By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 74 of 86
- CVE-2026-13373MEDIUM 4.8
WatchGuard Fireware OS contains a stored cross-site scripting (XSS) vulnerability in its Tigerpaw Technology Integration module. An attacker with high privilege access can inject malicious scripts that remain permanently stored in the system and execute when other users view affected pages. This is a secondary exploitation path related to CVE-2025-13936. The vulnerability requires user interaction to trigger and affects a wide range of WatchGuard Firebox appliances and FireboxCloud/FireboxV platforms.
- CVE-2026-13374MEDIUM 4.8
WatchGuard's Fireware operating system contains a stored cross-site scripting (XSS) vulnerability in the ConnectWise Technology Integration module. An attacker with high-level administrative privileges can inject malicious scripts that persist in the system and execute in the browsers of other users who view affected pages. This is a secondary attack path related to the previously disclosed CVE-2025-13937. The vulnerability requires user interaction to trigger and affects the confidentiality and integrity of data visible to victims, but does not impact system availability.
- CVE-2026-13375MEDIUM 4.8
WatchGuard Fireware OS contains a stored cross-site scripting (XSS) vulnerability in its Autotask Technology Integration module. An authenticated attacker with high privileges can inject malicious scripts that remain in the system and execute in the browsers of other users who interact with affected pages. This is a secondary attack vector for an earlier vulnerability (CVE-2025-13938). The vulnerability requires administrator-level access and user interaction to exploit, limiting immediate risk but warranting attention in environments with untrusted or compromised admin accounts.
- CVE-2026-13376MEDIUM 4.8
WatchGuard's Fireware OS contains a stored cross-site scripting (XSS) vulnerability in the spamBlocker module that allows authenticated attackers to inject malicious scripts into web pages. Because the payload is stored, any user accessing the affected page will execute the attacker's code in their browser. This is a secondary attack path related to the previously disclosed CVE-2025-1071 and requires administrative privilege to exploit, but once injected, affects all viewers of the compromised content.
- CVE-2026-13377MEDIUM 4.8
WatchGuard Fireware OS contains a stored cross-site scripting (XSS) vulnerability in its SIP Proxy module that allows authenticated attackers with high privileges to inject malicious scripts into web pages. When other users access the affected page, the injected script executes in their browser, potentially compromising their session or stealing sensitive information. This is a follow-on attack vector for an earlier vulnerability (CVE-2025-6947) that was not fully mitigated. The vulnerability affects a broad range of WatchGuard Firebox appliances and FireboxCloud deployments.
- CVE-2026-14154MEDIUM 4.8
CVE-2026-14154 is a UI spoofing vulnerability in Google Chrome's DevTools that requires an attacker to trick a user into installing a malicious extension. Once installed, the extension can display fake interface elements to deceive users, potentially leading to credential theft or social engineering attacks. While Google rates this as low severity, the attack chain depends on user action to install the extension, which limits but does not eliminate risk.
- CVE-2026-14781MEDIUM 4.8
Keycloak's OIDC identity provider feature contains a flaw in how it validates email addresses when integrating with external authentication systems. When configured to trust email claims from an upstream OIDC provider, Keycloak retrieves the actual email address from one source (userinfo endpoint) but checks whether that email is verified using a claim from a different source (the id_token). If an attacker controls the upstream OIDC provider and makes these two sources return different email addresses, Keycloak will incorrectly mark the userinfo email as verified based on the id_token claim, even though that claim refers to a completely different email address. This allows an attacker to bypass email verification controls and potentially take over accounts in applications that rely on the email_verified flag for account linking.
- CVE-2026-22674MEDIUM 4.8
Hashgraph Guardian versions up to 3.6.0 contain a stored cross-site scripting (XSS) flaw in the branding configuration feature. An authenticated user with the STANDARD_REGISTRY role can inject malicious JavaScript by submitting a specially crafted company name through the branding API. This injected script executes automatically in every authenticated user's browser on each page load, potentially allowing the attacker to steal session tokens, perform unauthorized actions, or redirect users to malicious sites.
- CVE-2026-25558MEDIUM 4.8
QloApps versions up to 1.7.0 contain a stored cross-site scripting (XSS) vulnerability in the admin file manager. An authenticated administrator can upload a specially crafted SVG file containing malicious JavaScript code. When any user subsequently views or accesses that file, the embedded script executes in their browser, potentially compromising their session or stealing sensitive information. The vulnerability requires administrator-level access to exploit but poses a persistent risk once injected.
- CVE-2026-26145MEDIUM 4.8
Azure Synapse contains an access control weakness that allows an already-authenticated user to gain elevated privileges through network interaction. An attacker with valid credentials can exploit improper permission enforcement to access capabilities or data they should not be able to reach, provided the victim performs a specific action. The vulnerability requires high effort to exploit and does not enable lateral movement to other systems or direct data modification.
- CVE-2026-27882MEDIUM 4.8
Coolify, an open-source platform for server and application management, contains a vulnerability in how it validates GitLab webhook requests. The flaw stems from using a standard string comparison method that takes slightly different amounts of time depending on where characters match or differ. An attacker can exploit this timing difference—measuring how long the validation takes—to systematically guess the webhook secret token character by character, similar to picking a lock by listening for clicks. The vulnerability affects versions prior to 4.0.0-beta.461 and is resolved in that beta release.
- CVE-2026-28301MEDIUM 4.8
CVE-2026-28301 is a URL redirection vulnerability that allows an attacker to craft a malicious link which, when followed by an authorized user, redirects them to an attacker-controlled website. The vulnerability requires an attacker to be on the same network segment as the target and needs a user with some level of system access to click the malicious link, but does not require the victim's interaction with a confirmation dialog. The attack results in confidentiality exposure rather than data modification or system unavailability.
- CVE-2026-34127MEDIUM 4.8
A stored cross-site scripting (XSS) vulnerability exists in TP-Link's TL-SG108PE v5 managed switch web interface. When an administrator imports a configuration file containing malicious code in the SYSNAM parameter, that code is stored without proper sanitization. The next time an administrator accesses the web management interface, the injected script executes in their browser. This could allow an attacker (who must already have administrator credentials) to steal session cookies, modify switch settings, or extract sensitive information from the management interface.
- CVE-2026-34694MEDIUM 4.8
Adobe Experience Manager Forms JEE contains a stored cross-site scripting (XSS) vulnerability in form fields that allows a high-privileged attacker to inject malicious JavaScript code. When other users visit a page containing the compromised form field, the malicious script executes in their browser, potentially compromising their session, credentials, or sensitive data. The vulnerability affects versions LTS SP1, 6.5.24.0 and earlier.
- CVE-2026-36460MEDIUM 4.8
Dovestones Software's ADPhonebook application before version 4.0.1.1 contains a Cross-Site Scripting (XSS) vulnerability in its administrative configuration API. An authenticated administrator can inject malicious JavaScript code into various system configuration sections, which is then stored and executed in the browsers of other users who access those settings. This requires both admin privileges and user interaction (a victim must view the affected configuration), limiting but not eliminating the risk.
- CVE-2026-40210MEDIUM 4.8
CVE-2026-40210 is a medium-severity vulnerability affecting the SetMacAddrAction function. When this action is invoked, a flaw in memory boundary checking can allow the software to read beyond allocated memory, potentially exposing uninitialized data that may be transmitted over the network or causing the application to crash. The vulnerability requires specific conditions to exploit but does not demand special privileges or user interaction.
- CVE-2026-40641MEDIUM 4.8
Dell PowerFlex Manager versions before 5.1.0.1 use weak cryptographic algorithms that could allow remote attackers without credentials to access or modify sensitive data. An attacker would need specific conditions to succeed, but the risk centers on information disclosure and tampering rather than system availability.
- CVE-2026-40986MEDIUM 4.8
Spring Web Flow contains a flaw in how it handles error responses from the JavaScript RemotingHandler. When an error occurs, the framework renders the response body as HTML regardless of the actual content type, which can allow an attacker to inject malicious scripts into the browser. An attacker could craft a request that triggers an error response containing attacker-controlled input (such as a parameter value), and if that input is reflected in the error details without proper sanitization, it executes as JavaScript in the victim's browser. This requires the victim to be logged in and click on a malicious link, making it a moderate-risk vulnerability.
- CVE-2026-40996MEDIUM 4.8
Spring Web Services incorrectly defaulted to accepting a weaker cryptographic key transport mechanism—RSA PKCS#1 v1.5—during inbound WS-Security message decryption. This override applied only to specific versions and would allow an attacker positioned to intercept and modify encrypted SOAP messages to exploit the known mathematical weaknesses in RSA v1.5 padding. Organizations using affected versions would need to manually reconfigure the security interceptor to reject this algorithm; the safer option was not the default.
- CVE-2026-41697MEDIUM 4.8
Spring Data Relational, a widely-used Java framework for database access, contains a vulnerability in its Query By Example (QBE) feature. When developers use string matching options like STARTING, ENDING, or CONTAINING, the framework fails to properly escape wildcard characters from user-supplied input. An attacker can exploit this by injecting wildcard characters to perform boolean-based blind SQL inference attacks—essentially asking yes-or-no questions about the underlying database without directly viewing the data. The vulnerability affects multiple versions across 2.4, 3.0, 3.1, 3.2, 3.3, 3.4, 3.5, and 4.0 release lines.
- CVE-2026-41838MEDIUM 4.8
Spring Framework's WebSocket session management generates predictable IDs instead of using cryptographic randomness. An attacker with valid login credentials could potentially guess or enumerate these session identifiers and, when combined with weak authorization controls, gain unauthorized access to other users' WebSocket sessions to view sensitive data. The vulnerability requires both authentication and specific authorization gaps to exploit, making it a moderate-risk issue requiring immediate attention in security-sensitive deployments.
- CVE-2026-41847MEDIUM 4.8
Spring WebFlux applications using Kotlin Router DSL are vulnerable to a security bypass that could allow an attacker to circumvent intended access controls. The issue affects Spring Framework versions 5.3.0 through 5.3.48 and requires specific configuration conditions to exploit, making it a moderate-severity concern for teams running these versions in production.
- CVE-2026-44040MEDIUM 4.8
UltraVNC versions up to 1.8.2.2 use a weak random number generator to create the authentication challenge sent during VNC login. An attacker observing the authentication exchange can predict the challenge by brute-forcing the seed value, which is based only on the system's clock time and process ID—both publicly observable. This enables an attacker to forge authentication or crack the VNC password offline. The vulnerability affects the rfb/vncauth.c code path; Windows binaries may be partially protected by the use of CryptGenRandom on that platform, though the exact code path in shipped binaries is still being verified.
- CVE-2026-44490MEDIUM 4.8
Axios, a widely-used HTTP client for JavaScript environments, contains two prototype-pollution vulnerabilities that can be exploited when an upstream dependency (such as lodash) has already polluted JavaScript's Object.prototype. An attacker cannot directly trigger these gadgets, but if your application uses a vulnerable dependency alongside axios, malicious code or data flowing through your supply chain could cause axios to either leak polluted properties in HTTP headers or crash on every request with a TypeError. Versions before 0.32.0 (for the 0.x line) and before 1.16.0 (for the 1.x line) are affected.
- CVE-2026-45446MEDIUM 4.8
OpenSSL's implementations of two advanced encryption modes, AES-SIV and AES-GCM-SIV, contain a flaw in how they verify message authenticity when the encrypted content is empty. An attacker can craft a fraudulent message with attached metadata (AAD) and an empty ciphertext that will pass authentication checks without knowing the encryption key. This is only exploitable in custom applications that implement their own protocols using OpenSSL's EVP interface and skip processing when receiving empty ciphertext.
- CVE-2026-47673MEDIUM 4.8
Hono, a JavaScript Web application framework, contains a flaw in its JWT authentication middleware that fails to enforce the Bearer scheme requirement. Prior to version 4.12.21, the jwt and jwk middlewares accept any two-part Authorization header value—regardless of whether it uses Bearer, Basic, Token, or any other scheme name—and proceed directly to JWT verification if the token is valid. This means an attacker could authenticate by presenting a valid JWT under an incorrect scheme (like Basic auth) and gain the same access as a properly formatted Bearer token request. The vulnerability is fixed in version 4.12.21.
- CVE-2026-47692MEDIUM 4.8
Envoy, a widely-used proxy for cloud applications, has a defect in how it generates PROXY Protocol v2 headers when handling larger request metadata. The issue occurs when the headers become too large—exceeding 65,535 bytes—but the proxy still marks them as fitting within that limit. This mismatch can cause leftover data to slip through to the upstream server, potentially leading to request smuggling attacks. The vulnerability affects Envoy versions 1.34.0 and later through specific releases in the 1.35, 1.36, 1.37, and 1.38 branches.
- CVE-2026-47933MEDIUM 4.8
Adobe ColdFusion versions 2023.19, 2025.8 and earlier contain a stored cross-site scripting (XSS) vulnerability that allows low-privileged attackers to inject malicious JavaScript into form fields. When other users view pages containing these compromised fields, the attacker's script executes in their browsers. This is a persistence mechanism rather than a one-time attack—the malicious code remains embedded in the application until remediated.
- CVE-2026-48142MEDIUM 4.8
NGINX Plus and NGINX Open Source contain a flaw in character encoding handling that can be exploited by remote attackers to leak small amounts of memory or cause the web server to crash. The vulnerability requires a specific configuration—using both UTF-8 source encoding and an alternative target charset (like KOI8-R) in the same location block—and attackers need circumstances partially outside their control to trigger it. The impact is limited to confidentiality and availability; no data modification is possible.
- CVE-2026-48783MEDIUM 4.8
Postiz, an AI-powered social media scheduling platform, contained a security flaw in versions before 2.21.8 where an unauthenticated endpoint failed to validate the purpose of authentication tokens. An attacker could exploit this by using a signed token to trigger subscription-enforcement side effects within their own organization—such as disabling team members, removing integrations, or resetting scheduled posts—without needing to authenticate normally. The vulnerability is self-contained; attackers cannot use it to affect other organizations' accounts. The issue has been patched in version 2.21.8.
- CVE-2026-48823MEDIUM 4.8
Shaarli, a self-hosted bookmarking application, contains a stored cross-site scripting (XSS) flaw in how it handles user-supplied tags. An authenticated attacker can embed malicious JavaScript into a bookmark's tags field. When other users search by tag on the homepage, the attacker's code executes in their browser. This affects anyone using the tag filtering feature, including administrators. The issue is fixed in version 0.16.2.
- CVE-2026-50009MEDIUM 4.8
Netty, a widely-used framework for building network applications, contains a flaw in its QUIC protocol implementation that leaks sensitive reset tokens onto the network. These tokens act like cryptographic keys that allow an attacker positioned on the network path to forge denial-of-service packets and disrupt connections. The vulnerability requires the attacker to be on-path and able to observe traffic, but no special privileges or user interaction are needed. This affects Netty versions before 4.2.15.Final.
- CVE-2026-50623MEDIUM 4.8
Apache CXF contains an authentication bypass flaw in its OAuth2 token introspection endpoint. A missing security check allows unauthenticated attackers to access the /services/oauth2/introspect endpoint if authentication has not been explicitly enabled on that service. While the vulnerability requires a pre-existing misconfiguration, it could expose token metadata or enable further attacks against OAuth2 flows. Patched versions 4.2.2 and 4.1.7 address the underlying code defect.
- CVE-2026-52756MEDIUM 4.8
Ghidra, the NSA's reverse-engineering framework, contains a path traversal flaw in its IsfServer network component. An unauthenticated attacker can connect to the default listening port and craft specially formatted messages to probe and enumerate files on the system running Ghidra. The vulnerability allows limited information disclosure and potential denial of service, but does not enable code execution or file modification.
- CVE-2026-53624MEDIUM 4.8
Fiber, a popular Go web framework modeled after Express, has a flaw in its security middleware that prevents HTTPS security headers from being properly configured. When developers set up Strict-Transport-Security (HSTS) protection—a critical safeguard that tells browsers to only connect via encrypted HTTPS—the middleware fails to apply it because it's checking the wrong property in the connection context. This leaves applications vulnerable to protocol downgrade attacks even when administrators believe they've enabled the protection. The issue is resolved in Fiber version 3.4.0.
- CVE-2026-53877MEDIUM 4.8
Django's GIS (Geographic Information System) module contains a buffer over-read vulnerability when processing binary geographic data. An attacker could craft malicious geographic data that, when parsed by a Django application, either exposes sensitive information from the server's memory or crashes the application. The vulnerability affects Django 6.0 before version 6.0.7 and 5.2 before version 5.2.16, with earlier unsupported versions potentially vulnerable as well.
- CVE-2026-54289MEDIUM 4.8
Hono, a JavaScript web framework, has a vulnerability affecting AWS Lambda@Edge deployments prior to version 4.12.25. When CloudFront forwards requests to Lambda@Edge, it may send repeated headers (like X-Forwarded-For) as separate entries. The vulnerable Hono adapter incorrectly overwrites each duplicate header value instead of preserving all of them, so only the last value reaches the application. This silent truncation can break security controls that rely on the full header chain and lose audit trail information about request routing.
- CVE-2026-54800MEDIUM 4.8
CPCI85 Central Processing/Communication and SICORE Base system ship with OPC UA (a widely-used industrial communication protocol) security disabled by default. This means an attacker on the network could interact with these systems without authentication, potentially reading sensitive data or modifying operations. The vulnerability exists in all versions before V26.20 and requires specific network conditions to exploit, but the risk is real in connected industrial environments.
- CVE-2026-54887MEDIUM 4.8
Erlang/OTP's DTLS server uses a predictable cookie value during startup instead of a random one, allowing attackers to forge valid DTLS cookies within a narrow window (0-15 seconds after server restart). The DTLS cookie is a security mechanism designed to prevent attackers from using spoofed IP addresses to force a server into expensive cryptographic operations. By observing unencrypted ClientHello messages, an attacker can compute the cookie themselves and bypass this protection, enabling amplification attacks with forged source addresses. This affects DTLS deployments in OTP versions 20.0 through 29.0.2 and specific patch releases.
- CVE-2026-55766MEDIUM 4.8
guzzlehttp/psr7, a widely-used PHP library for handling HTTP messages, fails to properly sanitize certain HTTP protocol fields when processing attacker-controlled input. Specifically, carriage return and line feed (CR/LF) characters are not rejected in the request method, protocol version, and response reason phrase. If an application accepts untrusted data and uses psr7 to serialize messages for network transmission, an attacker could inject additional HTTP headers into the serialized output, potentially bypassing security controls or manipulating message intent. The vulnerability requires deliberate serialization to HTTP/1.x format; simply creating or modifying a PSR-7 object is not exploitable on its own.
- CVE-2026-55890MEDIUM 4.8
Grav, a file-based web content platform, contains a stored cross-site scripting (XSS) vulnerability in how it handles Markdown image styling. An authenticated editor can inject malicious code through image style parameters in Markdown that will execute in the browsers of users viewing the rendered content. This vulnerability exists because a previous XSS fix (CVE-2026-42841) was incomplete and left another code path unprotected. The vulnerability requires editor-level permissions to exploit and is fixed in version 2.0.0-rc.9.
- CVE-2026-56294MEDIUM 4.8
A vulnerability in capacitor-native-biometric allows attackers to bypass biometric authentication on mobile applications. The flaw exists because the authentication success handler doesn't properly verify cryptographic parameters. An attacker with physical or programmatic access to a device can exploit this by intercepting and manipulating the authentication flow, gaining unauthorized access without providing valid biometric credentials. This is a medium-severity issue because it requires specific technical conditions and device access, but it directly undermines a critical security control.
- CVE-2026-56381MEDIUM 4.8
Craft CMS versions from 5.0.0-RC1 onward contain a stored cross-site scripting (XSS) vulnerability in the User Permissions page. An administrator can inject malicious JavaScript code into user group names, which then executes whenever other users access or modify permission settings. This is a privilege-based attack where an already-compromised or malicious admin account can harm other users through their browser.
- CVE-2026-56383MEDIUM 4.8
Craft CMS has a stored cross-site scripting (XSS) flaw in its editable table component when using row heading column types. An administrator with change permissions can inject malicious JavaScript into row heading default values. This code then runs automatically when other users view pages containing that table field, potentially compromising their accounts or stealing sensitive data. The vulnerability affects Craft CMS versions 4.5.0-beta.1 through 4.16.18 and 5.0.0-RC1 through 5.8.22.
- CVE-2026-56393MEDIUM 4.8
Craft CMS administrators can inject malicious JavaScript code into configuration fields—such as section names, volume names, or checkbox labels—that will execute when other administrators view those settings in the control panel. This happens because Craft renders these fields without removing potentially harmful code. An attacker with admin privileges and the ability to modify admin settings could weaponize this to steal session tokens or perform unauthorized actions on behalf of other users.
- CVE-2026-57289MEDIUM 4.8
Jenkins Bitbucket Push and Pull Request Plugin version 3.3.8 and earlier contains a security flaw that disables SSL/TLS certificate validation when sending authentication tokens to Bitbucket Server. This means an attacker positioned to intercept network traffic—such as on a shared network or compromised router—could potentially capture the authentication token in transit, even though the connection appears secure. The vulnerability requires specific network conditions to exploit but represents a meaningful risk to Jenkins installations that rely on this plugin for Bitbucket integration.
- CVE-2026-57352MEDIUM 4.8
A vulnerability exists in the ALD – Dropshipping and Fulfillment plugin for WooCommerce (versions 2.2.0 and earlier) that allows attackers to bypass authentication controls without credentials. The flaw stems from improper validation of authentication mechanisms, creating an opening for unauthorized access. An attacker would need to perform specific actions or supply particular input to exploit this—it's not trivial, but it is accessible over the network without user interaction.
- CVE-2026-57997MEDIUM 4.8
Strapi's users-permissions plugin has a cryptographic configuration flaw that allows attackers to bypass JWT (JSON Web Token) authentication controls. When administrators don't explicitly set the allowed JWT algorithm in their configuration, the plugin accepts multiple HMAC variants (HS384 and HS512) in addition to the default HS256. If an attacker obtains the JWT secret key—whether through a separate compromise, supply chain attack, or insider access—they can create valid tokens using these alternative algorithms to impersonate users and gain unauthorized access.
- CVE-2026-58034MEDIUM 4.8
A cross-site scripting (XSS) vulnerability exists in Wikimedia Foundation's CheckUser extension for MediaWiki. The flaw is located in a Vue component responsible for blocking connected temporary accounts. An authenticated administrator with high privileges can craft malicious input that executes unintended JavaScript in the browsers of other users viewing the affected page, potentially leading to session hijacking or credential theft.
- CVE-2026-58035MEDIUM 4.8
MediaWiki contains a cross-site scripting (XSS) vulnerability in its Special:Block page interface that allows an authenticated user with administrative privileges to inject malicious scripts. When a victim visits the affected page after the attacker has crafted a malicious block, the injected code executes in the victim's browser in the context of the wiki. This is a reflected or stored XSS issue depending on how the input flows through the Special Block feature, and it requires both high-privilege attacker account and user interaction to successfully exploit.
- CVE-2026-58657MEDIUM 4.8
Grav, a flat-file CMS platform, contains a stored CSS injection flaw in its Markdown image resize feature. A content editor with page-editing privileges can embed malicious CSS into image resize parameters that will execute in the browser of any administrator or reviewer who views the crafted page. Unlike traditional injections, this attack doesn't require JavaScript—it abuses CSS properties to manipulate the visual layout or create overlay attacks that could deceive users into performing unintended actions.
- CVE-2026-59876MEDIUM 4.8
protobufjs is a popular library that converts Protocol Buffer definitions into JavaScript functions for serialization and deserialization. Between versions 8.2.0 and 8.6.4, the Text Format extension (which parses human-readable protobuf text) contained a prototype pollution vulnerability. When processing map entries, the code would assign user-supplied keys directly to the map object using standard property assignment. An attacker who controls protobuf text input could inject a key named `__proto__` to modify the prototype chain of the resulting map object, potentially affecting how the application behaves with that object and related instances. This is a moderate-severity issue that requires specific attack conditions to exploit but can lead to unexpected property access or behavior changes.
- CVE-2026-59897MEDIUM 4.8
Hono, a JavaScript web application framework, has a flaw in how it handles HTTP headers when deployed on AWS API Gateway v1. The framework incorrectly removes duplicate header values by comparing substrings instead of exact matches. This means if a request contains the same header value multiple times with slight differences, one instance gets dropped. For applications relying on complete header chains—especially the X-Forwarded-For header used to track proxy chains—this data loss can break security controls like rate limiting, audit logging, and proxy validation. The vulnerability affects versions 4.3.3 through 4.12.26 and is resolved in 4.12.27.
- CVE-2026-59998MEDIUM 4.8
OpenSSH versions before 10.4 contain an undocumented security behavior where the GSSAPIStrictAcceptorCheck setting fails to function correctly when the SSH server is configured with Windows Active Directory authentication. This means servers relying on this setting for access control may not enforce the intended security checks, potentially allowing unauthorized access or credential exposure in Windows AD environments.
- CVE-2026-6324MEDIUM 4.8
libsoup, a widely-used HTTP client library, contains a logic error in how it processes chunked HTTP request bodies. An attacker can craft a malicious HTTP request that exploits an unsigned-to-signed integer conversion flaw in the chunked encoding handler. The vulnerability is most likely to be triggered in proxy scenarios—when libsoup is deployed behind a third-party proxy or acting as a proxy itself. Successful attacks can lead to cache poisoning, security control bypass, or unauthorized access to backend systems.
- CVE-2026-6371MEDIUM 4.8
Limatek System Inc.'s LimRAD NAC product contains a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker with limited network access to inject malicious scripts into the web interface. These scripts persist in the system and execute in the browsers of other users who view affected pages, potentially compromising session integrity and enabling unauthorized actions within the NAC application.
- CVE-2026-8078MEDIUM 4.8
Checkmk versions before 2.5.0p5, 2.4.0p31, 2.3.0p48, and all 2.2.0 releases contain a stored cross-site scripting (XSS) vulnerability in the global settings change log. An administrator with permission to modify global settings can inject malicious HTML or JavaScript into changelog messages. When other users view the Activate Changes page or Audit log, this malicious code executes in their browsers, potentially compromising their sessions or stealing information.
- CVE-2026-8661MEDIUM 4.8
A flaw in Rapid7 InsightConnect's Markdown Plugin allows attackers to trick the system into making unwanted outbound web requests when processing user-supplied Markdown content. The vulnerability exists in the markdown_to_pdf action and stems from incomplete sanitization of HTML elements like images and stylesheets that can load external resources. An attacker can embed specially crafted Markdown with image tags or CSS imports pointing to internal or external targets, causing the affected server to fetch those resources on the attacker's behalf. Versions prior to 4.0.2 are vulnerable; an initial patch in 4.0.0 addressed JavaScript execution but overlooked resource-loading vectors.
- CVE-2026-9549MEDIUM 4.8
Checkmk versions before 2.5.0p5, 2.4.0p31, 2.3.0p48, and all 2.2.0 releases contain a stored cross-site scripting vulnerability in the service discovery active check output feature. An administrator with the ability to configure active or custom checks can inject malicious HTML or JavaScript that will execute in the browsers of other administrators or users with host read permissions when they view or run checks on the service discovery page. The attack is persistent—the injected code remains in the system until removed.
- CVE-2026-9677MEDIUM 4.8
The Shariff for WordPress plugin through version 1.0.11 contains a stored cross-site scripting (XSS) vulnerability in how it handles the shariff_infourl setting. An administrator can inject malicious JavaScript that persists in the site's database and executes in visitors' browsers when the plugin displays the sharing interface. This is particularly concerning in multisite WordPress environments where administrators may not have the unfiltered_html capability, yet can still weaponize this setting to attack site visitors.
- CVE-2026-10070MEDIUM 4.7
A flaw in macrozheng mall versions up to 1.0.3 allows an authenticated administrator with high privileges to bypass authorization controls on the super admin password update endpoint. An attacker with admin credentials could manipulate requests to the /admin/update/ path and gain unauthorized access to sensitive administrative functions. The vulnerability requires valid admin-level authentication and cannot be exploited anonymously from the network.
- CVE-2026-10155MEDIUM 4.7
A SQL injection vulnerability exists in Bdtask Multi-Store Inventory Management System version 1.0 within the Accounts Report Handler. An authenticated attacker can manipulate the 'dtpToDate' parameter in the accounts report search function to inject malicious SQL commands. While the vulnerability requires high privileges to exploit, successful attacks could leak sensitive financial data, modify account records, or disrupt reporting functionality. Public exploit code is available, increasing real-world risk.
- CVE-2026-10171MEDIUM 4.7
A SQL injection vulnerability exists in code-projects Online Music Site version 1.0 that allows authenticated administrators to manipulate the ID parameter in the album update functionality. An attacker with admin credentials can inject malicious SQL commands through the /Administrator/PHP/AdminUpdateAlbum.php endpoint, potentially compromising database integrity and confidentiality. The vulnerability has been publicly disclosed and exploit code is available, increasing the likelihood of active exploitation.
- CVE-2026-10237MEDIUM 4.7
A SQL injection vulnerability was identified in SourceCodester Water Billing Management System version 1.0. An authenticated administrator can manipulate the ID parameter in the user management interface to inject malicious SQL commands, potentially reading or modifying sensitive database records. The vulnerability requires administrative privileges to exploit but poses a risk to data integrity and confidentiality within billing systems. Public proof-of-concept code exists, elevating the practical risk of exploitation.
- CVE-2026-10248MEDIUM 4.7
SourceCodester's Pharmacy Sales and Inventory System version 1.0 and earlier contains a CSV injection vulnerability in its supplier creation interface. An authenticated attacker with high privileges can inject malicious CSV formulas through the Address or Company Name fields when exporting supplier data, potentially causing data corruption, formula execution, or information disclosure when a user opens the exported file in a spreadsheet application.
- CVE-2026-10583MEDIUM 4.7
A server-side request forgery (SSRF) vulnerability exists in nextlevelbuilder GoClaw versions up to 3.11.3. The flaw is located in the TTS Configuration Endpoint's Import function, which fails to properly validate or restrict outbound HTTP requests. An authenticated attacker with high privileges can exploit this to make the affected server initiate requests to internal or external systems on their behalf, potentially accessing sensitive internal resources or launching further attacks. The vulnerability has been publicly disclosed.
- CVE-2026-10659MEDIUM 4.7
A NULL pointer dereference vulnerability exists in Zephyr's Dhara flash translation layer driver. When the driver initializes or mounts a flash-based storage disk, it may attempt to read checkpoint pages to resume the filesystem state. If the flash hardware returns an error (such as a corrected ECC failure or bad block detection), the driver code unconditionally writes the error code through a NULL pointer instead of using the library's safe error-handling function. This causes a kernel fault and system crash. The vulnerability requires local access and depends on specific flash health conditions or crafted on-disk content, making it a localized but critical availability risk for embedded systems relying on Zephyr's flash storage.
- CVE-2026-11233MEDIUM 4.7
CVE-2026-11233 is a same-origin policy bypass vulnerability in Google Chrome's FoldableAPIs feature. An attacker who has already gained control of Chrome's renderer process—the component that executes web page code—can use a specially crafted HTML page to break through Chrome's security boundary and access data from websites the user visits. This requires the attacker to have already compromised the renderer, making it a secondary exploit rather than a direct entry point. The vulnerability affects Chrome versions prior to 149.0.7827.53.
- CVE-2026-11249MEDIUM 4.7
Google Chrome versions before 149.0.7827.53 contain a use-after-free vulnerability in the Network component. If an attacker compromises Chrome's renderer process—the sandboxed part that runs web content—they could read sensitive data from the browser's memory using a specially crafted HTML page. This is a memory safety issue: the code attempts to access data after it has already been freed, potentially exposing unencrypted information that was in use moments before.
- CVE-2026-11448MEDIUM 4.7
GL.iNet GL-MT3000 routers running firmware version 4.4.5 and earlier contain a command injection flaw in the Minidlna service. An authenticated remote attacker can manipulate a specific parameter to inject arbitrary commands, potentially allowing them to execute code on the device. The vulnerability requires administrative privileges to exploit and has been resolved in firmware version 4.7 through enhanced input validation added to the SDK.
- CVE-2026-11469MEDIUM 4.7
A vulnerability exists in jishenghua jshERP versions up to 3.6 that allows an authenticated administrator to perform server-side request forgery (SSRF) attacks by manipulating configuration parameters. An attacker with high-level privileges can craft malicious input to the platformConfig add endpoint, causing the server to make unintended requests to internal or external systems. This vulnerability requires authentication and administrative access to exploit, limiting immediate risk but potentially enabling lateral movement or data exfiltration once an admin account is compromised.
- CVE-2026-11596MEDIUM 4.7
ScreenConnect versions before 26.2 contain a weakness in how it validates input when administrators or authorized users create Host Pass tokens—special access credentials that grant temporary delegated access. An authenticated user with Host Pass creation privileges can bypass the intended expiration time limits and specify tokens that remain valid far longer than intended, potentially allowing extended unauthorized access to systems after the token should have expired.
- CVE-2026-11621MEDIUM 4.7
Dcat-Admin versions up to 2.2.3-beta contain a file upload vulnerability in the User Setting Page. An authenticated administrator can upload arbitrary files by manipulating the image upload parameter in the editor component, potentially leading to code execution or data compromise. The vulnerability requires high-level privileges but poses a meaningful risk in multi-user admin environments.
- CVE-2026-12002MEDIUM 4.7
A WordPress plugin called Smash Balloon Social Photo Feed contains a security flaw that allows attackers to hijack the site's connection to Instagram and Facebook. The vulnerability exists because the plugin doesn't properly verify that requests to change authentication tokens actually come from authorized administrators. An attacker can craft a malicious link that, when clicked by a site admin, silently swaps out the legitimate access tokens for attacker-controlled ones. This doesn't give immediate visibility into private data, but it severs the site's legitimate social media feeds and could allow the attacker to post content or monitor activity through those accounts.
- CVE-2026-12175MEDIUM 4.7
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its student creation interface. An authenticated administrator can exploit this flaw by manipulating the admission number field to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive student and attendance data. The vulnerability requires valid admin credentials to exploit, but the attack itself is straightforward and exploit code is publicly available.
- CVE-2026-12311MEDIUM 4.7
CVE-2026-12311 is a sandbox escape vulnerability in Firefox and Thunderbird that can leak information to an attacker. The flaw exists in the process sandboxing security component and requires user interaction—such as clicking a link or visiting a malicious webpage—to trigger. While the vulnerability is rated as medium severity, it undermines a critical security boundary, allowing an attacker to read sensitive information that should be isolated within the sandbox. This affects current-generation Firefox and Thunderbird releases.
- CVE-2026-12313MEDIUM 4.7
A vulnerability in Firefox and Thunderbird's process sandboxing mechanism allows an attacker to leak sensitive information and potentially escape the sandbox through a crafted webpage or message. The attack requires user interaction (such as visiting a malicious site or opening a specially prepared message) and affects your system's security boundary—the sandbox that isolates the browser process from the rest of your computer. Mozilla has patched this in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- CVE-2026-12463MEDIUM 4.7
Google Chrome on Linux contains a flaw in how it handles Views that allows an attacker who has already compromised Chrome's rendering engine to inject malicious scripts or HTML content into web pages. This is a secondary attack—the attacker must first gain control of the renderer process before exploiting this vulnerability. The flaw affects Chrome versions prior to 149.0.7827.155 on Linux systems.
- CVE-2026-12789MEDIUM 4.7
ILIAS Learning Management System version 11.0 contains a SQL injection vulnerability in its Learning Progress Tracking component. An authenticated administrator can manipulate a parameter called troup_table_nav to inject malicious SQL commands, potentially allowing unauthorized data access or modification within the LMS database. The vulnerability requires administrative privileges to exploit and poses a medium-severity risk to institutions using this open-source learning platform.
- CVE-2026-13034MEDIUM 4.7
Google Chrome versions before 149.0.7827.197 contain a flaw in how it handles passwords that allows an attacker who has already compromised Chrome's renderer process to break out of site isolation—Chrome's critical security boundary that prevents malicious websites from accessing data belonging to other websites. An attacker would need to trick a user into visiting a specially crafted webpage after first gaining control of the renderer, but if successful, could view sensitive information like passwords or cookies from other sites.
- CVE-2026-13495MEDIUM 4.7
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the /adminprofile.php file. An attacker with administrative privileges can manipulate the loginid parameter to inject malicious SQL commands, potentially allowing unauthorized data access or modification. The vulnerability has been publicly disclosed and is remotely exploitable, though it requires high-level privileges to execute.
- CVE-2026-13569MEDIUM 4.7
A SQL injection vulnerability exists in EyouCMS versions up to 1.7.1, affecting the API endpoint at /index.php. An authenticated attacker can inject malicious SQL commands through the 'click_like' parameter to manipulate database queries. The vulnerability requires administrative or high-privilege credentials to exploit, but once triggered, allows an attacker to read, modify, or delete sensitive database records. Public exploit code is already available.
- CVE-2026-13812MEDIUM 4.7
A vulnerability in Google Chrome for iOS allows attackers to inject malicious scripts or HTML into web pages through specific user interactions. An attacker would need to convince a user to perform particular gestures on a crafted webpage to exploit this flaw. The vulnerability stems from insufficient validation of user-supplied input before processing it in the browser's rendering engine.
- CVE-2026-14361MEDIUM 4.7
Consul-template versions before 0.42.1 contain a vulnerability in how the writeToFile template helper processes file paths. An attacker with local access and limited privileges could potentially craft a malicious template that writes output to unintended directories or overwrites existing files on the system. This is a local privilege escalation concern rather than a remote vulnerability, and requires active template manipulation to exploit.
- CVE-2026-14620MEDIUM 4.7
webpack-dev-server, a popular development utility for JavaScript applications, contains a cross-site request forgery (CSRF) vulnerability that allows any website a developer visits to secretly perform actions on their local development server. Specifically, two internal endpoints that manage file editing and code recompilation accept requests from external sites without verification. An attacker can craft a malicious webpage that, when opened by a developer, triggers these endpoints to open arbitrary files on the developer's system in their code editor or force wasteful recompilations. The vulnerability affects webpack-dev-server version 5.2.5 and earlier.
- CVE-2026-15173MEDIUM 4.7
Wireshark versions 4.6.0 through 4.6.6 contain a flaw in how they parse pcapng packet capture files. A malformed pcapng file can cause Wireshark to crash, denying service to users who open the file. An attacker would need to trick a user into opening a specially crafted pcapng file, but requires no special privileges and the attack leaves no data integrity or confidentiality impact—only availability is affected.
- CVE-2026-2827MEDIUM 4.7
The Open User Map PRO WordPress plugin contains a security flaw that allows attackers to inject malicious scripts into website pages. An unauthenticated attacker can exploit insufficient input validation in the 'oum_location_notification' parameter to store harmful code that executes whenever site visitors view an affected page. This stored cross-site scripting (XSS) vulnerability affects all versions up to and including 1.4.31.
- CVE-2026-3602MEDIUM 4.7
IBM App Connect Enterprise and Integration Bus contain a SQL injection vulnerability that could allow a remote attacker to trick users into inadvertently creating files on their systems. While the attack requires user interaction and operates with local system access constraints, successful exploitation could result in unauthorized file creation or modification. The vulnerability affects multiple versions across IBM's integration middleware stack.
- CVE-2026-41991MEDIUM 4.7
GNU gzip's gzexe utility has a flaw in how it creates temporary files when the mktemp utility is unavailable. Instead of using a secure method, it generates predictable temporary filenames based on the process ID (PID) alone. A local attacker can exploit this by creating a symbolic link at the predicted filename pointing to any file the victim can write to. When gzexe runs and follows that symlink, it overwrites the target file—giving an attacker a way to corrupt or modify files belonging to the user running gzexe.
- CVE-2026-42329MEDIUM 4.7
Iris, a web platform used by incident responders to collaborate and share technical details during security investigations, contains an open redirect vulnerability in versions before 2.4.28. An attacker can craft a malicious link within the application that tricks users into visiting an external website under the attacker's control. This is a social engineering risk rather than a direct system compromise—the attack depends on user interaction and targets the trust users place in links shared within their incident response platform.
- CVE-2026-43743MEDIUM 4.7
CVE-2026-43743 is a race condition affecting Apple's operating systems that can cause an application to unexpectedly crash or terminate the system. The vulnerability requires an attacker to already have code execution on the device (local access) and involves a timing-sensitive flaw in how the operating system handles concurrent operations. While the impact is limited to availability—the system can be made to crash—the fix is straightforward through standard OS updates.
- CVE-2026-44587MEDIUM 4.7
CarrierWave, a popular Ruby file-upload framework, contains a flaw in its content-type blocking mechanism that silently fails to prevent dangerous uploads. When developers configure a denylist to block file types—most commonly SVG files to prevent stored cross-site scripting (XSS)—the framework inadvertently allows those exact files through due to improper handling of special characters in the filter rules. An attacker can exploit this to upload malicious SVG files containing embedded JavaScript that executes in users' browsers when served by the application, resulting in account compromise or data theft.
- CVE-2026-44757MEDIUM 4.7
SAP Wily Introscope Enterprise Manager contains a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious code into a specially crafted URL. When a legitimate user visits that URL, the attacker's script runs in their browser under the application's security context. This could expose sensitive session data or allow the attacker to perform actions on behalf of the victim. The vulnerability requires the attacker to trick a user into clicking a link, and carries a CVSS 4.7 (Medium) severity rating.
- CVE-2026-45366MEDIUM 4.7
The @utcp/http package in typescript-utcp contains a blind Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to trick the software into making requests to internal services. The flaw stems from inconsistent validation: while manual URL registration checks that URLs are HTTPS or localhost, the tool invocation pathway skips this validation and directly uses URLs from attacker-controlled OpenAPI specifications. An attacker can host a malicious OpenAPI spec on a legitimate HTTPS endpoint that declares internal server addresses (like http://127.0.0.1:9090 or AWS metadata endpoints), and the affected software will create tools that point to those internal targets. Versions prior to 1.1.2 are vulnerable.
- CVE-2026-45460MEDIUM 4.7
A buffer over-read vulnerability in Microsoft Office could allow an attacker to read sensitive information from a user's computer. The attacker would need to trick a user into opening a specially crafted Office document, but once triggered, the flaw could expose data in memory that shouldn't be accessible. This is a local-only issue affecting the person using the Office application, not a remote attack vector.
- CVE-2026-45614MEDIUM 4.7
OP-TEE, a Trusted Execution Environment for Arm systems, fails to validate that ECDH public keys lie on the correct elliptic curve before deriving shared secrets. An attacker with local access can craft approximately 30-40 malformed public keys and submit them through TEE_DeriveKey calls to leak fragments of the private key. By collecting these leaks and applying the Chinese Remainder Theorem, the attacker can reconstruct the full private key. This breaks the confidentiality of ECDH operations and affects systems relying on OP-TEE for cryptographic operations prior to version 4.11.0.
- CVE-2026-46159MEDIUM 4.7
A race condition in the Linux kernel's btrfs filesystem driver can leak uninitialized kernel memory to unprivileged local users. The vulnerability exists in the ioctl handler that reports storage space information. When block groups are concurrently removed by the system during the space query operation, the kernel copies more data to userspace than it actually wrote, exposing sensitive kernel memory. An attacker with local access can exploit this timing window to read information that should not be accessible.
- CVE-2026-46187MEDIUM 4.7
The Linux kernel's RSI wireless driver has a race condition in how it shuts down worker threads. The driver uses two different methods to stop these threads: a self-terminating approach and an external stop command. When the self-terminating method completes first and then the external stop is called, the code tries to access a thread that has already been freed from memory—a use-after-free vulnerability. This affects local users with moderate privileges and can cause a system crash or unexpected behavior.
- CVE-2026-46194MEDIUM 4.7
A race condition exists in the Linux kernel's F2FS file system implementation that can cause a kernel crash. When an inode is being dropped from memory, the extent node destruction process does not properly signal that no new extent nodes should be added. Meanwhile, concurrent write-back operations may attempt to insert new extent nodes, creating a collision that triggers a kernel bug check. The vulnerability affects systems using F2FS, particularly in multi-threaded I/O scenarios where inode cleanup and write-back operations overlap.
- CVE-2026-46272MEDIUM 4.7
CVE-2026-46272 is a race condition in the Linux kernel's CoreSight Trace Memory Controller (TMC) Embedded Trace Receiver (ETR) driver. When a system attempts to run both performance tracing (perf) and sysfs-based hardware tracing simultaneously, a timing gap between buffer allocation and hardware enablement in sysfs mode allows the perf mode to initialize its own buffer state. This causes sysfs mode to later detect the unexpected state and trigger a kernel warning, resulting in denial of service through system instability. The vulnerability exists because the sysfs enablement process was split across two separate locking regions, creating a window where perf mode could intervene.