By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 66 of 86
- CVE-2026-11818MEDIUM 5.4
WPCafe, a popular WordPress plugin for restaurant management, contains a flaw that allows low-privilege users to perform actions restricted to administrators. Specifically, any logged-in user with subscriber access or higher can create, modify, or delete automated notification workflows—a capability meant only for site administrators. The vulnerability exists because the plugin relies on a single check (a REST API nonce) that is publicly visible in the webpage source, making it trivial for any authenticated user to bypass intended restrictions.
- CVE-2026-12084MEDIUM 5.4
IBM DevOps Deploy (UCD) contains a Cross-Origin Resource Sharing (CORS) misconfiguration that allows attackers to trick authenticated users into performing unauthorized actions or exposing sensitive data. The vulnerability affects versions 8.1 through 8.1.2.6 and 8.2 through 8.2.1.0. Because CORS policies are not properly restricting trusted domains, an attacker can host a malicious webpage that, when visited by a logged-in DevOps Deploy user, silently executes privileged operations or exfiltrates information in the user's security context.
- CVE-2026-12298MEDIUM 5.4
A memory safety vulnerability was discovered in Mozilla Firefox and Thunderbird that allows an attacker to read or modify memory during user interaction with a malicious website or email. The flaw does not enable remote code execution or denial of service, but could leak sensitive information or corrupt application state. Mozilla has released patched versions to address this issue.
- CVE-2026-12299MEDIUM 5.4
A flaw in Firefox and Thunderbird's just-in-time (JIT) compiler causes incorrect code generation when processing web page structures (DOM). An attacker can craft a malicious webpage that, when visited, exploits this miscompilation to read small amounts of data or alter page content in the user's browser session. The vulnerability requires user interaction—specifically, visiting a compromised or attacker-controlled site—but does not allow the attacker to execute arbitrary code or crash the application.
- CVE-2026-12321MEDIUM 5.4
A flaw in Firefox and Thunderbird's JavaScript-to-WebAssembly compiler causes it to generate incorrect machine code in certain scenarios. An attacker could exploit this by serving a malicious webpage or email with crafted script, potentially allowing them to read sensitive data or modify page content. The vulnerability requires user interaction (visiting a site or opening an email) and does not enable system crashes or privilege escalation.
- CVE-2026-12322MEDIUM 5.4
A clickjacking vulnerability exists in the Gtk widget component used by Firefox and Thunderbird. An attacker could craft a malicious webpage that tricks users into clicking on hidden UI elements, potentially allowing unauthorized actions such as modifying settings or accessing sensitive information. The vulnerability requires user interaction—a click on a deceptive overlay—but no special privileges. It affects both confidentiality and availability of the application.
- CVE-2026-12323MEDIUM 5.4
A spoofing vulnerability exists in Firefox and Thunderbird's DOM (Document Object Model) and HTML processing component. An attacker could potentially deceive users about the true origin or content of a webpage or email through DOM manipulation. The issue requires user interaction to trigger and affects confidentiality and availability rather than integrity. Mozilla fixed this in Firefox 152 and Thunderbird 152.
- CVE-2026-12330MEDIUM 5.4
A boundary condition error in Mozilla Firefox and Thunderbird's internationalization component can allow an attacker to read small amounts of user data or modify content on a webpage, provided the user interacts with a malicious site. The vulnerability requires user action (clicking, submitting forms) to trigger, and does not enable system-level compromise or denial of service. Mozilla has released security updates across multiple Firefox ESR branches and Thunderbird to address this flaw.
- CVE-2026-12528MEDIUM 5.4
A bug in 389 Directory Server's ACI (Access Control Instruction) parsing can allow an authenticated user to corrupt memory on the server. When a specially crafted ACI string is processed, the parser fails to properly validate keyword length after removing whitespace, causing it to write one byte beyond allocated heap memory and then read from invalid locations. An attacker with write permissions to the aci attribute could exploit this to silently damage the server's memory state, potentially leading to service degradation or unexpected behavior.
- CVE-2026-12580MEDIUM 5.4
EasyFlow .NET, a Digiwin product, contains a vulnerability that lets authenticated users inject malicious JavaScript code into web pages. When other users visit those pages, the injected code runs automatically in their browsers, potentially compromising their sessions, stealing sensitive data, or redirecting them to malicious sites. This is a stored attack—the malicious code persists on the server and affects anyone who views the affected content.
- CVE-2026-12619MEDIUM 5.4
Microchip GridTime 3000 contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts into web pages. When another user views the affected page, the injected script executes in their browser within the GridTime 3000 application context, potentially compromising their session, stealing credentials, or performing unauthorized actions on their behalf. The vulnerability requires an authenticated attacker and user interaction (a victim must click a link or visit a crafted page), but can affect users across different security boundaries.
- CVE-2026-12621MEDIUM 5.4
A cross-site scripting (XSS) vulnerability exists in the password reset form of GridTime 3000. An attacker with valid login credentials can inject malicious JavaScript code that executes in the browser of other users viewing the form, potentially stealing session cookies, credentials, or triggering unauthorized actions. The vulnerability affects versions 1.0r0.03 through 1.1.x, with the fix available in version 1.2r0.0 and later.
- CVE-2026-12622MEDIUM 5.4
GridTime 3000 GNSS Time Servers contain an open redirect flaw in their password change functionality. When an authenticated user submits a password change request, the application can be tricked into redirecting them to an attacker-controlled website. An attacker would need valid credentials or the ability to socially engineer a legitimate user into clicking a malicious link that contains the redirect target. While the attacker cannot directly steal data or crash the system through this flaw, they can use it to harvest credentials, distribute malware, or conduct phishing attacks by making the redirect destination appear trustworthy.
- CVE-2026-12770MEDIUM 5.4
A security flaw was found in BerriAI's litellm, an open-source library for managing large language model API calls, affecting versions up to 1.63.1. The vulnerability resides in the admin key management system and allows authenticated users to perform actions they shouldn't be authorized to perform. An attacker who already has some level of access to the system could exploit this to modify or disrupt operations. The flaw has been publicly disclosed and patches are available.
- CVE-2026-13426MEDIUM 5.4
Mattermost's Go module contains a path traversal vulnerability in API route construction that allows authenticated attackers to redirect API calls to unintended endpoints. An attacker with valid credentials can craft malicious IDs containing path traversal sequences to bypass intended routing logic, potentially accessing or modifying data they shouldn't have access to. The vulnerability affects versions of the mattermost/server/public module prior to v0.1.22.
- CVE-2026-13549MEDIUM 5.4
CodeAstro Complaint Management System version 1.0 contains an authorization bypass vulnerability in its Report deletion functionality. An attacker can remotely trigger improper access controls in the deletereport function, allowing unauthorized deletion or modification of report data. The vulnerability requires user interaction (such as tricking an administrator into clicking a malicious link) but does not require authentication. Public exploit code is available, increasing the risk of opportunistic attacks.
- CVE-2026-13977MEDIUM 5.4
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser parses HTML that allows attackers to inject malicious scripts or HTML content into web pages. An attacker can craft a specially designed webpage that, when visited, injects arbitrary code into the page—potentially stealing data, capturing user credentials, or performing actions on the user's behalf. The vulnerability requires user interaction (visiting the malicious page) but does not require special browser permissions or system access.
- CVE-2026-14131MEDIUM 5.4
Google Chrome versions prior to 150.0.7871.47 contain a flaw in the WebAppInstalls feature that fails to properly validate user-supplied input. An attacker who has already compromised the renderer process—the sandboxed component responsible for displaying web content—could exploit this to deceive users through visual spoofing attacks. The attacker could craft a deceptive HTML page that mimics legitimate Chrome UI elements, potentially tricking users into performing unintended actions. This is a post-compromise attack; the initial renderer compromise is the critical prerequisite.
- CVE-2026-14132MEDIUM 5.4
A flaw in Google Chrome's WebXR (extended reality) implementation allows attackers to trick users by displaying fake UI elements on web pages. An attacker crafting a malicious HTML page can exploit this to make users believe they're interacting with legitimate interface elements when they're actually interacting with attacker-controlled content. This requires user interaction and doesn't affect data confidentiality or system availability, but can be used for phishing or social engineering attacks.
- CVE-2026-14135MEDIUM 5.4
Google Chrome versions prior to 150.0.7871.47 contain a vulnerability that allows an attacker who has already compromised Chrome's renderer process to trick users into seeing fake interface elements or UI components. The attacker would deliver a malicious HTML page that exploits insufficient input validation in the Network component, creating a spoofing condition. While the underlying severity is rated Low by Chromium, the CVSS score reflects moderate concern due to user interaction requirements and the need for prior renderer compromise.
- CVE-2026-14142MEDIUM 5.4
A flaw in how Google Chrome handles extensions could allow an attacker who has already compromised your browser's rendering engine to trick you into clicking malicious UI elements by disguising them as legitimate browser controls. The attacker would need to first gain control of the renderer process—typically through a separate vulnerability or compromise—then exploit this weakness to display fake dialogs or buttons that appear to come from Chrome itself. This is a secondary attack that depends on prior compromise.
- CVE-2026-14150MEDIUM 5.4
Google Chrome versions before 150.0.7871.47 contain a flaw in how the Speech feature validates user input. An attacker who has already gained control of Chrome's renderer process—the component that displays web pages—can exploit this to trick users into thinking they're interacting with legitimate browser UI when they're actually seeing forged content. This is a UI spoofing attack that requires the attacker to have compromised the renderer first, limiting the immediate threat but still worth addressing through timely patching.
- CVE-2026-14614MEDIUM 5.4
Keycloak administrators with limited permissions can bypass access controls to modify hidden client scopes—settings that control what data and permissions get added to security tokens. By exploiting this flaw, a restricted admin could inject unauthorized permissions into tokens issued to end-users, potentially granting other applications unintended access. This affects Keycloak installations using the Fine-Grained Admin Permissions v2 feature.
- CVE-2026-14636MEDIUM 5.4
A path traversal vulnerability exists in the Ecommerce-CodeIgniter-Bootstrap project's vendor image upload feature. When authenticated users upload images through the Vendor Image Manager, an attacker can manipulate the folder parameter to access or write files outside the intended upload directory. The flaw is remotely exploitable by any logged-in user and requires no special interaction. This is a medium-severity issue affecting file integrity and confidentiality for systems using the vulnerable codebase.
- CVE-2026-14693MEDIUM 5.4
A vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System version 1.0 that allows authenticated users to perform unauthorized actions through the order cancellation feature. An attacker with valid login credentials can manipulate the cancel_order function to bypass authorization checks, potentially modifying or disrupting orders that should not be under their control. The vulnerability requires authentication but poses a real risk in multi-tenant or shared-credential environments. An exploit is publicly available.
- CVE-2026-15320MEDIUM 5.4
Sipeed PicoClaw versions up to 0.2.9 contain a flaw in how it handles configuration reload requests. An authenticated user can manipulate a message parameter to bypass authorization checks, allowing them to modify system behavior or deny service to others. The vulnerability requires an existing login but no special privileges, and exploitation can occur over the network. Public exploit code is available.
- CVE-2026-15331MEDIUM 5.4
CowAgent, a framework used for building AI agent skills, contains a path traversal vulnerability in its Skill Installation Handler. An authenticated attacker can manipulate the 'Name' parameter during skill installation to write files to unintended locations on the system, potentially corrupting data or disrupting service availability. The vulnerability affects versions up to 2.1.0 and is resolved in version 2.1.2.
- CVE-2026-24754MEDIUM 5.4
Kiteworks, a private data network platform used for secure file sharing and collaboration, contains a stored cross-site scripting (XSS) vulnerability in its Secure Data Forms feature. An authenticated user with legitimate access could craft malicious input that persists in the application and executes in other users' browsers when they view the affected form. This allows the attacker to steal session tokens, perform actions on behalf of victims, or harvest sensitive data passing through their sessions. The vulnerability requires prior authentication and user interaction (clicking a link or viewing a page), limiting but not eliminating its risk. Kiteworks versions before 9.3.0 are affected; upgrading resolves the issue.
- CVE-2026-24755MEDIUM 5.4
Kiteworks, a platform for secure data sharing and management, contains a flaw in its Secure Data Forms feature that allows logged-in users to change permissions on files and folders belonging to other users. The vulnerability stems from the system not properly verifying whether a user actually owns or has authority over a resource before allowing permission changes. An attacker with valid credentials could exploit this to gain access to, or revoke access from, other users' sensitive data without authorization.
- CVE-2026-25557MEDIUM 5.4
Evoluted PHP Directory Listing Script versions up to 4.0.5 contain a reflected cross-site scripting (XSS) vulnerability in the directory parameter handling. When a user visits a specially crafted malicious link, JavaScript code embedded in the directory path gets executed in their browser, potentially allowing attackers to steal session cookies, redirect users to phishing sites, or perform actions on their behalf. The vulnerability requires user interaction—victims must click a malicious link—but no special privileges are needed to exploit it.
- CVE-2026-26378MEDIUM 5.4
Koha, an open-source library management system, contains a cross-site scripting (XSS) vulnerability in its Invoice feature file upload functionality. An authenticated attacker can craft a malicious file upload that executes arbitrary code in the browsers of users who interact with the uploaded invoice. The vulnerability affects Koha version 25.11 and earlier. Exploitation requires an attacker to have valid library system credentials and user interaction—typically a staff member viewing or processing the invoice.
- CVE-2026-27351MEDIUM 5.4
Sekander Badsha Crew HRM contains a missing authorization vulnerability that allows authenticated users to perform actions they should not be permitted to perform due to incorrectly configured access controls. An attacker with valid login credentials can exploit weak permission checks to modify data or disrupt availability, even if their role should restrict such access.
- CVE-2026-29509MEDIUM 5.4
Patool, a popular archive extraction utility, contains a flaw in how it validates whether extracted files stay within their intended directory. An attacker can craft a malicious archive with specially named files that trick the validation check and write files anywhere on the system. The vulnerability only affects systems running Python versions before 3.12. While the immediate impact is limited by the need for user interaction (the user must extract the archive), this is a classic arbitrary file write scenario that could lead to code execution or system compromise depending on file placement and permissions.
- CVE-2026-33113MEDIUM 5.4
Microsoft Office SharePoint contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. When a user visits a compromised SharePoint page, the injected code executes in their browser, potentially allowing the attacker to steal session tokens, redirect users to phishing sites, or perform actions on behalf of the victim. This is a reflected or stored XSS flaw—the vulnerability itself requires user interaction to trigger, but the impact can be significant for organizations relying on SharePoint for document collaboration and intranet services.
- CVE-2026-33244MEDIUM 5.4
React Router versions 7.5.1 through 7.13.1 contain a cross-site scripting (XSS) vulnerability when used in Framework Mode with pre-rendering. If your application redirects users to untrusted URLs and generates static HTML files during build time, attackers can inject malicious scripts into those pre-rendered pages. This vulnerability does not affect applications using the more common Declarative Mode or Data Mode routing approaches. The issue has been fixed in version 7.13.2.
- CVE-2026-3341MEDIUM 5.4
IBM Langflow Desktop versions 1.0.0 through 1.9.2 contain a server-side request forgery (SSRF) vulnerability that allows authenticated users to make unauthorized network requests from the affected system. An attacker with valid credentials could exploit this to map internal networks, access restricted services, or set up for secondary attacks. The vulnerability requires authentication, which reduces—but does not eliminate—the risk in environments where account compromise is possible.
- CVE-2026-34033MEDIUM 5.4
Apache Answer contains a cross-site scripting (XSS) vulnerability in its notification email system. When authenticated users include content in certain fields, that content reaches other users' inboxes without proper HTML escaping, potentially allowing injection of malicious scripts. An attacker with valid credentials could craft messages designed to execute code when recipients open their emails or click embedded links. This affects Apache Answer versions through 2.0.0.
- CVE-2026-34460MEDIUM 5.4
NamelessMC, a website platform for Minecraft servers, contains a vulnerability in how it handles OAuth authentication callbacks. When a user logs in via OAuth (a third-party authentication method), the application fails to verify a security token called a 'state parameter' before accepting the login. An attacker can exploit this by crafting a malicious link that tricks a victim into logging in with the attacker's own account credentials. Once clicked, the victim's session becomes authenticated as the attacker, potentially granting unauthorized access to the victim's account on that NamelessMC instance. The vulnerability affects NamelessMC versions 2.2.4 and earlier.
- CVE-2026-34507MEDIUM 5.4
OpenClaw versions before 2026.4.29 contain a flaw that allows authenticated users to bypass security policies protecting sensitive admin commands. Specifically, attackers can circumvent message delivery restrictions (DM-only policy) and sender authorization checks (allowFrom policy), enabling them to execute administrative functions from contexts or senders that should be blocked. The vulnerability requires an attacker to already have authentication credentials, limiting its blast radius but creating insider risk and account compromise scenarios.
- CVE-2026-34692MEDIUM 5.4
Adobe Experience Manager contains a cross-site scripting (XSS) flaw that allows attackers to inject and execute malicious JavaScript in a user's browser. The attack requires tricking a victim into visiting a specially crafted webpage while authenticated to AEM. Once executed, the attacker can steal session data, modify page content, or perform actions on behalf of the victim within the AEM interface.
- CVE-2026-36162MEDIUM 5.4
LiquidFiles v4.2.7 contains a vulnerability that allows authenticated users to inject malicious code into file share names. When other users view these crafted shares, the malicious code executes in their browsers, potentially allowing the attacker to steal session data, redirect users, or perform actions on their behalf. The attacker must already have valid credentials to exploit this, and a victim must interact with the poisoned share for the attack to succeed.
- CVE-2026-36163MEDIUM 5.4
LiquidFiles v4.2.7 contains a stored HTML injection flaw in its file viewing feature. When an authenticated user uploads a crafted HTML file, the application fails to properly sanitize or escape the content before displaying it to other users. This allows an attacker to embed malicious JavaScript that executes in victims' browsers, potentially stealing session tokens, redirecting users, or performing actions on their behalf within the LiquidFiles interface.
- CVE-2026-36722MEDIUM 5.4
Bookcars v8.3 contains a file upload vulnerability in its car image creation API that allows authenticated users to upload specially crafted files and potentially execute arbitrary code on the server. An attacker with valid credentials can exploit this weakness to compromise the application and potentially gain control of the underlying system.
- CVE-2026-36728MEDIUM 5.4
FastapiAdmin version 2.2.0 contains a stored cross-site scripting (XSS) vulnerability in its AI assistant chat feature. An authenticated attacker can inject malicious JavaScript or HTML through a crafted chat message. When other users view the message, the malicious script executes in their browser with access to their session and sensitive data. This requires an attacker with valid login credentials and victim user interaction (viewing the chat), limiting but not eliminating real-world risk.
- CVE-2026-38979MEDIUM 5.4
Ajenti, a system administration interface, fails to protect its login and administrative panels from clickjacking attacks. An attacker can craft a webpage that tricks users into unknowingly interacting with hidden Ajenti UI elements, potentially leading to unauthorized actions or credential harvesting. The vulnerability exists because Ajenti does not add browser-level framing protections to its responses.
- CVE-2026-40082MEDIUM 5.4
Cacti, a widely-deployed open source monitoring and management framework, contains a session fixation vulnerability in its login process. When users authenticate, the application fails to rotate the session identifier, allowing an attacker to potentially hijack authenticated sessions through same-site attack vectors. The flaw exists in versions 1.2.30 and earlier; version 1.2.31 and later address it. While the session cookie itself is well-configured with security flags (httpOnly, Strict SameSite, secure for HTTPS), the missing session ID regeneration leaves a window for exploitation during the critical authentication moment.
- CVE-2026-40930MEDIUM 5.4
A parsing flaw in libpng 1.8.0's APNG (Animated PNG) handler can cause specially crafted image data to be misinterpreted. When the parser encounters certain frame chunks in an APNG file, it clears internal state flags but fails to skip over the actual chunk data and checksum. On the next data processing call, bytes from the ignored chunk can masquerade as a new chunk header, potentially leading to integrity violations or denial of service. An attacker needs user interaction—typically opening a malicious PNG file—to trigger the issue.
- CVE-2026-40995MEDIUM 5.4
Spring Web Services has a vulnerability in its X509 certificate authentication handler that bypasses Spring Security's standard account status checks. When a user presents a valid certificate that maps to a known user account, the system authenticates them without verifying whether that account is disabled, locked, expired, or has expired credentials. This means someone with a legitimate certificate could gain access even if their account should be inactive.
- CVE-2026-41479MEDIUM 5.4
Authlib, a popular Python library for building OAuth and OpenID Connect servers, contains an open redirect vulnerability in its authorization endpoint. When an attacker sends a specially crafted request with an unsupported response type and a malicious redirect URL, the server redirects users to that attacker-controlled site without proper validation. This happens before the system even checks if the client is legitimate or if the user is logged in, meaning an attacker needs no prior setup—just a single request can redirect an unsuspecting user elsewhere. The flaw affects versions before 1.6.10 and 1.7.1.
- CVE-2026-41972MEDIUM 5.4
CVE-2026-41972 is a path traversal vulnerability in an SMS application that could allow an attacker to manipulate file paths and disrupt service availability. The vulnerability requires user interaction (such as clicking a malicious link) but does not require authentication, making it accessible to remote attackers. While the flaw does not compromise confidentiality or enable data theft, it can degrade or interrupt the SMS app's normal operation.
- CVE-2026-42547MEDIUM 5.4
IRIS, a web platform used by incident response teams to collaborate and share investigation details, contains an authorization flaw in versions before 2.4.28 that allows users to create alerts falsely attributed to customers they don't manage. When combined with cross-site scripting vulnerabilities, attackers can also steal alerts belonging to other customers. This means a low-privileged user could pollute another team's alert stream with fraudulent incidents or harvest sensitive investigation data.
- CVE-2026-42951MEDIUM 5.4
A vulnerability in Danelec MacGregor Voyage Data Recorder (VDR) devices allows authenticated users to download a complete backup file that exposes sensitive account credentials and password hashes. While an attacker must already have valid user credentials to exploit this issue, successful exploitation grants access to password material that could enable lateral movement or privilege escalation within maritime network environments. The vulnerability is classified as medium severity due to the authentication requirement, though the disclosure of password hashes represents a meaningful step toward further compromise.
- CVE-2026-43915MEDIUM 5.4
Coturn, an open-source TURN/STUN server implementation, contains a stored cross-site scripting (XSS) flaw in its web administration interface. An attacker can inject malicious HTML or JavaScript through a crafted username when creating a TURN allocation. When an authenticated administrator views the session list, the injected code executes in their browser, potentially allowing session hijacking, credential theft, or administrative takeover. The vulnerability is particularly concerning in deployments using anonymous access mode, where no TURN credentials are required for exploitation. Version 4.11.0 and later resolve this issue.
- CVE-2026-44311MEDIUM 5.4
Fabric.js, a popular JavaScript library for working with HTML5 canvas, contains a Cross-Site Scripting (XSS) vulnerability in versions before 7.4.0. The issue stems from improper handling of user input when converting gradient objects to SVG format. Specifically, when the toSVG() method processes color values in gradient color stops, it fails to escape special characters. If a web application takes the generated SVG string and inserts it into a webpage, an attacker can craft malicious input that executes arbitrary JavaScript in users' browsers. The vulnerability requires user interaction and affects the integrity and confidentiality of the browser session.
- CVE-2026-44611MEDIUM 5.4
Danelec MacGregor's Voyage Data Recorder (VDR) uses a weak password hashing method that restricts password length and is vulnerable to brute force attacks. An authenticated attacker with local network access could potentially crack stored passwords to gain unauthorized access to the device or escalate privileges. This is a medium-severity issue affecting maritime safety and navigation systems.
- CVE-2026-44727MEDIUM 5.4
Jupyter Server versions before 2.20 contain a stored cross-site scripting (XSS) vulnerability in the notebook conversion feature. When a user opens a malicious notebook through the web interface, specially crafted HTML content in the notebook can execute arbitrary JavaScript in the browser with access to session cookies and the Jupyter API. An attacker who can get a user to open a prepared notebook—either by hosting it or tricking them into uploading it—can steal credentials, modify notebooks, or execute code on the Jupyter kernel itself. The vulnerability requires user interaction (opening the notebook) and authenticated access to Jupyter, which limits the immediate blast radius but poses significant risk in multi-user or shared research environments.
- CVE-2026-44783MEDIUM 5.4
Discourse, a popular open-source discussion platform, contains a flaw in how it handles replies to whisper posts. The vulnerability allows authenticated users who are not members of groups configured to access whispers to inject messages into staff-only whisper channels. This means someone with a regular user account could post messages that appear alongside legitimate staff whispers, potentially disrupting internal conversations or spreading misinformation among staff members. The vulnerability affects versions released between early 2026 and April 2026, and has been patched in all active release branches.
- CVE-2026-44794MEDIUM 5.4
Nautobot, a network automation platform, contains a permission bypass vulnerability in its REST API that affects how it validates references between database objects. When users create or update records that link to other objects in the system, the API fails to properly check whether the user has permission to view those referenced objects. This means an authenticated user could potentially reference objects they shouldn't have access to, leading to information disclosure or unintended modifications. The issue affects Nautobot versions before 2.4.33 and 3.1.2.
- CVE-2026-44958MEDIUM 5.4
Revive Adserver versions 6.0.6 and earlier contain a flaw that allows advertiser-level users to toggle banner advertisements on and off without proper authorization. An attacker with basic advertiser credentials can activate or deactivate banners belonging to other accounts or campaigns, disrupting ad delivery even if they lack permission to make such changes. The vulnerability stems from inadequate permission checks in the banner management interface.
- CVE-2026-45023MEDIUM 5.4
AutoGPT versions before 0.6.59 contain a flaw in their API implementation that allows authenticated users to execute workflow blocks without consuming credits from their account balance. The vulnerability stems from an API endpoint that bypasses the credit-checking logic present elsewhere in the system, enabling users to run unlimited blocks at no cost. This is a business model violation rather than a critical system compromise, but it undermines the platform's monetization and resource management controls.
- CVE-2026-45453MEDIUM 5.4
CVE-2026-45453 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows attackers to inject malicious scripts into web pages. When a user visits a compromised page, the attacker's script executes in their browser, enabling spoofing attacks—such as stealing credentials, impersonating legitimate content, or redirecting users to phishing sites. The vulnerability requires user interaction (clicking a malicious link or visiting a crafted URL) but does not require authentication to exploit.
- CVE-2026-45464MEDIUM 5.4
CVE-2026-45464 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows attackers to inject malicious scripts into web pages. An attacker can trick users into visiting a crafted SharePoint page, causing their browser to execute the injected code. This enables spoofing attacks where legitimate content or UI elements can be forged to deceive users into divulging credentials, transferring funds, or trusting false information. The vulnerability requires user interaction—a person must click a malicious link or visit a compromised page—but the attacker does not need authentication to craft the attack.
- CVE-2026-45465MEDIUM 5.4
CVE-2026-45465 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an attacker to inject malicious code into web pages generated by the application. When a user visits a compromised page, the injected script executes in their browser, potentially stealing session tokens, credentials, or performing actions on behalf of the victim. The vulnerability requires user interaction—someone must click a malicious link or visit a booby-trapped SharePoint page—but no special privileges are needed to launch the attack. This is a spoofing risk, meaning attackers could impersonate legitimate SharePoint content or trusted users.
- CVE-2026-45488MEDIUM 5.4
Microsoft Edge (Chromium-based) contains a user interface flaw that allows attackers to misrepresent critical information to users, potentially tricking them into believing they are interacting with a legitimate website or service when they are not. An attacker can exploit this over the network by manipulating what Edge displays, leading to spoofing attacks. The vulnerability requires user interaction—specifically, the user must take an action in the browser—but does not require special privileges or complex setup to attempt. Impact is limited to partial information disclosure and integrity issues; system availability is not affected.
- CVE-2026-45580MEDIUM 5.4
WWBN AVideo, an open-source video streaming platform, contains a stored cross-site scripting (XSS) vulnerability in its Live plugin. A user with streaming permissions can inject malicious JavaScript into the stream configuration, which then executes in the browsers of anyone—logged-in or anonymous—who views that live stream. The vulnerability persists because user-controlled input (the stream key) is inserted directly into an HTML class attribute without proper sanitization.
- CVE-2026-45595MEDIUM 5.4
Windows Mark of the Web (MOTW) is a security feature that warns users when they open files downloaded from the internet. CVE-2026-45595 is a flaw that allows attackers to bypass this warning through network-based attacks. An attacker could craft a malicious file that appears safe to the operating system, potentially tricking users into executing it without the usual security prompts. While the vulnerability requires user interaction to be exploited, it undermines a foundational defense mechanism in Windows.
- CVE-2026-45660MEDIUM 5.4
Statamic is a content management system built on Laravel that includes an image proxy feature called Glide. A flaw in how this proxy validates URLs allows attackers to bypass security checks by using alternate IP address formats that aren't properly normalized before validation. An unauthenticated attacker could exploit this to make the server fetch content from internal addresses—such as localhost, private networks, or cloud metadata services—potentially exposing sensitive information. The vulnerability only affects Statamic versions before 5.73.22 and 6.18.1, and does not impact deployments running PHP 8.3 or later.
- CVE-2026-45669MEDIUM 5.4
Nuxt, a popular Vue.js web framework, has a vulnerability in its navigateTo() function when used with the external flag. If an application directs a user to an attacker-controlled URL using this function, the framework generates a server-side redirect page with insufficient sanitization. An attacker can inject malicious HTML and JavaScript into that redirect page, which then executes in the user's browser under the application's origin. This could allow session hijacking, credential theft, or malware distribution. The issue affects Nuxt versions 3.4.3 through 3.21.5 and 4.0.0-alpha.1 through 4.4.5.
- CVE-2026-45670MEDIUM 5.4
Nuxt, a popular Vue.js framework, contains a security gap in its development server configuration. When developers run the dev server on a non-loopback address (such as making it accessible from other machines on the network), and a developer visits a malicious website while that server is running, an attacker on the same network could potentially steal the developer's source code. This is a regression—an incomplete fix for a previously identified issue. The vulnerability affects versions 3.15.4 through 3.21.5 and 4.0.0-alpha.1 through 4.4.5; patched versions 3.21.6 and 4.4.6 are now available.
- CVE-2026-45692MEDIUM 5.4
Caddy, a popular open-source web server known for automatic HTTPS, contains a path traversal vulnerability affecting versions 2.4.0 through 2.11.2. The vulnerability arises from a disagreement between two critical layers: the authorization system checks permissions using simple text matching, while the configuration API parses the same paths using numerical array indexing. An attacker with valid credentials can exploit this mismatch to access configuration objects they shouldn't be able to reach. For example, a user authorized to view `/config/servers/0` might be able to access `/config/servers/1` by manipulating how indices are parsed. The flaw requires authentication, so it primarily affects scenarios where multiple users or services share a Caddy instance.
- CVE-2026-45778MEDIUM 5.4
OpenXDMoD, an open-source HPC (High Performance Computing) metrics collection and analysis framework, contains a stored cross-site scripting (XSS) vulnerability in user profiles combined with a password reset abuse vector. An authenticated attacker can inject malicious JavaScript into their profile, then weaponize the password reset feature to send victims a crafted link. When a victim clicks the link, the attacker's payload executes in their browser, enabling credential theft and account hijacking. All versions prior to 11.0.3 are affected.
- CVE-2026-46342MEDIUM 5.4
Nuxt, a popular Vue.js framework, contains a vulnerability in its island component rendering system that allows attackers to manipulate server responses by crafting malicious requests. The vulnerability exists because the framework computes a security hash client-side but never validates it server-side, meaning an attacker can request the same endpoint with different parameters and receive unintended responses. This could enable attackers to conduct XSS attacks or retrieve sensitive information if islands expose data meant for other users. The issue affects Nuxt 3.1.0 through 3.21.5 and 4.0.0-alpha.1 through 4.4.5, as well as the associated @nuxt/nitro-server package.
- CVE-2026-46448MEDIUM 5.4
OpenStack Nova before version 33.0.2 has a flaw in its server creation API that fails to properly clean up certain hint data sent during instance creation. This results in newly created instances lacking proper Placement allocation, which tracks where compute resources are assigned in the cloud. The vulnerability requires authenticated access but can lead to partial information disclosure and service availability impact.
- CVE-2026-46546MEDIUM 5.4
Frappe Learning Management System prior to version 2.53.0 contains a vulnerability where authenticated users can inject malicious code into certain editable fields. When these fields are displayed in page metadata, visiting users' browsers are automatically redirected to attacker-controlled URLs without their knowledge. The vulnerability requires an attacker to have valid user credentials and for a victim to visit a page containing the injected content, but once triggered, it can lead to credential theft, malware distribution, or other social engineering attacks.
- CVE-2026-46550MEDIUM 5.4
NocoDB, a popular open-source database platform that presents data in a spreadsheet-like interface, contains a cookie security misconfiguration in versions prior to 2026.04.1. The refresh token used to maintain user sessions is vulnerable to interception and cross-site request forgery (CSRF) attacks. An attacker on an unencrypted network could capture the token, or trick a logged-in user into performing an action that unknowingly refreshes their token on an attacker-controlled site. While the cookie was marked httpOnly to prevent JavaScript access, the absence of the secure flag and sameSite attribute creates a meaningful window of exposure.
- CVE-2026-46616MEDIUM 5.4
Umbraco CMS contains an open-redirect vulnerability in member-related Surface Controllers that fail to properly validate redirect URLs. When a Razor template uses user-controlled query parameters to set a redirect destination, an attacker can craft a malicious link that redirects users to an external site after they interact with the application. This undermines user trust and can be leveraged in phishing campaigns. Versions 13.14.0 and 17.4.0 and later address this issue.
- CVE-2026-47106MEDIUM 5.4
Ellucian Banner Self-Service contains a stored cross-site scripting (XSS) vulnerability in its course search feature. An authenticated user with write access to the Banner ERP system can inject malicious code into faculty names, email addresses, course descriptions, or course titles. When other users later view course meeting times through an unauthenticated API endpoint, that malicious code executes in their browsers without any sanitization, potentially compromising their sessions or stealing sensitive information. The vulnerability affects all versions released before April 23, 2025.
- CVE-2026-47222MEDIUM 5.4
NanaZip, a Windows-native variant of the 7-Zip compression utility, contains a flaw in how it processes Android Verified Boot (AVB) image files. When opening a specially crafted .avb or .img file, an arithmetic error in the parser allows an attacker to trigger a crash by causing the application to read far beyond safe memory boundaries. This denial-of-service vulnerability affects NanaZip versions 3.0.1000.0 through 5.x, and has been resolved in version 6.0.1698.0 and newer.
- CVE-2026-47223MEDIUM 5.4
NanaZip, a modern Windows adaptation of the 7-Zip archive utility, contains a flaw in how it handles specially crafted Android Verified Boot (AVB) vbmeta image files. Versions 3.0.1000.0 through 6.0.1698.0 are vulnerable to a heap memory read error triggered by a malformed salt field in vbmeta headers. An attacker can craft a malicious vbmeta image that, when opened in NanaZip, causes the application to read far beyond allocated memory—potentially exposing sensitive data from the process heap or crashing the application. The vulnerability requires user interaction (opening a file) but does not require special privileges.
- CVE-2026-47636MEDIUM 5.4
CVE-2026-47636 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows attackers to inject malicious scripts into web pages. When a user visits a specially crafted SharePoint page, the injected code executes in their browser with their privileges, enabling attackers to impersonate users, steal session data, or perform actions on their behalf. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require authentication to exploit.
- CVE-2026-47639MEDIUM 5.4
CVE-2026-47639 is a cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint that allows an attacker to inject malicious scripts into web pages. When a user visits a compromised page, the attacker's script executes in their browser, potentially stealing credentials, session tokens, or sensitive data, or redirecting users to fraudulent sites. Exploitation requires user interaction—the victim must click a link or visit a crafted page—but no authentication is needed from the attacker's side.
- CVE-2026-47694MEDIUM 5.4
WWBN AVideo, an open-source video platform, contains a stored cross-site scripting (XSS) vulnerability in how it handles category descriptions. Any user with permission to create or modify video categories can inject malicious JavaScript code into the description field. This code then executes in the browsers of other users who view that category's gallery page. Unlike previously patched XSS issues affecting video titles or comments, this flaw specifically targets the category description rendering pipeline.
- CVE-2026-4772MEDIUM 5.4
TR7 Cyber Defense Inc.'s WAF-ASP product contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts into web pages. An attacker with login credentials can craft a request that causes the WAF-ASP system to store and later serve malicious JavaScript to other users, potentially compromising their sessions, stealing credentials, or performing actions on their behalf. This is a stored variant of XSS, meaning the attack persists in the system rather than requiring each victim to click a malicious link.
- CVE-2026-47935MEDIUM 5.4
Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw that allows an attacker to inject malicious JavaScript code into a victim's browser session. The vulnerability affects multiple versions up to 6.5.24, LTS SP1, and 2026.04. An attacker must trick a user into visiting a specially crafted webpage to trigger the exploit, but once executed, the malicious script runs with the victim's privileges and can access or modify sensitive data within the AEM application context across different origin boundaries.
- CVE-2026-47936MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with basic user permissions to embed malicious code into form fields. When other users view those pages, the attacker's JavaScript runs in their browsers. This is particularly concerning because the injected script can affect other domains or applications (indicated by the changed scope), potentially compromising session tokens or sensitive data from multiple contexts.
- CVE-2026-47939MEDIUM 5.4
Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers. This is a persistence threat—the malicious payload remains in the system until remediated, affecting anyone who accesses the affected content.
- CVE-2026-47941MEDIUM 5.4
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored cross-site scripting (XSS) flaw in form field handling. A low-privileged user can inject malicious JavaScript that persists in the application and executes in other users' browsers when they view the affected page. This is a persistence problem: the attack code lives in the application, not just in a URL or temporary input. The scope change means the XSS can affect resources beyond the vulnerable component itself.
- CVE-2026-47942MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level user access to embed malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript executes in their browsers. This represents a medium-severity risk because it requires both initial low-privileged access and user interaction, but affects multiple versions of a widely-deployed content management platform.
- CVE-2026-47943MEDIUM 5.4
Adobe Experience Manager (AEM) contains a stored cross-site scripting vulnerability affecting versions 6.5.24, LTS SP1, 2026.04 and earlier. A user with low-level permissions can inject malicious JavaScript code into form fields, which then executes when other users view the affected page. This is particularly risky because the malicious payload persists in the system rather than being temporary, and it affects the security boundary between different parts of the application (indicated by the scope change in the CVSS vector). The attack requires user interaction—victims must browse to the page containing the injected field—but the damage is real: attackers can steal session tokens, capture credentials, or perform unauthorized actions on behalf of victims.
- CVE-2026-47944MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious JavaScript code into form fields. When other users view pages containing these compromised fields, the attacker's scripts execute in their browsers. This is a persistence issue—the malicious payload remains in the system until removed, affecting anyone who accesses the affected content.
- CVE-2026-47945MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with low-level account access to inject malicious JavaScript into form fields. When legitimate users view pages containing these compromised fields, the malicious script executes in their browsers, potentially compromising their sessions, stealing credentials, or performing unauthorized actions on their behalf. The vulnerability affects multiple versions of AEM through version 2026.04 and earlier LTS releases.
- CVE-2026-47946MEDIUM 5.4
Adobe Experience Manager contains a DOM-based Cross-Site Scripting vulnerability that allows an attacker to inject malicious JavaScript code into a victim's browser session. The attack requires a logged-in user to visit a specially crafted webpage, at which point the attacker's script executes with the victim's privileges within the AEM application context. This can lead to unauthorized actions, data theft, or session hijacking depending on the victim's role and permissions.
- CVE-2026-47947MEDIUM 5.4
Adobe Experience Manager contains a DOM-based cross-site scripting (XSS) flaw that allows attackers to inject malicious JavaScript into web pages viewed by authenticated users. The vulnerability affects multiple AEM versions through 6.5.24, LTS SP1, and 2026.04. Successful exploitation requires convincing a user to visit an attacker-controlled or compromised webpage while logged into an affected AEM instance. The attacker's code would then execute with the victim's privileges, potentially stealing session data, modifying content, or performing actions on their behalf.
- CVE-2026-47948MEDIUM 5.4
Adobe Experience Manager versions up to 6.5.24, LTS SP1, and 2026.04 contain a stored cross-site scripting (XSS) flaw that allows attackers with low-level account access to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the attacker's scripts execute in their browsers, potentially allowing credential theft, session hijacking, or other client-side attacks. The vulnerability requires user interaction (viewing the affected page) and a valid login, but can impact users across different security contexts.
- CVE-2026-47949MEDIUM 5.4
Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers with basic user privileges to inject malicious JavaScript. When legitimate users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially enabling session hijacking, credential theft, or further compromise. The vulnerability affects AEM 6.5.24, LTS SP1, 2026.04, and earlier versions.
- CVE-2026-47950MEDIUM 5.4
Adobe Experience Manager (AEM) contains a stored cross-site scripting (XSS) flaw that allows low-privileged users to embed malicious scripts into form fields. When other users view pages containing these compromised fields, the attacker's JavaScript runs in their browsers with the victim's permissions. The vulnerability affects multiple AEM versions including 6.5.24, LTS SP1, 2026.04 and earlier.
- CVE-2026-47951MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability that allows attackers with low-level account privileges to embed malicious code into form fields. When other users visit pages containing these compromised fields, the injected scripts execute in their browsers, potentially compromising their sessions or stealing sensitive information. The vulnerability affects multiple AEM versions up to and including 6.5.24, LTS SP1, and 2026.04.
- CVE-2026-47953MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) vulnerability in form field handling that allows low-privileged users to inject malicious scripts. When a victim visits a page containing an affected form field, the injected script executes in their browser with the victim's privileges, potentially compromising their session or stealing sensitive data. The vulnerability affects multiple versions of AEM through 2026.04 and requires authenticated access to exploit, limiting but not eliminating the attack surface.
- CVE-2026-47954MEDIUM 5.4
Adobe Experience Manager contains a stored cross-site scripting (XSS) flaw that allows attackers with basic user privileges to embed malicious code into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially allowing the attacker to steal credentials, session tokens, or perform actions on behalf of the victim. The vulnerability affects multiple versions of AEM up to and including 6.5.24, LTS SP1, and 2026.04.
- CVE-2026-47956MEDIUM 5.4
Adobe Experience Manager versions through 6.5.24, LTS SP1, and 2026.04 contain a stored cross-site scripting (XSS) flaw in form field handling. An attacker with basic user privileges can inject malicious JavaScript into vulnerable fields. When legitimate users view pages containing these fields, the injected scripts execute in their browsers. This is particularly concerning because the vulnerability changes scope—meaning an attacker could potentially affect other users or system functionality beyond the immediate form context.