cve
Veille des vulnérabilités Archive complète
identifiantvulnérabilitésévéritépublié
CVE-2026-56642Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.Microsoft Fabric Data Warehouse Élevée CVSS 8.8 CVE-2026-56643Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56644Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-56647Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-56648Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-56649Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 CVE-2026-56650Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57087Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57088Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-57089Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-57090Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-57091Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57092Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Critique CVSS 9.9 CVE-2026-57093Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57094Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 CVE-2026-57095Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57096Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-57102Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.Microsoft Visual Studio Code Élevée CVSS 8.8 CVE-2026-57107Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.Microsoft Windows Admin Center Élevée CVSS 7.8 CVE-2026-57108Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.Microsoft .net Élevée CVSS 7.5 CVE-2026-57898In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API.
The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. A remote attacker could upload thumbnail content using an absolute or traversal-style filename, then trigger thumbnail retrieval so that the uploaded bytes were written to the attacker-chosen path on the server filesystem.
This could allow writing files anywhere the Java process has permission to write and may lead to remote code execution. The default InMemory backend is not affected by this specific path because it normalizes and restricts file paths to its temporary directory.
The issue is fixed in Eclipse BaSyx Java Server SDK 2.0.0-milestone-13.Analyse NVD en cours Critique CVSS 9 CVE-2026-57968Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.Microsoft Windows Subsystem For Linux Élevée CVSS 7.8 CVE-2026-57969Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.Microsoft Azure Cyclecloud Élevée CVSS 8.8 CVE-2026-57979Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58229Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service.
The Mint.HTTP1.decode_headers/5 and Mint.HTTP1.decode_trailer_headers/4 functions in lib/mint/http1.ex accumulate every parsed response header and chunked-trailer field into a per-request list that persists across incoming TCP segments as request.headers_buffer, and only clear it when the terminating blank line is received. The section has no cap on the number of headers or on total bytes, and the underlying :erlang.decode_packet(:httph_bin, binary, []) parser is invoked with an empty option list so its per-line and per-packet size limits also default to unlimited.
A malicious HTTP server (reachable directly, via an attacker-controlled redirect, via SSRF, or via a man-in-the-middle) can stream complete header lines (or, after a chunked body, complete trailer lines) indefinitely without ever emitting the terminating blank line. The connection state grows without bound until the BEAM node is killed by the operating system's out-of-memory handler, taking down the entire application that uses Mint as an HTTP client.
This issue affects mint: from 0.1.0 before 1.9.2. Élevée CVSS 8.2 CVE-2026-58233SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system.Analyse NVD en cours Élevée CVSS 7.6 CVE-2026-58277Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server Élevée CVSS 8.8 CVE-2026-58319Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service.
This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.Apache Doris Critique CVSS 9.1 CVE-2026-58476Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the default configuration exposing these endpoints to unauthenticated users due to no required passphrase and a default credential of 'opendoor'.Dan-in-ca Sustainable Irrigation Platform Élevée CVSS 8.1 CVE-2026-58477Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.Dan-in-ca Sustainable Irrigation Platform Élevée CVSS 7.5 CVE-2026-58479Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.Dan-in-ca Sustainable Irrigation Platform Critique CVSS 9.8 CVE-2026-58526Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58527Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-58529Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.Microsoft Windows 11 26h1 Élevée CVSS 7.1 CVE-2026-58530Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58531Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58532Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58533Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58534Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58535Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58536Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58537Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-58538Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58539Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58540Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58541Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58542Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-58544Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 CVE-2026-58547Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58594Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Critique CVSS 9.8 CVE-2026-58595Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.Microsoft Bing Search Élevée CVSS 8.1 CVE-2026-58601Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58602Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 CVE-2026-58608Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58609Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58610Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58613Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58617Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.Microsoft 365 Copilot Critique CVSS 9.8 CVE-2026-58618Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 CVE-2026-58619Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-58626Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.Microsoft Windows 10 21h2 Élevée CVSS 8.8 CVE-2026-58627Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 CVE-2026-58628Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58629Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-58631Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.Microsoft Windows Admin Center Élevée CVSS 7.8 CVE-2026-58632Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-58633Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 26h1 Élevée CVSS 7.8 CVE-2026-58634Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 26h1 Élevée CVSS 7.8 CVE-2026-58635Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 CVE-2026-58636Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.Microsoft Pc Manager Élevée CVSS 7.8 CVE-2026-58637Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 CVE-2026-58640Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 CVE-2026-59083Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.Apache Tomcat Critique CVSS 9.1 CVE-2026-59084Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.Apache Tomcat Critique CVSS 9.1 CVE-2026-59197Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 8.2 CVE-2026-59198Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 7.5 CVE-2026-59199Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 7.5 CVE-2026-59200Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 7.5 CVE-2026-59203Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 7.5 CVE-2026-59204Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 7.5 CVE-2026-59205Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.Python Pillow Élevée CVSS 7.5 CVE-2026-59674A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root.
This issue affects openSUSE Tumbleweed: from ? before 8.0.5-2.1; openSUSE Tumbleweed: from ? before 8.0.5-2.1. Élevée CVSS 7.1 CVE-2026-59733Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.Rclone Élevée CVSS 8.8 CVE-2026-59835A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.Fortinet Fortisandbox Élevée CVSS 8.6 CVE-2026-59836A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>Fortinet Forticlientems Critique CVSS 9.8 CVE-2026-59841A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>Fortinet Fortisiem Élevée CVSS 7.5 CVE-2026-59884pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.Pyasn1 Élevée CVSS 7.5 CVE-2026-59885pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.Pyasn1 Élevée CVSS 7.5 CVE-2026-59886pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.Pyasn1 Élevée CVSS 7.5 CVE-2026-59891sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an exact host match, credentials configured for one registry can be selected for and transmitted to a different registry whose hostname has a substring relationship with a configured auth key. This issue is fixed in version 0.7.1.Analyse NVD en cours Critique CVSS 9.6 CVE-2026-60081DBI::ProfileData versions before 1.651 for Perl do not limit the path index.
The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory. Élevée CVSS 7.5 CVE-2026-60082DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row.
When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index.
This could be triggered by a caller supplying inconsistent metadata and rows to the prepare method. Critique CVSS 9.1 CVE-2026-60114Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.Dan-in-ca Sustainable Irrigation Platform Élevée CVSS 7.5 CVE-2026-61520Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without validating resolved destination IPs against private address ranges, loopback, or link-local addresses. Attackers can leverage SMF's automatic HMAC signature generation for any embedded image URL to obtain valid signed proxy requests targeting internal services such as cloud instance metadata endpoints, internal web applications, and container network services. Élevée CVSS 7.7 CVE-2026-62390Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
This issue affects Apache Kylin: from 4 through 5.0.3.
Users are recommended to upgrade to version 5.0.4, which fixes the issue.Apache Kylin Critique CVSS 9.8 CVE-2026-62392Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.
This issue affects Apache Kylin: from 4 through 5.0.3.
Users are recommended to upgrade to version 5.0.4, which fixes the issue.Apache Kylin Critique CVSS 9.8 CVE-2026-62422In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possibleAnalyse NVD en cours Critique CVSS 10 CVE-2026-62643In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.Roundcube Webmail Critique CVSS 10 CVE-2026-62644In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.Roundcube Webmail Critique CVSS 9.8 CVE-2026-6851An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on Windows allows a less-privileged local user to elevate rights by leveraging a race conditions via Symbolic Links.
This issue affects Total Security: before 27.0.58.315; Internet Security: before 27.0.58.315.Analyse NVD en cours Élevée CVSS 7 3101–3200 / 5155 CVE