General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-39832 | When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not seriali… | Unknown | 2026-05-22 | General Purpose |
| CVE-2026-7890 | In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-… | Unknown | 2026-05-21 | General Purpose |
| CVE-2026-4093 | In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. V… | Unknown | 2026-05-21 | General Purpose |
| CVE-2026-8426 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prep… | Unknown | 2026-05-21 | General Purpose |
| CVE-2026-8421 | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/sing… | Unknown | 2026-05-21 | General Purpose |