832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-6745
Bagisto General
5.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and explains: "We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases."

CVE-2026-41466
ProjeQtor Web
5.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by only detecting specific patterns while returning unsanitized strings without output encoding. Attackers can inject malicious payloads that bypass the filter using alternative syntax such as img tags with event handlers, which are stored and executed in the browsers of users viewing the affected content.

CVE-2026-41467
ProjeQtor Web
5.1
MEDIUM
EPSS
0.0%
2026 CWE-79 1 PoC

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and HTM file uploads. Authenticated attackers can upload HTML files containing arbitrary JavaScript through the image upload or attachment endpoints, and any user accessing the uploaded file URL will execute the embedded JavaScript in their browser.

CVE-2026-4925
Server General
5.0
MEDIUM
EPSS
0.1%
2026 CWE-862 1 PoC

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.11.

CVE-2026-3113
Mattermost General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-732 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593

CVE-2026-5704
Red Hat Enterprise Linux 10 General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-434 2 PoCs

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVE-2026-6845
Red Hat Enterprise Linux 10 General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

CVE-2026-5175
Server Web
5.0
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests.  This issue affects Server: from 2026.1.6 through 2026.1.11.

CVE-2026-34881
Glance Web
5.0
MEDIUM
EPSS
0.0%
2026 CWE-918 1 PoC

OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin.

CVE-2026-34262
SAP HANA Cockpit and HANA Database Explorer General
5.0
MEDIUM
EPSS
0.0%
2026 CWE-522 1 PoC

Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer

CVE-2026-20029
Cisco Identity Services Engine Software Networking
4.9
MEDIUM
EPSS
0.1%
2026 CWE-611 1 PoC

A vulnerability in the licensing features of&nbsp;Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information.&nbsp; This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating

CVE-2026-3116
Mattermost General
4.9
MEDIUM
EPSS
0.1%
2026 CWE-400 1 PoC

Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589

CVE-2026-3221
Server General
4.9
MEDIUM
EPSS
0.0%
2026 CWE-312 1 PoC

Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.

CVE-2026-1430
WP Lightbox 2 Web Windows
4.8
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-3675
dGEN1 General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-285 1 PoC

A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppReceiver of the component org.ethosmobile.ethoslauncher. Executing a manipulation can lead to improper authorization. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-1417
GPAC General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-476 1 PoC

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: f96bd57c3ccdcde4335a0be28cd3e8fe296993de. Applying a patch is the recommended action to fix this issue.

CVE-2026-1858
wget2 General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-20 1 PoC

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

CVE-2026-2889
CCExtractor General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-416 1 PoC

A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.

CVE-2026-22212
TinyOS General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-121 1 PoC

TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility. The vulnerability is caused by unsafe use of strcpy() and strcat() functions when constructing device paths during automatic device discovery. A local attacker can exploit this by creating specially crafted filenames under /dev/usb/, leading to stack memory corruption and application crashes.

CVE-2026-3407
yosys General
4.8
MEDIUM
EPSS
0.0%
2026 CWE-122 1 PoC

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Applying a patch is the recommended action to fix this issue. It appears that the issue is not reproducible all the time.