Vulnerabilities

  

CVE-2026-76460 | Cisco Identity Services Engine Software API improper authentication

A vulnerability classified as very critical was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. This

  

CVE-2026-76413 | Cisco Secure Firewall Management Center up to 10.0.1 SSO improper authentication

A vulnerability, which was classified as critical, has been found in Cisco Secure Firewall Management Center. This impacts an unknown

  

CVE-2026-76425 | Cisco Identity Services Engine up to 3.5.0 APIs sql injection

A vulnerability, which was classified as problematic, was found in Cisco Identity Services Engine. Affected is an unknown function of

  

CVE-2026-20309 | Cisco Identity Services Engine up to 3.5.0 Web-based Management Interface cross site scripting

A vulnerability has been found in Cisco Identity Services Engine and classified as problematic. Affected by this vulnerability is an

  

CVE-2026-85469 | Red Hat Quay quay-builder-qemu behavioral workflow

A vulnerability was found in Red Hat Quay. It has been classified as problematic. This affects an unknown part of

  

CVE-2026-92828 | service-ca-operator privileges management

A vulnerability was found in service-ca-operator. It has been declared as very critical. This vulnerability affects unknown code. Such manipulation

  

CVE-2026-92593 | craftcms Craft CMS up to 5.10.12 Redirect renderObjectTemplate returnUrl/redirect special elements in template engine

A vulnerability was found in craftcms Craft CMS up to 5.10.12. It has been rated as critical. This issue affects

  

CVE-2026-92580 | WWBN AVideo up to 29.0 CloneSite cloneClient.json.php str_replace Password os command injection

A vulnerability categorized as very critical has been discovered in WWBN AVideo up to 29.0. Impacted is the function str_replace

  

CVE-2026-92592 | craftcms Craft CMS up to 4.18.5/5.10.12 Twig template system redirect

A vulnerability identified as problematic has been detected in craftcms Craft CMS up to 4.18.5/5.10.12. The affected element is the

  

CVE-2026-92585 | WWBN AVideo up to 29.0 API like endpoint set.json.php APIName permission

A vulnerability labeled as critical has been found in WWBN AVideo up to 29.0. The impacted element is an unknown

  

CVE-2026-92579 | WWBN AVideo up to 29.0 on WordPress login.json.php autoCSRFGuard cross-site request forgery

A vulnerability marked as problematic has been reported in WWBN AVideo up to 29.0 on WordPress. This affects the function

  

CVE-2026-92584 | WWBN AVideo up to 29.0 Unauthenticated View-Counter Endpoint videoAddViewCount.json.php VideoStatistic::save cross site scripting

A vulnerability described as problematic has been identified in WWBN AVideo up to 29.0. This impacts the function VideoStatistic::save of

  

CVE-2026-92582 | WWBN AVideo up to 29.0 CSRF Check Bypass videoAddNew.json.php loginFromRequestIfNotLogged user/pass cross-site request forgery (e01e41ecc)

A vulnerability classified as problematic has been found in WWBN AVideo up to 29.0. Affected is the function User::loginFromRequestIfNotLogged of

  

CVE-2026-92591 | Craft CMS up to 5.10.12 Installer Site::getName information disclosure

A vulnerability classified as problematic was found in Craft CMS up to 5.10.12. Affected by this vulnerability is the function

  

CVE-2026-92583 | WWBN AVideo up to 29.0 Brute-Force Protection enforceRateLimit race condition

A vulnerability, which was classified as critical, has been found in WWBN AVideo up to 29.0. Affected by this issue

  

CVE-2026-92587 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 Git node path traversal

A vulnerability, which was classified as critical, was found in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. This affects an unknown part

  

CVE-2026-92578 | WWBN AVideo up to 29.0 loginFromRequest/encryptPasswordVerify weak password hash

A vulnerability has been found in WWBN AVideo up to 29.0 and classified as problematic. This vulnerability affects the function

  

CVE-2026-92588 | n8n-io n8n prior 1.123.76/2.37.7/2.38.2 Source Control Push Endpoint privileges management

A vulnerability was found in n8n-io n8n and classified as problematic. This issue affects some unknown processing of the component

  

CVE-2026-92586 | WWBN AVideo up to 29.0 Comment API set_api_comment permission

A vulnerability was found in WWBN AVideo up to 29.0. It has been classified as problematic. Impacted is the function

  

CVE-2026-61592 | djust-org djust up to 1.0.6 Session Management session_id state issue

A vulnerability was found in djust-org djust up to 1.0.6. It has been declared as critical. The affected element is

  

CVE-2026-61597 | djust-org djust up to 1.0.6 Template Tags neutralization

A vulnerability was found in djust-org djust up to 1.0.6. It has been rated as critical. The impacted element is

  

CVE-2026-92577 | WWBN AVideo up to 29.0 access control

A vulnerability categorized as problematic has been discovered in WWBN AVideo up to 29.0. This affects an unknown function. The

  

CVE-2026-92581 | WWBN AVideo up to 29.0 Like Like::__construct like race condition

A vulnerability identified as problematic has been detected in WWBN AVideo up to 29.0. This impacts the function Like::__construct of

  

CVE-2026-92589 | craftcms Craft CMS up to 5.10.12 Nested Elements Reorder reorder offset privileges management

A vulnerability labeled as problematic has been found in craftcms Craft CMS up to 5.10.12. Affected is an unknown function

  

CVE-2026-92576 | HKUDS nanobot up to 0.2.x WebFetchTool _validate_url server-side request forgery

A vulnerability marked as problematic has been reported in HKUDS nanobot up to 0.2.x. Affected by this vulnerability is the

  

CVE-2026-92590 | Craft CMS up to 5.10.12 Generated Fields cross site scripting

A vulnerability described as problematic has been identified in Craft CMS up to 5.10.12. Affected by this issue is some

  

CVE-2026-76438 | Cisco BroadWorks Web-based Management Interface improper authorization

A vulnerability classified as problematic has been found in Cisco BroadWorks. This affects an unknown part of the component Web-based

  

CVE-2026-61599 | djust-org djust up to 1.0.6 Live Transport __import__ view input validation

A vulnerability classified as critical was found in djust-org djust up to 1.0.6. This vulnerability affects the function __import__ of

  

CVE-2026-61596 | djust-org djust up to 1.0.6 Render Entry Points get_object/has_object_permission authorization

A vulnerability, which was classified as critical, has been found in djust-org djust up to 1.0.6. This issue affects the

  

CVE-2026-61589 | djust-org djust up to 1.0.6 Tenant Resolution ViewRuntime._build_request information disclosure

A vulnerability, which was classified as problematic, was found in djust-org djust up to 1.0.6. Impacted is the function ViewRuntime._build_request

  

CVE-2026-61594 | djust-org djust up to 1.0.6 WebSocket Transport check_view_auth improper authorization

A vulnerability has been found in djust-org djust up to 1.0.6 and classified as critical. The affected element is the

  

CVE-2026-92596 | Nodemailer up to 9.0.x Addressparser resource consumption

A vulnerability was found in Nodemailer up to 9.0.x and classified as problematic. The impacted element is an unknown function

  

CVE-2026-92597 | Nodemailer up to 9.0.x Addressparser lib/addressparser input validation

A vulnerability was found in Nodemailer up to 9.0.x. It has been classified as critical. This affects an unknown function

  

CVE-2026-92599 | hapijs joi up to 17.13.6/18.0.0-18.2.5 isoDate Joi.string.isoDate redos

A vulnerability was found in hapijs joi up to 17.13.6/18.0.0-18.2.5. It has been declared as problematic. This impacts the function

  

CVE-2026-89034 | TCH QRing RT09R20_1.00.00_250318 Nordic UART Service improper authorization

A vulnerability was found in TCH QRing RT09R20_1.00.00_250318. It has been rated as problematic. Affected is an unknown function of

  

CVE-2026-81875 | hapifhir org.hl7.fhir.core up to 6.9.11 SHCParser SHCParser.java SHCParser.decodeJWT input validation

A vulnerability classified as problematic was found in hapifhir org.hl7.fhir.core up to 6.9.11. Impacted is the function SHCParser.decodeJWT of the

  

CVE-2026-59823 | BerriAI LiteLLM up to 1.83.8 Request Body Validator user_config server-side request forgery

A vulnerability, which was classified as critical, has been found in BerriAI LiteLLM up to 1.83.8. The affected element is

  

CVE-2026-77360 | middleapi orpc up to 1.14.7 CORS cors.ts cross-domain policy

A vulnerability, which was classified as problematic, was found in middleapi orpc up to 1.14.7. The impacted element is an

  

CVE-2026-82399 | CoreDNS up to 1.14.6 DNS-over-HTTPS plugin/pkg/doh/doh.go dns.Msg.Unpack allocation of resources

A vulnerability has been found in CoreDNS up to 1.14.6 and classified as problematic. This affects the function dns.Msg.Unpack of

  

CVE-2026-86003 | CoreDNS up to 1.14.6 DNS-over-HTTPS Listener plugin/pkg/doh/doh.go dns.Msg.Unpack privileges management

A vulnerability was found in CoreDNS up to 1.14.6 and classified as problematic. This impacts the function dns.Msg.Unpack of the

  

CVE-2026-91105 | HP HPLIP up to 3.26.5 privileges management

A vulnerability was found in HP HPLIP up to 3.26.5. It has been classified as critical. Affected is an unknown

  

CVE-2026-91106 | HP HPLIP up to 3.26.5 privilege escalation

A vulnerability was found in HP HPLIP up to 3.26.5. It has been declared as critical. Affected by this vulnerability

  

CVE-2026-91100 | HP Linux Imaging and Printing Software up to 3.26.5 privileges management

A vulnerability was found in HP Linux Imaging and Printing Software up to 3.26.5. It has been rated as critical.

  

CVE-2026-91101 | HP HPLIP up to 3.26.5 privileges management

A vulnerability categorized as critical has been discovered in HP HPLIP up to 3.26.5. This affects an unknown part. Executing

  

CVE-2026-91102 | HP HPLIP up to 3.26.5 privileges management

A vulnerability identified as critical has been detected in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The

  

CVE-2026-91103 | HP HPLIP up to 3.26.5 information disclosure

A vulnerability labeled as problematic has been found in HP HPLIP up to 3.26.5. This issue affects some unknown processing.

  

CVE-2026-81876 | HAPI FHIR org.hl7.fhir.core up to 6.9.11 SHCParser SHCParser.java SHCParser.decodeJWT input validation

A vulnerability marked as problematic has been reported in HAPI FHIR org.hl7.fhir.core up to 6.9.11. Impacted is the function SHCParser.decodeJWT

  

CVE-2026-73456 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F gRPC Network Packet Sampling Interface code injection

A vulnerability described as very critical has been identified in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. The affected element is an

  

CVE-2026-86043 | Zalando Skipper up to 0.27.36 opaAuthorizeRequestWithBody Filter openpolicyagent.go improper authorization

A vulnerability classified as problematic has been found in Zalando Skipper up to 0.27.36. The impacted element is the function

  

CVE-2026-73442 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP missing encryption

A vulnerability classified as problematic was found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This affects an unknown function of the

  

CVE-2026-73443 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP authentication replay

A vulnerability, which was classified as critical, has been found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This impacts an unknown

  

CVE-2026-73457 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F gRPC Network Packet Sampling Interface information disclosure

A vulnerability, which was classified as problematic, was found in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. Affected is an unknown function

  

CVE-2026-79298 | Howyar SysReturn prior 11.3.0.34 BOOTia32.efi os command injection

A vulnerability has been found in Howyar SysReturn and classified as very critical. Affected by this vulnerability is an unknown

  

CVE-2026-73462 | Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.1F IGMP Snooping Agent input validation

A vulnerability was found in Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.1F and classified as critical. Affected by this issue is some

  

CVE-2026-86071 | Junrar up to 7.6.0 LocalFolderExtractor LocalFolderExtractor.java LocalFolderExtractor.makeFile path traversal

A vulnerability was found in Junrar up to 7.6.0. It has been classified as problematic. This affects the function LocalFolderExtractor.makeFile

  

CVE-2026-91104 | HP Linux Imaging and Printing Software/HPLIP up to 3.26.5 privileges management

A vulnerability was found in HP Linux Imaging and Printing Software and HPLIP up to 3.26.5. It has been declared

  

CVE-2026-89082 | HP Advance privileges management

A vulnerability was found in HP Advance. It has been rated as very critical. This issue affects some unknown processing.

  

CVE-2026-86831 | AWS aws-network-policy-agent/amazon-vpc-cni-k8s Pod Identifier Validation access control

A vulnerability categorized as very critical has been discovered in AWS aws-network-policy-agent and amazon-vpc-cni-k8s. Impacted is an unknown function of

  

CVE-2026-88592 | sg-summer kkFileView 4.2.0 Cross-Origin File Proxy Endpoint urlPath server-side request forgery

A vulnerability identified as critical has been detected in sg-summer kkFileView 4.2.0. The affected element is an unknown function of

  

CVE-2026-87076 | Tanium Discover up to 4.10.189/4.15.197/4.19.113 information disclosure

A vulnerability labeled as problematic has been found in Tanium Discover up to 4.10.189/4.15.197/4.19.113. The impacted element is an unknown

  

CVE-2026-86865 | Tanium Asset up to 1.33.325/1.36.173/1.39.152 sql injection

A vulnerability marked as critical has been reported in Tanium Asset up to 1.33.325/1.36.173/1.39.152. This affects an unknown function. Performing

  

CVE-2026-87024 | Tanium Asset up to 1.33.325/1.36.173/1.39.152 sql injection

A vulnerability described as critical has been identified in Tanium Asset up to 1.33.325/1.36.173/1.39.152. This impacts an unknown function. Executing

  

CVE-2026-87026 | Tanium Threat Response up to 4.9.453/4.12.323/4.17.291 access control

A vulnerability classified as problematic has been found in Tanium Threat Response up to 4.9.453/4.12.323/4.17.291. Affected is an unknown function.

  

CVE-2026-87105 | Tanium Threat Response up to 4.9.446/4.12.316/4.17.288 sql injection

A vulnerability classified as critical was found in Tanium Threat Response up to 4.9.446/4.12.316/4.17.288. Affected by this vulnerability is an

  

CVE-2026-87113 | Tanium Threat Response up to 4.9.448/4.12.318/4.17.290 access control

A vulnerability, which was classified as critical, has been found in Tanium Threat Response up to 4.9.448/4.12.318/4.17.290. Affected by this

  

CVE-2026-87116 | Tanium Threat Response up to 4.9.453/4.12.323/4.17.291 server-side request forgery

A vulnerability, which was classified as problematic, was found in Tanium Threat Response up to 4.9.453/4.12.323/4.17.291. This affects an unknown

  

CVE-2026-20176 | Cisco Identity Services Engine Software up to 3.5.0 os command injection

A vulnerability has been found in Cisco Identity Services Engine Software and classified as very critical. This vulnerability affects unknown

  

CVE-2026-20211 | Cisco Identity Services Engine up to 3.5.0 deserialization

A vulnerability was found in Cisco Identity Services Engine and classified as very critical. This issue affects some unknown processing.

  

CVE-2026-20242 | Cisco Secure Firewall Management Center up to 10.0.1 External Database Access deserialization

A vulnerability was found in Cisco Secure Firewall Management Center. It has been classified as very critical. Impacted is an

  

CVE-2026-20194 | Cisco Identity Services Engine resource transfer

A vulnerability was found in Cisco Identity Services Engine and ISE Passive Identity Connector. It has been declared as very

  

CVE-2026-20324 | Cisco Secure Firewall Management Center up to 10.0.1 sftunnel permission

A vulnerability was found in Cisco Secure Firewall Management Center. It has been rated as very critical. The impacted element

  

CVE-2026-20341 | Cisco Secure Firewall Management Center up to 10.0.1 sftunnel deserialization

A vulnerability categorized as very critical has been discovered in Cisco Secure Firewall Management Center. This affects an unknown function

  

CVE-2026-20130 | Cisco Identity Services Engine injection

A vulnerability identified as very critical has been detected in Cisco Identity Services Engine and ISE Passive Identity Connector. This

  

CVE-2026-20192 | Cisco Identity Services Engine access control

A vulnerability labeled as very critical has been found in Cisco Identity Services Engine and ISE Passive Identity Connector. Affected

  

CVE-2026-20237 | Cisco Identity Services Engine input validation

A vulnerability marked as very critical has been reported in Cisco Identity Services Engine and ISE Passive Identity Connector. Affected

  

CVE-2026-20322 | Cisco Nexus Dashboard up to 4.2.1 access control

A vulnerability described as very critical has been identified in Cisco Nexus Dashboard. Affected by this issue is some unknown

  

CVE-2026-20325 | Cisco Nexus Dashboard up to 4.2.1 command injection

A vulnerability classified as very critical has been found in Cisco Nexus Dashboard. This affects an unknown part. This manipulation

  

CVE-2026-20326 | Cisco Nexus Dashboard up to 4.2.1 missing authentication

A vulnerability classified as very critical was found in Cisco Nexus Dashboard. This vulnerability affects unknown code. Such manipulation leads

  

CVE-2026-20329 | Cisco Secure Adaptive Security Appliance Software improper check or handling of exceptional conditions

A vulnerability, which was classified as very critical, has been found in Cisco Secure Adaptive Security Appliance Software, Secure Firewall

  

CVE-2026-20330 | Cisco Secure Firewall Adaptive Security Appliance Software neutralization

A vulnerability, which was classified as very critical, was found in Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall

  

CVE-2026-20361 | Cisco Nexus Dashboard up to 4.2.1 sql injection

A vulnerability has been found in Cisco Nexus Dashboard and classified as critical. The affected element is an unknown function.

  

CVE-2026-76423 | Cisco Identity Services Engine REST API improper authorization

A vulnerability was found in Cisco Identity Services Engine and ISE Passive Identity Connector and classified as very critical. The

  

CVE-2026-62949 | ronf asyncssh up to 2.23.x Channel asyncssh/connection.py send_pktsize infinite loop

A vulnerability was found in ronf asyncssh up to 2.23.x. It has been classified as problematic. This affects the function

  

CVE-2026-81870 | OpenTelemetry OpenTelemetry-Go up to 1.44.x MarshalLog sdk/trace.NewTracerProvider information disclosure

A vulnerability was found in OpenTelemetry OpenTelemetry-Go up to 1.44.x. It has been declared as problematic. This impacts the function

  

CVE-2026-92808 | Altium Enterprise Server up to 8.1.0 UnifiedLogin service server-side request forgery

A vulnerability was found in Altium Enterprise Server up to 8.1.0. It has been rated as critical. Affected is an

  

CVE-2026-59944 | Composer up to 2.2.29/2.10.2 Symlink installed.json symlink

A vulnerability, which was classified as problematic, was found in Composer up to 2.2.29/2.10.2. The affected element is an unknown

  

CVE-2026-59974 | Stanford NLP Stanza up to 1.13.x Unzip common.py stanza.resources.common.unzip path traversal

A vulnerability has been found in Stanford NLP Stanza up to 1.13.x and classified as critical. The impacted element is

  

CVE-2026-92600 | stylefeng Guns up to 8.3.5 SysUserController information disclosure

A vulnerability was found in stylefeng Guns up to 8.3.5 and classified as problematic. This affects an unknown function of

  

CVE-2026-69200 | node-opcua up to 2.144.x node-opcua-client client_alarm.ts fieldsToJson prototype pollution

A vulnerability was found in node-opcua up to 2.144.x. It has been classified as critical. This impacts the function fieldsToJson

  

CVE-2026-92601 | stylefeng Guns up to 8.3.5 SysNoticeController requiredPermission access control

A vulnerability was found in stylefeng Guns up to 8.3.5. It has been declared as problematic. Affected is an unknown

  

CVE-2026-71179 | Dell Update Package Framework up to 26.07.2 os command injection

A vulnerability was found in Dell Update Package Framework up to 26.07.2. It has been rated as very critical. Affected

  

CVE-2026-71180 | Dell Update Package Framework 19.1.0.413/22.01.02 return value

A vulnerability categorized as critical has been discovered in Dell Update Package Framework 19.1.0.413/22.01.02. Affected by this issue is some

  

CVE-2026-71181 | Dell Update Package Framework path traversal

A vulnerability identified as very critical has been detected in Dell Update Package Framework. This affects an unknown part. Performing

  

CVE-2026-92602 | TDuckCloud TDuck Survey Form up to 5.3 Webhook Configuration WebhookConfigController privileges management

A vulnerability labeled as critical has been found in TDuckCloud TDuck Survey Form up to 5.3. This vulnerability affects the

  

CVE-2026-92603 | Continew Admin up to 4.1.0 Personal Message Delete Endpoint IdsReq authorization

A vulnerability marked as problematic has been reported in Continew Admin up to 4.1.0. This issue affects some unknown processing

  

CVE-2026-84993 | MikroORM up to 6.6.15/7.1.6 Shared SQL Layer direction sql injection

A vulnerability described as critical has been identified in MikroORM up to 6.6.15/7.1.6. Impacted is the function em.find/em.findOne/em.findAndCount/QueryBuilder.orderBy/QueryBuilderHelper.getQueryOrderFromObject of the

  

CVE-2026-87031 | Concrete CMS up to 9.5.3 REST API user creation endpoint Users.php add cross site scripting

A vulnerability classified as problematic has been found in Concrete CMS up to 9.5.3. The affected element is the function

  

CVE-2026-85731 | oras-project oras-go up to 2.6.1 Tar Extraction extractTarDirectory path traversal

A vulnerability classified as critical was found in oras-project oras-go up to 2.6.1. The impacted element is the function extractTarDirectory

  

CVE-2026-57173 | vllm-project vLLM up to 0.23.x Audio Decoder /v1/chat/completions AudioMediaIO.load_bytes resource consumption

A vulnerability, which was classified as problematic, has been found in vllm-project vLLM up to 0.23.x. This affects the function