6.5
CVE-2026-25219 - Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposeβ¦
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azβ¦
8.5
CVE-2026-4145 - Local Privilege Escalation in Lenovo Software Fix
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
5.2
CVE-2026-4135 - Local Authenticated File Write Vulnerability in Lenovo Software Fix
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
7
CVE-2026-4134 - Local Privilege Escalation During Lenovo Software Fix Installation
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.
5.4
CVE-2026-1636 - Potential DLL Hijacking in Lenovo Service Bridge Enables Local Privilege Escalation
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
6.9
CVE-2026-0827 - Local Privilege Escalation via Arbitrary File Write in Lenovo Diagnostics and Vantage
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privβ¦
6.1
CVE-2026-1852 - Product Pricing Table by WooBeWoo <= 1.1.0 - Cross-Site Request Forgery to Stored XSS and Pricing Tβ¦
The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers β¦
6.5
CVE-2026-3590 - Race Condition in Guest Magic Link Authentication Allows Token Reuse
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent β¦
7.5
CVE-2026-30778 - Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuratβ¦
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0. Users are recommended to upgrade to version 10.4.0, which fixes the issue.
4.3
CVE-2026-40786 - WordPress MyRewards plugin <= 5.7.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.