CVE.report search for "CVE-2026-97155"

Listed below are 50 relevant search results for "CVE-2026-97155" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-97225A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers...
CVE-2026-97155Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via we...
CVE-2026-96456The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the s...
CVE-2026-96454Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the...
CVE-2026-96260Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body ...
CVE-2026-96259Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-conn...
CVE-2026-95897A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/...
CVE-2026-95815OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public d...
CVE-2026-95666Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the...
CVE-2026-95273A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the f...
CVE-2026-94613authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can sub...
CVE-2026-94612authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies a...
CVE-2026-94611authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return st...
CVE-2026-94609authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permissio...
CVE-2026-94606authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrol...
CVE-2026-94301The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect....
CVE-2026-94109openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortle...
CVE-2026-94094A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/can...
CVE-2026-93352Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent fro...
CVE-2026-93235In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to zero post-EOF data when extending file size...
CVE-2026-93189In the Linux kernel, the following vulnerability has been resolved: HID: core: quiesce input in hid_hw_stop() to prevent use...
CVE-2026-92680Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Window...
CVE-2026-92593Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl(...
CVE-2026-92580In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.js...
CVE-2026-92571Rejected reason: CVE ID reserved in error and not assigned to a vulnerability. The correct CVE ID is CVE-2026-92574.
CVE-2026-92472A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file src/...
CVE-2026-92419WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople...
CVE-2026-92395@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it bac...
CVE-2026-92237Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2...
CVE-2026-91181Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects r...
CVE-2026-91134Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sani...
CVE-2026-91133Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users cou...
CVE-2026-91132Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard pa...
CVE-2026-91130Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistic...
CVE-2026-91129Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integ...
CVE-2026-91123Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversa...
CVE-2026-91122Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder c...
CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows ...
CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticat...
CVE-2026-90818A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the functi...
CVE-2026-90788A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown funct...
CVE-2026-90616In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which ca...
CVE-2026-90481In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via...
CVE-2026-90386In the Linux kernel, the following vulnerability has been resolved: i3c: dw: avoid shift-out-of-bounds when DAA assigns no d...
CVE-2026-90264In the Linux kernel, the following vulnerability has been resolved: btrfs: always wait for ordered extents to avoid OE races...
CVE-2026-90218In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix WARNING in res_to_rt syzbot reported a WA...
CVE-2026-90055In the Linux kernel, the following vulnerability has been resolved: usb: atm: usbatm: fix invalid ci_range initialization s...
CVE-2026-90040In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Forcefully invalidate SNP VMSA if its backing ...
CVE-2026-89793In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char device mm...
CVE-2026-89495In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler Pat...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report