security controls and gain unauthorized write access to content. The attack requires the victim to visit a malicious link or interact with a compromised webpage, making it a practical but not trivial threat in environments where AEM is exposed to users. This is not currently listed as exploited in the wild.

  • CVE-2026-8981LOW 3.5

    The Custom Block Builder WordPress plugin before version 4.3.0 fails to properly validate user permissions when handling block template code in certain scenarios. This allows site administrators—particularly on WordPress multisite networks or single-site installations with `DISALLOW_UNFILTERED_HTML` enabled—to inject malicious JavaScript into block templates. When visitors load pages containing these blocks, the injected code executes in their browsers, potentially compromising user sessions or stealing sensitive information.

  • CVE-2026-9060LOW 3.5

    The Store Locator WordPress plugin before version 1.6.6 contains a stored cross-site scripting (XSS) vulnerability in its admin settings. An administrator or similarly privileged user can inject malicious JavaScript into one of the plugin's settings, which is then executed when other high-privileged users (such as network super admins on multisite installations) visit the admin page. This bypasses WordPress's standard HTML filtering protections that normally prevent such attacks.

  • CVE-2026-9061LOW 3.5

    The Store Locator WordPress plugin versions prior to 1.6.9 contain a stored cross-site scripting (XSS) vulnerability in how it handles store logo metadata. An administrator or other high-privileged user can inject malicious scripts through the store logo field that will execute when viewed on the plugin's admin page. This remains exploitable even in environments where HTML filtering is normally disabled, such as WordPress multisite networks. The vulnerability requires administrator-level access to exploit, limiting its scope but still representing a control bypass concern in restricted environments.

  • CVE-2026-9269LOW 3.5

    Administrators and high-privilege users of the Secure Copy Content Protection and Content Locking WordPress plugin (versions before 5.1.5) can inject malicious scripts into the plugin's settings that persist in the database and execute in other users' browsers. This stored cross-site scripting (XSS) vulnerability bypasses WordPress's standard HTML filtering restrictions, even in restrictive multisite environments where the unfiltered_html capability is intentionally disabled.

  • CVE-2026-49370LOW 3.4

    JetBrains YouTrack versions before 2026.1.13162 contain an information disclosure vulnerability affecting the fetchApp request handler. An authenticated user with high privileges can trigger unintended data exposure through a request that includes user interaction, though the scope of disclosed information is limited. This is a low-severity issue that requires administrative or privileged account access to exploit.

  • CVE-2026-49381LOW 3.4

    CVE-2026-49381 is a stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity's SAML login page that existed prior to version 2026.1. An attacker with high privileges could inject malicious scripts into the login interface, which would then execute in the browsers of users who interact with that page. The vulnerability requires user interaction to trigger and has limited scope, affecting only the confidentiality of information visible to the victim during their session.

  • CVE-2026-9062LOW 3.4

    The Store Locator WordPress plugin versions before 1.6.9 contain a path traversal vulnerability that allows site administrators to read sensitive files from the server, such as PHP configuration files containing database credentials and authentication keys. The vulnerability requires an authenticated administrator account to exploit, limiting its immediate risk to insider threats or compromised admin accounts.

  • CVE-2025-48616LOW 3.3

    CVE-2025-48616 is a logic error in Android's KeyguardViewMediator that allows a local attacker with basic user privileges to bypass lockdown mode when screen pinning is active, potentially exposing sensitive information on the device. The vulnerability requires no user interaction and poses a localized risk to data confidentiality on affected Android devices.

  • CVE-2025-62338LOW 3.3

    CVE-2025-62338 is a low-severity vulnerability in HCL BigFix Cloud Lifecycle Management caused by insufficient input validation. An authenticated local user can exploit this flaw to bypass security controls and access sensitive information they shouldn't have permission to view. The issue does not allow attackers to modify data or crash the system, only to read information they're not authorized to access.

  • CVE-2026-0016LOW 3.3

    A permissions validation flaw in Android's credential management system allows a local attacker with limited user privileges to read sensitive information across other user accounts without special permissions or user interaction. The vulnerability resides in how the system handles credential provider updates when services are removed, creating a bypass that exposes data intended to be isolated between users.