CVE.report search for "CVE-2026-12920"

Listed below are 50 relevant search results for "CVE-2026-12920" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-73230Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 st...
CVE-2026-73210A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option...
CVE-2026-72867Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-456...
CVE-2026-72759In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization chec...
CVE-2026-72735Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/...
CVE-2026-72732Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates...
CVE-2026-72731Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest...
CVE-2026-72730Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor re...
CVE-2026-72729Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dat...
CVE-2026-72728Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs ...
CVE-2026-72727Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged user co...
CVE-2026-72726Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user c...
CVE-2026-72725Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous an...
CVE-2026-72724Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/o...
CVE-2026-72723Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymou...
CVE-2026-72722Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from,...
CVE-2026-72721Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.i...
CVE-2026-72720Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has ...
CVE-2026-72597A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a fre...
CVE-2026-72595A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket r...
CVE-2026-72563A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead ...
CVE-2026-72552A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the serve...
CVE-2026-72550An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute...
CVE-2026-72538An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code exec...
CVE-2026-72537A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped...
CVE-2026-72534A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped...
CVE-2026-71959Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collec...
CVE-2026-71315Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys ...
CVE-2026-71260ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/co...
CVE-2026-71259ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Bec...
CVE-2026-70636Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAu...
CVE-2026-69152JuliangruberBrace-expansionThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6,...
CVE-2026-69125Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a dupli...
CVE-2026-69124Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason: This candidate is a dupli...
CVE-2026-69123Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67319. Reason: This candidate is a dupli...
CVE-2026-68970Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape...
CVE-2026-68969Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted t...
CVE-2026-68948Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason: This candidate is a dupli...
CVE-2026-68947Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67317. Reason: This candidate is a dupli...
CVE-2026-68946Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67315. Reason: This candidate is a dupli...
CVE-2026-68944Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason: This candidate is a dupli...
CVE-2026-68943Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason: This candidate is a dupli...
CVE-2026-68942Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason: This candidate is a dupli...
CVE-2026-68941Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a dupli...
CVE-2026-68494The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass i...
CVE-2026-67587Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the m...
CVE-2026-67260Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the sched...
CVE-2026-67180Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing reque...
CVE-2026-67179Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer vi...
CVE-2026-66373Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report