Vulnerabilities

  

CVE-2026-76268 | Splunk Enterprise up to 10.2.6/10.4.2 Patroni REST API improper authentication

A vulnerability marked as very critical has been reported in Splunk Enterprise up to 10.2.6/10.4.2. This affects an unknown part

  

CVE-2026-76275 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 REST API improper authorization

A vulnerability described as problematic has been identified in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. This vulnerability affects unknown code of

  

CVE-2026-76277 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 Username Validation privileges management

A vulnerability classified as problematic has been found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. This issue affects some unknown processing

  

CVE-2026-76266 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 privileges management

A vulnerability classified as critical was found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. Impacted is an unknown function. Executing a

  

CVE-2026-107227 | AsyncHttpClient async-http-client up to 3.0.13 WebSocketClientCompressionHandler resource consumption

A vulnerability, which was classified as problematic, has been found in AsyncHttpClient async-http-client up to 3.0.13. The affected element is

  

CVE-2026-107228 | async-http-client up to 3.0.13 Cookie Store setHeader session fixiation

A vulnerability, which was classified as critical, was found in async-http-client up to 3.0.13. The impacted element is the function

  

CVE-2026-76264 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.5/10.4.1 Scripted Lookup privileges management

A vulnerability has been found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.5/10.4.1 and classified as problematic. This affects an unknown function

  

CVE-2026-76269 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 REST API improper authorization

A vulnerability was found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 and classified as problematic. This impacts an unknown function of

  

CVE-2026-76270 | Splunk Enterprise up to 10.4.2 SPL2 Module Filtering sql injection

A vulnerability was found in Splunk Enterprise up to 10.4.2. It has been classified as critical. Affected is an unknown

  

CVE-2026-76272 | Splunk Enterprise/Secure Gateway improper authorization

A vulnerability was found in Splunk Enterprise and Secure Gateway. It has been declared as problematic. Affected by this vulnerability

  

CVE-2026-76273 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 Collect Command collect index name input validation

A vulnerability was found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. It has been rated as problematic. Affected by this issue

  

CVE-2026-76279 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 Collect Command privileges management

A vulnerability categorized as problematic has been discovered in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. This affects an unknown part of

  

CVE-2026-76281 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 access control

A vulnerability identified as very critical has been detected in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. This vulnerability affects unknown code.

  

CVE-2026-76271 | Splunk Enterprise up to 10.0.9/10.2.6/10.4.2 Discover Splunk Observability Cloud App resource consumption

A vulnerability labeled as problematic has been found in Splunk Enterprise up to 10.0.9/10.2.6/10.4.2. This issue affects some unknown processing

  

CVE-2026-76276 | Splunk Enterprise up to 10.0.9/10.2.6/10.4.2 Source Maps information disclosure

A vulnerability marked as problematic has been reported in Splunk Enterprise up to 10.0.9/10.2.6/10.4.2. Impacted is an unknown function of

  

CVE-2026-76274 | Splunk Enterprise up to 10.0.9/10.2.6/10.4.2 Splunk App for Splunk Observability Cloud redirect

A vulnerability described as problematic has been identified in Splunk Enterprise up to 10.0.9/10.2.6/10.4.2. The affected element is an unknown

  

CVE-2026-76280 | Splunk Enterprise/Splunk Secure Gateway up to 10.4.2 App Key Value Store improper authorization

A vulnerability classified as critical has been found in Splunk Enterprise and Splunk Secure Gateway up to 10.4.2. The impacted

  

CVE-2026-76267 | Splunk Enterprise up to 10.0.9/10.2.6/10.4.2 Splunk App for Splunk O11y Cloud injection

A vulnerability classified as problematic was found in Splunk Enterprise up to 10.0.9/10.2.6/10.4.2. This affects an unknown function of the

  

CVE-2026-76278 | Splunk Enterprise up to 10.0.9/10.2.6/10.4.2 SPL2 module privileges management

A vulnerability, which was classified as problematic, has been found in Splunk Enterprise up to 10.0.9/10.2.6/10.4.2. This impacts an unknown

  

CVE-2026-76282 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 allocation of resources

A vulnerability, which was classified as very critical, was found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. Affected is an unknown

  

CVE-2026-76283 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 protection mechanism

A vulnerability has been found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 and classified as critical. Affected by this vulnerability is

  

CVE-2026-76284 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 neutralization

A vulnerability was found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 and classified as very critical. Affected by this issue is

  

CVE-2026-76285 | Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2 isolation

A vulnerability was found in Splunk Enterprise up to 9.4.14/10.0.9/10.2.6/10.4.2. It has been classified as critical. This affects an unknown

  

CVE-2026-76286 | Splunk MCP Server up to 1.2.0 access control

A vulnerability was found in Splunk MCP Server up to 1.2.0. It has been declared as problematic. This vulnerability affects

  

CVE-2026-107229 | async-http-client up to 2.16.1/3.0.13 ThreadSafeCookieStore session fixiation

A vulnerability was found in async-http-client up to 2.16.1/3.0.13. It has been rated as problematic. This issue affects some unknown

  

CVE-2026-106108 | Quasar Framework SSG Page getSsgPages filename path traversal

A vulnerability was found in Quasar Framework and classified as critical. Affected by this vulnerability is the function getSsgPages of

  

CVE-2026-107211 | qax-os excelize up to 2.11.0 Pivot Table Processing extractPivotTableFields fld memory corruption

A vulnerability was found in qax-os excelize up to 2.11.0. It has been classified as problematic. Affected by this issue

  

CVE-2026-96335 | WPMU DEV Forminator Plugin up to 1.57.2 on WordPress authorization

A vulnerability was found in WPMU DEV Forminator Plugin up to 1.57.2 on WordPress. It has been declared as problematic.

  

CVE-2026-107212 | qax-os excelize up to 2.11.0 Rows File.GetRows row resource consumption

A vulnerability was found in qax-os excelize up to 2.11.0. It has been rated as problematic. This vulnerability affects the

  

CVE-2026-106066 | Red Hat Enterprise Linux Raw Data Export g_malloc integer overflow

A vulnerability categorized as very critical has been discovered in Red Hat Enterprise Linux. This issue affects the function g_malloc

  

CVE-2026-107213 | qax-os Excelize up to 2.11.0 Drawing File.GetSlicers null pointer dereference

A vulnerability identified as problematic has been detected in qax-os Excelize up to 2.11.0. Impacted is the function File.GetSlicers of

  

CVE-2026-106067 | Red Hat Enterprise Linux Hot color filter plug-in integer overflow

A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux. The affected element is an unknown function

  

CVE-2026-107216 | Qax-os Excelize up to 2.11.0 ANCHORARRAY CalcCellValue stack-based overflow

A vulnerability marked as problematic has been reported in Qax-os Excelize up to 2.11.0. The impacted element is the function

  

CVE-2026-107215 | qax-os Excelize up to 2.11.0 CFB Directory extractPart buffer size

A vulnerability described as problematic has been identified in qax-os Excelize up to 2.11.0. This affects the function extractPart of

  

CVE-2026-107214 | qax-os Excelize up to 2.11.0 Decryption Dispatch Decrypt uncaught exception

A vulnerability classified as problematic has been found in qax-os Excelize up to 2.11.0. This impacts the function Decrypt of

  

CVE-2026-56851 | x-text-secure-precis up to 0.40.x Nickname Profile out-of-bounds write

A vulnerability classified as critical was found in x-text-secure-precis up to 0.40.x. Affected is an unknown function of the component

  

CVE-2026-103371 | Apache Geode Management REST API log file

A vulnerability, which was classified as problematic, has been found in Apache Geode. Affected by this vulnerability is an unknown

  

CVE-2026-107313 | pgjdbc 42.7.4/42.7.5 GSS Encryption information disclosure

A vulnerability, which was classified as problematic, was found in pgjdbc 42.7.4/42.7.5. Affected by this issue is the function setString/setBytes/ByteStreamWriter/CopyIn.writeToCopy/LargeObject.write

  

CVE-2026-106164 | Progress Telerik Document Processing Libraries 2024.4.1106/2025.1.205 SpreadProcessing infinite loop

A vulnerability has been found in Progress Telerik Document Processing Libraries 2024.4.1106/2025.1.205 and classified as critical. This affects an unknown

  

CVE-2026-107220 | qax-os excelize up to 2.11.0 mergeCellsParser cellInRange out-of-bounds

A vulnerability was found in qax-os excelize up to 2.11.0 and classified as problematic. This vulnerability affects the function cellInRange

  

CVE-2026-107217 | qax-os excelize up to 1.4.1/2.11.0 Column Name Parser ColumnNameToNumber integer overflow

A vulnerability was found in qax-os excelize up to 1.4.1/2.11.0. It has been classified as problematic. This issue affects the

  

CVE-2026-107218 | qax-os excelize up to 2.11.0 Formula Evaluation CalcCellValue out-of-bounds

A vulnerability was found in qax-os excelize up to 2.11.0. It has been declared as problematic. Impacted is the function

  

CVE-2026-107219 | qax-os excelize up to 2.11.0 Agile Decryption openFile spinCount resource consumption

A vulnerability was found in qax-os excelize up to 2.11.0. It has been rated as problematic. The affected element is

  

CVE-2026-107221 | qax-os Excelize up to 2.11.0 Non-streaming Worksheet API GetCellValue out-of-bounds

A vulnerability categorized as problematic has been discovered in qax-os Excelize up to 2.11.0. The impacted element is the function

  

CVE-2026-107161 | Cyrus Cyrus-SASL add_to_challenge heap-based overflow

A vulnerability identified as very critical has been detected in Cyrus Cyrus-SASL. This affects the function add_to_challenge. Performing a manipulation

  

CVE-2026-107223 | qax-os excelize up to 2.11.0 Column Width flatCols Min/Max resource consumption

A vulnerability labeled as problematic has been found in qax-os excelize up to 2.11.0. This impacts the function flatCols of

  

CVE-2026-107224 | Qax-os Excelize up to 2.11.0 Zip64 ReadZipReader UncompressedSize64 integer overflow

A vulnerability marked as problematic has been reported in Qax-os Excelize up to 2.11.0. Affected is the function ReadZipReader of

  

CVE-2026-107225 | qax-os excelize up to 2.11.0 Style Extraction styles.xml GetStyle fillId/borderId/fontId input validation

A vulnerability described as problematic has been identified in qax-os excelize up to 2.11.0. Affected by this vulnerability is the

  

CVE-2026-107222 | qax-os Excelize up to 2.11.0 Conditional Format Extraction GetConditionalFormats null pointer dereference

A vulnerability classified as problematic has been found in qax-os Excelize up to 2.11.0. Affected by this issue is the

  

CVE-2026-62252 | sipcapture Homer up to 11.0.282 Bootstrap auth_bootstrap.go EnsureBootstrapAdminUser hard-coded credentials

A vulnerability labeled as critical has been found in sipcapture Homer up to 11.0.282. Impacted is the function EnsureBootstrapAdminUser of

  

CVE-2026-62176 | MervinPraison PraisonAI up to 4.6.77 Deploy API api.py subprocess.Popen agents_file code injection

A vulnerability marked as problematic has been reported in MervinPraison PraisonAI up to 4.6.77. The affected element is the function

  

CVE-2026-76437 | Cisco License On-Prem up to 10-202606 Web-based User Interface code injection

A vulnerability described as problematic has been identified in Cisco License On-Prem. The impacted element is an unknown function of

  

CVE-2026-62251 | SipCapture Homer up to 11.0.282 Statistics Query statistics_v4.go V4StatisticsQuery rawquery sql injection

A vulnerability classified as critical has been found in SipCapture Homer up to 11.0.282. This affects the function V4StatisticsQuery of

  

CVE-2026-20032 | Cisco NX-OS up to 10.6(3s) Python Interpreter sandbox

A vulnerability classified as very critical was found in Cisco NX-OS. This impacts an unknown function of the component Python

  

CVE-2026-20173 | Cisco NX-OS Software up to 10.5(5) Rate Limiting denial of service

A vulnerability, which was classified as critical, has been found in Cisco NX-OS Software. Affected is an unknown function of

  

CVE-2026-20321 | Cisco Application Policy Infrastructure Controller up to 6.2(2e) Web-based Management API os command injection

A vulnerability, which was classified as problematic, was found in Cisco Application Policy Infrastructure Controller up to 6.2(2e). Affected by

  

CVE-2026-76455 | Cisco NX-OS Software access control

A vulnerability has been found in Cisco NX-OS Software, NX-OS System Software in ACI Mode and Unified Computing System and

  

CVE-2026-76453 | Cisco NX-OS Software neutralization

A vulnerability was found in Cisco NX-OS Software, NX-OS System Software in ACI Mode and Unified Computing System and classified

  

CVE-2026-76456 | Cisco NX-OS Software input validation

A vulnerability was found in Cisco NX-OS Software, NX-OS System Software in ACI Mode and Unified Computing System. It has

  

CVE-2026-76457 | Cisco NX-OS Software out-of-bounds

A vulnerability was found in Cisco NX-OS Software, NX-OS System Software in ACI Mode and Unified Computing System. It has

  

CVE-2026-20038 | Cisco NX-OS System Software up to 16.2(2e) Endpoint Group Contract Functionality access control

A vulnerability was found in Cisco NX-OS System Software. It has been rated as problematic. Impacted is an unknown function

  

CVE-2026-20328 | Cisco License On-Prem up to 10-202606 Password Reset improper authorization

A vulnerability categorized as critical has been discovered in Cisco License On-Prem. The affected element is an unknown function of

  

CVE-2026-76454 | Cisco License On-Prem up to 10-202606 Smart Licensing Utility API input validation

A vulnerability identified as critical has been detected in Cisco License On-Prem. The impacted element is an unknown function of

  

CVE-2026-76452 | Cisco License On-Prem up to 10-202606 Web-based Management Interface sql injection

A vulnerability labeled as problematic has been found in Cisco License On-Prem. This affects an unknown function of the component

  

CVE-2026-92542 | Docker Engine Overlay Network Driver input validation

A vulnerability marked as very critical has been reported in Docker Engine. This impacts an unknown function of the component

  

CVE-2026-101886 | Cisco Jabber up to 11.1 ContentProvider display name path traversal

A vulnerability described as problematic has been identified in Cisco Jabber up to 11.1. Affected is an unknown function of

  

CVE-2026-20362 | Cisco Finesse up to 15.0(1)SU2 Web-based Management Interface server-side request forgery

A vulnerability classified as critical has been found in Cisco Finesse. Affected by this vulnerability is an unknown functionality of

  

CVE-2026-106557 | Backstage up to 1.14.5/1.15.3 plugin-techdocs-node access control

A vulnerability classified as problematic was found in Backstage up to 1.14.5/1.15.3. Affected by this issue is some unknown functionality

  

CVE-2026-62253 | SipCapture Homer up to 11.0.282 JWT Middleware JWTMiddleware/JWTMiddlewareV4 missing authentication

A vulnerability, which was classified as critical, has been found in SipCapture Homer up to 11.0.282. This affects the function

  

CVE-2026-76465 | Cisco NX-OS Software up to 10.6(3s) MPLS OAM code injection

A vulnerability, which was classified as very critical, was found in Cisco NX-OS Software. This vulnerability affects unknown code of

  

CVE-2026-76485 | Cisco NX-OS up to 10.6(3s) NGOAM input validation

A vulnerability has been found in Cisco NX-OS and classified as very critical. This issue affects some unknown processing of

  

CVE-2026-76486 | Cisco NX-OS up to 10.6(3s) NGOAM code injection

A vulnerability was found in Cisco NX-OS and classified as very critical. Impacted is an unknown function of the component

  

CVE-2026-76471 | Cisco NX-OS Software/Unified Computing System NX-API input validation

A vulnerability was found in Cisco NX-OS Software and Unified Computing System. It has been classified as very critical. The

  

CVE-2026-76458 | Cisco NX-OS Software/Unified Computing System improper check or handling of exceptional conditions

A vulnerability was found in Cisco NX-OS Software and Unified Computing System. It has been declared as critical. The impacted

  

CVE-2026-76459 | Cisco NX-OS Software out-of-bounds write

A vulnerability was found in Cisco NX-OS Software, NX-OS System Software in ACI Mode and Unified Computing System. It has

  

CVE-2026-76467 | Cisco Campus Gateway Software resource control

A vulnerability categorized as critical has been discovered in Cisco Campus Gateway Software, Meraki MR Wireless Access Points Software, Meraki

  

CVE-2026-76488 | Cisco Application Policy Infrastructure Controller up to 6.1(2g) Export Policies access control

A vulnerability identified as problematic has been detected in Cisco Application Policy Infrastructure Controller. Affected is an unknown function of

  

CVE-2026-76463 | Cisco Campus Gateway Software access control

A vulnerability labeled as very critical has been found in Cisco Campus Gateway Software, Meraki MR Wireless Access Points Software,

  

CVE-2026-76464 | Cisco Campus Gateway memory corruption

A vulnerability marked as very critical has been reported in Cisco Campus Gateway, Meraki MR Wireless Access Points, Meraki MV

  

CVE-2026-76469 | Cisco Campus Gateway Software insufficient control flow management

A vulnerability described as problematic has been identified in Cisco Campus Gateway Software, Meraki MR Wireless Access Points Software, Meraki

  

CVE-2026-76468 | Cisco Campus Gateway Software input validation

A vulnerability classified as critical has been found in Cisco Campus Gateway Software, Meraki MR Wireless Access Points Software, Meraki

  

CVE-2026-76470 | Cisco Campus Gateway Software calculation

A vulnerability classified as very critical was found in Cisco Campus Gateway Software, Meraki MR Wireless Access Points Software, Meraki

  

CVE-2026-76480 | Cisco License On-Prem up to 10-202608 missing authentication

A vulnerability, which was classified as very critical, has been found in Cisco License On-Prem. Impacted is an unknown function.

  

CVE-2026-76472 | Cisco Campus Gateway Software injection

A vulnerability, which was classified as critical, was found in Cisco Campus Gateway Software, Meraki MR Wireless Access Points Software,

  

CVE-2026-76482 | Cisco License On-Prem up to 10-202608 signature verification

A vulnerability has been found in Cisco License On-Prem and classified as very critical. The impacted element is an unknown

  

CVE-2026-76484 | Cisco License On-Prem up to 10-202608 code injection

A vulnerability was found in Cisco License On-Prem and classified as very critical. This affects an unknown function. The manipulation

  

CVE-2026-76483 | Cisco License On-Prem up to 10-202608 insufficiently protected credentials

A vulnerability was found in Cisco License On-Prem. It has been classified as critical. This impacts an unknown function. This

  

CVE-2026-76498 | Cisco Application Policy Infrastructure Controller up to 6.2(2e) access control

A vulnerability was found in Cisco Application Policy Infrastructure Controller. It has been declared as very critical. Affected is an

  

CVE-2026-76499 | Cisco Application Policy Infrastructure Controller up to 6.2(2e) neutralization

A vulnerability was found in Cisco Application Policy Infrastructure Controller. It has been rated as very critical. Affected by this

  

CVE-2026-76501 | Cisco NX-OS up to 10.6(3s) NGOAM input validation

A vulnerability categorized as very critical has been discovered in Cisco NX-OS. Affected by this issue is some unknown functionality

  

CVE-2026-106065 | Red Hat Enterprise Linux PCX export plug-in integer overflow

A vulnerability identified as problematic has been detected in Red Hat Enterprise Linux. This affects an unknown part of the

  

CVE-2026-76500 | Cisco Application Policy Infrastructure Controller up to 6.2(2e) resource control

A vulnerability labeled as very critical has been found in Cisco Application Policy Infrastructure Controller. This vulnerability affects unknown code.

  

CVE-2026-92543 | Docker/Moby Docker Engine Registry Hostname Validation loadInsecureRegistries certificate validation

A vulnerability marked as problematic has been reported in Docker/Moby Docker Engine. This issue affects the function loadInsecureRegistries of the

  

CVE-2026-95605 | Passionate Programmer Peter WP Data Access Plugin up to 5.5.82 on WordPress sql injection

A vulnerability described as critical has been identified in Passionate Programmer Peter WP Data Access Plugin up to 5.5.82 on

  

CVE-2026-95534 | Unlimited Elements Plugin up to 2.0.19 on WordPress deserialization

A vulnerability classified as critical has been found in Unlimited Elements Plugin up to 2.0.19 on WordPress. The affected element

  

CVE-2026-95595 | Disable and Remove Google Fonts Plugin up to 2.0.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in Disable and Remove Google Fonts Plugin up to 2.0.2 on WordPress. The

  

CVE-2026-94662 | Unlimited Elements for Elementor Plugin up to 2.0.19 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in Unlimited Elements for Elementor Plugin up to 2.0.19 on

  

CVE-2026-95606 | Liquid Web/StellarWP The Events Calendar Plugin up to 6.17.4 on WordPress deserialization

A vulnerability, which was classified as critical, was found in Liquid Web/StellarWP The Events Calendar Plugin up to 6.17.4 on

  

CVE-2026-94670 | Everest Forms Plugin up to 3.6.1 on WordPress cross site scripting

A vulnerability has been found in Everest Forms Plugin up to 3.6.1 on WordPress and classified as problematic. Affected is

  

CVE-2026-46570 | BINARY ntfs-3g prior 2026.7.7 Index libntfs-3g/index.c ntfs_index_walk_down heap-based overflow

A vulnerability was found in BINARY ntfs-3g. It has been rated as very critical. Affected by this issue is the