--===============8728627738968554007==
Content-Type: multipart/alternative; boundary="===============7146585765089518506=="
MIME-Version: 1.0
--===============7146585765089518506==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrast= ructure Security Agency. This information has recently been updated and is = now available.
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities t= hat have been recorded in the past week. In some cases, the vulnerabilities=
in the bulletin may not yet have assigned CVSS scores.
Vulnerabilities are based on the=C2=A0Common Vulnerabilities and Exposures =
[
https://www.cve.org/ ]=C2=A0(CVE) vulnerability naming standard and are o= rganized according to severity, determined by the=C2=A0Common Vulnerability=
Scoring System [
https://www.cve.org/about/relatedefforts ]=C2=A0(CVSS) st= andard. The division of high, medium, and low severities correspond to the = following scores:
* *High*: vulnerabilities with a CVSS base score of 7.0=E2=80=9310.0=20
* *Medium*: vulnerabilities with a CVSS base score of 4.0=E2=80=936.9=20
* *Low*: vulnerabilities with a CVSS base score of 0.0=E2=80=933.9=20
Entries may include additional information provided by organizations and ef= forts sponsored by CISA. This information may include identifying informati= on, values, definitions, and related links. Patch information is provided w= hen available. Please note that some of the information in the bulletin is = compiled from external, open-source reports and is not a direct result of C= ISA analysis.
=C2=A0
Vulnerability Summary for the Week of May 11, 2026 [
https://www.cisa.gov/n= ews-events/bulletins/sb26-138 ] 05/18/2026 05:00 PM EDT=20
High Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info Patch Info a= cl--ACL Analytics ACL Analytics versions 11.x through 13.0.0.579 contain an=
arbitrary code execution vulnerability that allows attackers to execute ar= bitrary commands by leveraging the EXECUTE function. Attackers can use bits= admin to download malicious PowerShell scripts and execute them with system=
privileges to establish reverse shells and gain complete system control. 2= 026-05-17 9.8 CVE-2018-25320 [
https://www.cve.org/CVERecord?id=3DCVE-2018-= 25320 ] ExploitDB-44281 [
https://www.exploit-db.com/exploits/44281 ]
Official Product Homepage [
https://www.acl.com ]
Product Reference [
https://www.acl.com/products/acl-analytics/ ]
VulnCheck Advisory: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Executio=
n [
https://www.vulncheck.com/advisories/acl-analytics-11-x-arbitrary-code-= execution ]
=C2=A0 gitbucket--GitBucket GitBucket 4.23.1 contains an unauthenticated re= mote code execution vulnerability that allows attackers to execute arbitrar=
y commands by exploiting weak secret token generation and insecure file upl= oad functionality. Attackers can brute-force the Blowfish encryption key, u= pload a malicious JAR plugin via the git-lfs endpoint, and execute system c= ommands through an exposed exploit endpoint. 2026-05-17 9.8 CVE-2018-25332 =
[
https://www.cve.org/CVERecord?id=3DCVE-2018-25332 ] ExploitDB-44668 [ htt= ps://www.exploit-db.com/exploits/44668 ]
Official Product Homepage [
https://security.szurek.pl/ ]
Product Reference [
https://github.com/gitbucket/gitbucket ]
VulnCheck Advisory: GitBucket 4.23.1 Unauthenticated Remote Code Execution =
[
https://www.vulncheck.com/advisories/gitbucket-unauthenticated-remote-cod= e-execution ]
=C2=A0 peugeot-music-plugin--Peugeot Music WordPress Plugin Peugeot Music 1=
.0 contains an arbitrary file upload vulnerability that allows unauthentica= ted attackers to upload malicious files by sending POST requests to the upl= oad.php endpoint. Attackers can upload files with arbitrary extensions by m= anipulating the 'name' parameter to execute code from the uploads directory=
. 2026-05-17 9.8 CVE-2018-25335 [
https://www.cve.org/CVERecord?id=3DCVE-20= 18-25335 ] ExploitDB-44737 [
https://www.exploit-db.com/exploits/44737 ] VulnCheck Advisory: WordPress Plugin Peugeot Music 1.0 Arbitrary File Uploa=
d [
https://www.vulncheck.com/advisories/wordpress-plugin-peugeot-music-arb= itrary-file-upload ]
=C2=A0 Paiement--Ecommerce Systempay Ecommerce Systempay 1.0 contains a wea=
k cryptographic implementation vulnerability that allows attackers to brute=
force the 16-character production secret key used for payment signature ge= neration. Attackers can extract payment form data and signatures from POST = requests to the payment endpoint, then use SHA1 hash comparison to iterativ= ely test key candidates until discovering the correct production key, enabl= ing them to forge valid payment signatures and manipulate transaction amoun= ts. 2026-05-13 9.8 CVE-2020-37168 [
https://www.cve.org/CVERecord?id=3DCVE-= 2020-37168 ] ExploitDB-48017 [
https://www.exploit-db.com/exploits/48017 ] Official Product Homepage [
https://paiement.systempay.fr/doc/fr-FR/ ]
Product Reference [
https://paiement.systempay.fr/doc/fr-FR/module-de-paiem= ent-gratuit/ ]
VulnCheck Advisory: Ecommerce Systempay 1.0 Production Key Brute Force [ ht= tps://www.vulncheck.com/advisories/ecommerce-systempay-production-key-brute= -force ]
=C2=A0 Yerootech--iDS6 DSSPro Digital Signage System iDS6 DSSPro Digital Si= gnage System 6.2 contains a CAPTCHA security bypass vulnerability that allo=
ws attackers to bypass authentication by requesting the autoLoginVerifyCode=
object. Attackers can retrieve valid CAPTCHA codes via the login endpoint = and use them to perform brute-force attacks against user accounts. 2026-05-=
16 9.8 CVE-2020-37228 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37228 ]=
ExploitDB-48991 [
https://www.exploit-db.com/exploits/48991 ]
Vulnerability Advisory [
https://www.zeroscience.mk/en/vulnerabilities/ZSL-= 2020-5607.php ]
Official Product Homepage [
http://www.yerootech.com ]
VulnCheck Advisory: iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security=
Bypass [
https://www.vulncheck.com/advisories/ids6-dsspro-digital-signage-= system-captcha-security-bypass ]
=C2=A0 Gegl--libbabl libbabl 0.1.62 contains a broken double free detection=
vulnerability that allows attackers to bypass memory safety checks by expl= oiting signature overwriting in freed chunks. Attackers can call babl_free(=
) twice on the same pointer without triggering detection, as libc's malloc = metadata overwrites babl's signature field upon freeing, enabling potential=
memory corruption and code execution. 2026-05-16 9.8 CVE-2020-37239 [ http= s://www.cve.org/CVERecord?id=3DCVE-2020-37239 ] ExploitDB-49259 [
https://w= ww.exploit-db.com/exploits/49259 ]
Official Product Homepage [
https://www.gegl.org ]
Product Reference [
https://www.gegl.org/babl/ ]
VulnCheck Advisory: libbabl 0.1.62 Broken Double Free Detection Memory Safe=
ty [
https://www.vulncheck.com/advisories/libbabl-broken-double-free-detect= ion-memory-safety ]
=C2=A0 Jsonpickle--python jsonpickle python jsonpickle 2.0.0 contains a rem= ote code execution vulnerability that allows attackers to execute arbitrary=
Python commands by deserializing malicious JSON payloads containing py/rep=
r objects. Attackers can craft JSON strings with py/repr directives that in= voke the eval function during deserialization to execute system commands an=
d arbitrary code. 2026-05-16 9.8 CVE-2021-47952 [
https://www.cve.org/CVERe= cord?id=3DCVE-2021-47952 ] ExploitDB-49585 [
https://www.exploit-db.com/exp= loits/49585 ]
Official Product Homepage [
https://jsonpickle.github.io ]
Product Reference [
https://github.com/jsonpickle/jsonpickle ]
VulnCheck Advisory: python jsonpickle 2.0.0 Remote Code Execution via py/re=
pr [
https://www.vulncheck.com/advisories/python-jsonpickle-remote-code-exe= cution-via-py-repr ]
=C2=A0 wp-super-edit--WP Super Edit WordPress Plugin WP Super Edit 2.5.4 an=
d earlier contains an unrestricted file upload vulnerability in the FCKedit=
or component that allows attackers to upload dangerous file types without v= alidation. Attackers can upload arbitrary files through the filemanager upl= oad endpoint to achieve remote code execution and complete system compromis=
e. 2026-05-15 9.8 CVE-2021-47965 [
https://www.cve.org/CVERecord?id=3DCVE-2= 021-47965 ] ExploitDB-49839 [
https://www.exploit-db.com/exploits/49839 ] Official Product Homepage [
https://wordpress.org ]
Product Reference [
https://wordpress.org/plugins/wp-super-edit/ ]
VulnCheck Advisory: WordPress Plugin WP Super Edit 2.5.4 Unrestricted File = Upload [
https://www.vulncheck.com/advisories/wordpress-plugin-wp-super-edi= t-unrestricted-file-upload ]
=C2=A0 Akilli Commerce Software Technologies Ltd. Co.--E-Commerce Website I= mproper neutralization of special elements used in an SQL command ('SQL inj= ection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-= Commerce Website allows Blind SQL Injection. This issue affects E-Commerce = Website: before 4.5.001. 2026-05-14 9.8 CVE-2025-11024 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-11024 ]
https://siberguvenlik.gov.tr/guvenlik-bil= dirimleri/detay/tr-26-0222
=C2=A0 Hitachi Vantara--Pentaho Data Integration and Analytics Hitachi Vant= ara Pentaho Data Integration & Analytics of all versions contain a JDBC dri= ver for H2 databases which is vulnerable to external script execution when =
a new connection is created by a=C2=A0data source administrator. 2026-05-13=
9.1 CVE-2025-11159 [
https://www.cve.org/CVERecord?id=3DCVE-2025-11159 ] h= ttps://support.pentaho.com/hc/en-us/articles/39954640408077--Resolved-Hitac= hi-Vantara-Pentaho-Data-Integration-Analytics-Dependency-on-Vulnerable-Thir= d-Party-Component-Versions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2025-1= 1159
=C2=A0 alloksoft--Fast AVI MPEG Splitter Allok Fast AVI MPEG Splitter 1.2 c= ontains a stack based buffer overflow vulnerability that allows local attac= kers to execute arbitrary code by supplying a malicious license name string=
. Attackers can craft a payload with 780 bytes of junk data followed by str= uctured shellcode and place it in the License Name field to trigger the ove= rflow and execute code with application privileges. 2026-05-17 8.4 CVE-2018= -25322 [
https://www.cve.org/CVERecord?id=3DCVE-2018-25322 ] ExploitDB-4434=
1 [
https://www.exploit-db.com/exploits/44341 ]
Official Product Homepage [
http://www.alloksoft.com ]
Product Reference [
http://www.alloksoft.com/allok_vconverter.exe ]
VulnCheck Advisory: Allok Fast AVI MPEG Splitter 1.2 Stack Based Buffer Ove= rflow [
https://www.vulncheck.com/advisories/allok-fast-avi-mpeg-splitter-s= tack-based-buffer-overflow ]
=C2=A0 Alloksoft--Allok AVI DivX MPEG to DVD Converter Allok AVI DivX MPEG =
to DVD Converter 2.6.1217 contains a structured exception handler buffer ov= erflow vulnerability that allows local attackers to execute arbitrary code =
by supplying a malicious payload. Attackers can craft a text file with a sp= ecially crafted buffer containing shellcode and SEH chain overwrite values,=
then paste the contents into the License Name field to trigger code execut= ion. 2026-05-17 8.4 CVE-2018-25323 [
https://www.cve.org/CVERecord?id=3DCVE= -2018-25323 ] ExploitDB-44363 [
https://www.exploit-db.com/exploits/44363 ] VulnCheck Advisory: Allok AVI DivX MPEG to DVD Converter 2.6.1217 Buffer Ov= erflow SEH [
https://www.vulncheck.com/advisories/allok-avi-divx-mpeg-to-dv= d-converter-buffer-overflow-seh ]
=C2=A0 vxsearch--VX Search VX Search 10.6.18 contains a local buffer overfl=
ow vulnerability that allows attackers to overwrite the instruction pointer=
by supplying an oversized string in the directory field. Attackers can cra=
ft a malicious input file containing 271 bytes of junk data followed by a r= eturn address to execute arbitrary code with application privileges. 2026-0= 5-17 8.4 CVE-2018-25328 [
https://www.cve.org/CVERecord?id=3DCVE-2018-25328=
] ExploitDB-44494 [
https://www.exploit-db.com/exploits/44494 ]
Official Product Homepage [
https://www.7elements.co.uk ]
Official Product Homepage [
http://www.vxsearch.com ]
VulnCheck Advisory: VX Search 10.6.18 Local Buffer Overflow via Directory F= ield [
https://www.vulncheck.com/advisories/vx-search-local-buffer-overflow= -via-directory-field ]
=C2=A0 Joomlaextensions--Joomla! extension EkRishta Joomla! extension EkRis= hta 2.10 contains persistent cross-site scripting and SQL injection vulnera= bilities that allow attackers to inject malicious code through profile fiel=
ds and POST parameters. Attackers can inject script payloads in profile inf= ormation fields like Address that execute when users visit the profile, or = submit SQL injection payloads via the phone_no parameter to the user_settin=
g endpoint to manipulate database queries. 2026-05-17 8.2 CVE-2018-25330 [ =
https://www.cve.org/CVERecord?id=3DCVE-2018-25330 ] ExploitDB-44660 [ https= ://www.exploit-db.com/exploits/44660 ]
Official Product Homepage [
https://www.joomlaextensions.co.in/ ]
Product Reference [
https://extensions.joomla.org/extensions/extension/livi= ng/dating-a-relationships/ek-rishta/ ]
VulnCheck Advisory: Joomla! EkRishta 2.10 Persistent XSS and SQL Injection =
[
https://www.vulncheck.com/advisories/joomla-ekrishta-persistent-xss-and-s= ql-injection ]
=C2=A0 nordex-online--N149 Wind Turbine Web Server Nordex N149/4.0-4.5 Wind=
Turbine Web Server 4.0 contains an SQL injection vulnerability that allows=
unauthenticated attackers to execute arbitrary SQL queries by injecting ma= licious code through the login parameter in login.php. Attackers can submit=
crafted POST requests with SQL injection payloads in the login field to ex= tract sensitive database information and bypass authentication mechanisms. = 2026-05-17 8.2 CVE-2018-25333 [
https://www.cve.org/CVERecord?id=3DCVE-2018= -25333 ] ExploitDB-44684 [
https://www.exploit-db.com/exploits/44684 ]
Official Product Homepage [
http://www.nordex-online.com ]
VulnCheck Advisory: Nordex N149/4.0-4.5 Wind Turbine Web Server SQL Injecti=
on [
https://www.vulncheck.com/advisories/nordex-n149-wind-turbine-web-serv= er-sql-injection ]
=C2=A0 Bylancer--Zechat Zechat 1.5 contains a SQL injection vulnerability i=
n the hashtag parameter that allows unauthenticated attackers to extract da= tabase information using union-based techniques. Attackers can exploit the = hashtag parameter with union-based payloads to retrieve table and column na= mes. 2026-05-17 8.2 CVE-2018-25338 [
https://www.cve.org/CVERecord?id=3DCVE= -2018-25338 ] ExploitDB-44685 [
https://www.exploit-db.com/exploits/44685 ] Official Product Homepage [
https://bylancer.com ]
VulnCheck Advisory: Zechat 1.5 SQL Injection via hashtag parameter [ https:= //www.vulncheck.com/advisories/zechat-sql-injection-via-hashtag-parameter ] =C2=A0 Bylancer--Zechat Zechat 1.5 contains a SQL injection vulnerability i=
n the v parameter that allows unauthenticated attackers to extract database=
information using time-based blind techniques. Attackers can exploit the v=
parameter with sleep-based blind injection to confirm vulnerability and ex= tract data. 2026-05-17 8.2 CVE-2018-25339 [
https://www.cve.org/CVERecord?i= d=3DCVE-2018-25339 ] ExploitDB-44685 [
https://www.exploit-db.com/exploits/= 44685 ]
Official Product Homepage [
https://bylancer.com ]
VulnCheck Advisory: Zechat 1.5 SQL Injection via v parameter (time-based bl= ind) [
https://www.vulncheck.com/advisories/zechat-sql-injection-via-v-para= meter-time-based-blind ]
=C2=A0 Hdwplayer--com_hdwplayer Joomla com_hdwplayer 4.2 contains an SQL in= jection vulnerability in the search.php file that allows unauthenticated at= tackers to execute arbitrary SQL queries by injecting malicious code throug=
h the hdwplayersearch parameter. Attackers can submit POST requests with cr= afted SQL payloads in the hdwplayersearch parameter to extract sensitive da= tabase information from the hdwplayer_videos table. 2026-05-13 8.2 CVE-2020= -37218 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37218 ] ExploitDB-4824=
2 [
https://www.exploit-db.com/exploits/48242 ]
Official Product Homepage [
https://www.hdwplayer.com/ ]
Product Reference [
https://www.hdwplayer.com/download/ ]
VulnCheck Advisory: Joomla com_hdwplayer 4.2 SQL Injection via search.php [=
https://www.vulncheck.com/advisories/joomla-com-hdwplayer-sql-injection-vi= a-search-php ]
=C2=A0 Drive-software--Atomic Alarm Clock Atomic Alarm Clock 6.3 contains a=
stack overflow vulnerability that allows local attackers to execute arbitr= ary code by supplying a malicious string to the display name textbox in the=
Time Zones Clock configuration. Attackers can craft a buffer with structur=
ed exception handling overwrite and encoded shellcode to bypass SafeSEH pro= tections and execute arbitrary commands with application privileges. 2026-0= 5-13 8.4 CVE-2020-37221 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37221=
] ExploitDB-48346 [
https://www.exploit-db.com/exploits/48346 ]
VulnCheck Advisory: Atomic Alarm Clock 6.3 Stack Overflow via SEH Unicode [=
https://www.vulncheck.com/advisories/atomic-alarm-clock-stack-overflow-via= -seh-unicode ]
=C2=A0 Heliossolutions--HS Brand Logo Slider HS Brand Logo Slider 2.1 conta= ins an unrestricted file upload vulnerability that allows authenticated use=
rs to bypass client-side file extension validation by uploading arbitrary f= iles. Attackers can intercept upload requests to the logoupload parameter i=
n the admin interface and rename files to executable extensions .php to ach= ieve remote code execution. 2026-05-16 8.8 CVE-2020-37227 [
https://www.cve= .org/CVERecord?id=3DCVE-2020-37227 ] ExploitDB-48913 [
https://www.exploit-= db.com/exploits/48913 ]
Official Product Homepage [
https://www.heliossolutions.co/ ]
Product Reference [
https://ms.wordpress.org/plugins/hs-brand-logo-slider/ ] VulnCheck Advisory: WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted = File Upload [
https://www.vulncheck.com/advisories/wordpress-plugin-hs-bran= d-logo-slider-unrestricted-file-upload ]
=C2=A0 Supsystic--Ultimate Maps Supsystic Ultimate Maps 1.1.12 contains an = SQL injection vulnerability that allows unauthenticated attackers to execut=
e arbitrary SQL queries by injecting malicious code through the 'sidx' GET = parameter. Attackers can send crafted requests to the getListForTbl action = with boolean-based blind or time-based blind SQL injection payloads to extr= act sensitive database information. 2026-05-16 8.2 CVE-2020-37242 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2020-37242 ] ExploitDB-49532 [
https://www.= exploit-db.com/exploits/49532 ]
Official Product Homepage [
https://supsystic.com/ ]
Product Reference [
https://downloads.wordpress.org/plugin/ultimate-maps-by= -supsystic.1.1.12.zip ]
VulnCheck Advisory: WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Inj= ection via sidx [
https://www.vulncheck.com/advisories/wordpress-plugin-sup= systic-ultimate-maps-sql-injection-via-sidx ]
=C2=A0 Supsystic--Pricing Table Supsystic Pricing Table 1.8.7 contains an S=
QL injection vulnerability in the 'sidx' GET parameter that allows unauthen= ticated attackers to execute arbitrary SQL queries through the getListForTb=
l action. The plugin also contains stored cross-site scripting vulnerabilit= ies in the 'Edit name' and 'Edit HTML' fields that execute malicious script=
s when viewing pricing tables. 2026-05-16 8.2 CVE-2020-37243 [
https://www.= cve.org/CVERecord?id=3DCVE-2020-37243 ] ExploitDB-49533 [
https://www.explo= it-db.com/exploits/49533 ]
Official Product Homepage [
https://supsystic.com/ ]
Product Reference [
https://downloads.wordpress.org/plugin/pricing-table-by= -supsystic.1.8.7.zip ]
VulnCheck Advisory: WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Inje= ction XSS [
https://www.vulncheck.com/advisories/wordpress-plugin-supsystic= -pricing-table-sql-injection-xss ]
=C2=A0 Supsystic--Membership Supsystic Membership 1.4.7 contains an SQL inj= ection vulnerability that allows unauthenticated attackers to execute arbit= rary SQL queries by injecting malicious code through the 'search' and 'sidx=
' parameters. Attackers can send GET requests to the badges module with cra= fted payloads to extract sensitive database information using time-based bl= ind or UNION-based SQL injection techniques. 2026-05-16 8.2 CVE-2020-37244 =
[
https://www.cve.org/CVERecord?id=3DCVE-2020-37244 ] ExploitDB-49540 [ htt= ps://www.exploit-db.com/exploits/49540 ]
Official Product Homepage [
https://supsystic.com/ ]
Product Reference [
https://downloads.wordpress.org/plugin/membership-by-su= psystic.1.4.7.zip ]
VulnCheck Advisory: WordPress Plugin Supsystic Membership 1.4.7 SQL Injecti=
on via sidx [
https://www.vulncheck.com/advisories/wordpress-plugin-supsyst= ic-membership-sql-injection-via-sidx ]
=C2=A0 LayerBB--LayerBB LayerBB 1.1.4 contains an SQL injection vulnerabili=
ty that allows unauthenticated attackers to manipulate database queries by = injecting SQL code through the search_query parameter. Attackers can send P= OST requests to /search.php with malicious search_query values using CASE W= HEN statements to extract sensitive database information. 2026-05-16 8.2 CV= E-2021-47954 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47954 ] ExploitD= B-49593 [
https://www.exploit-db.com/exploits/49593 ]
VulnCheck Advisory: LayerBB 1.1.4 SQL Injection via search_query Parameter =
[
https://www.vulncheck.com/advisories/layerbb-sql-injection-via-search-que= ry-parameter ]
=C2=A0 Egavilanmedia--EgavilanMedia PHPCRUD EgavilanMedia PHPCRUD 1.0 conta= ins an SQL injection vulnerability that allows unauthenticated attackers to=
manipulate database queries by injecting SQL code through the firstname pa= rameter. Attackers can send POST requests to insert.php with malicious firs= tname values to extract sensitive database information. 2026-05-16 8.2 CVE-= 2021-47956 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47956 ] ExploitDB-= 49878 [
https://www.exploit-db.com/exploits/49878 ]
Official Product Homepage [
https://egavilanmedia.com ]
Product Reference [
https://egavilanmedia.com/crud-operation-with-php-mysql= -bootstrap-and-dompdf/ ]
VulnCheck Advisory: EgavilanMedia PHPCRUD 1.0 SQL Injection via firstname [=
https://www.vulncheck.com/advisories/egavilanmedia-phpcrud-sql-injection-v= ia-firstname ]
=C2=A0 Schlix--Schlix CMS Schlix CMS 2.2.6-6 contains a remote code executi=
on vulnerability that allows authenticated attackers to execute arbitrary P=
HP code by uploading malicious extension packages through the block manager=
. Attackers can upload a crafted ZIP file containing PHP code in the packag= einfo.inc file and trigger execution by accessing the About tab of the inst= alled extension. 2026-05-15 8.8 CVE-2021-47964 [
https://www.cve.org/CVERec= ord?id=3DCVE-2021-47964 ] ExploitDB-49838 [
https://www.exploit-db.com/expl= oits/49838 ]
Official Product Homepage [
https://www.schlix.com/ ]
Product Reference [
https://www.schlix.com/downloads/schlix-cms/schlix-cms-= v2.2.6-6.zip ]
VulnCheck Advisory: Schlix CMS 2.2.6-6 Remote Code Execution via core.block= manager [
https://www.vulncheck.com/advisories/schlix-cms-6-remote-code-exe= cution-via-core-blockmanager ]
=C2=A0 Timeclock--PHP Timeclock PHP Timeclock 1.04 contains time-based and = boolean-based blind SQL injection vulnerabilities in the login_userid param= eter of login.php that allows unauthenticated attackers to extract database=
contents. Attackers can submit crafted POST requests with SQL payloads usi=
ng SLEEP functions or RLIKE conditional statements to dump sensitive databa=
se information including employee names and credentials. 2026-05-15 8.2 CVE= -2021-47966 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47966 ] ExploitDB= -49849 [
https://www.exploit-db.com/exploits/49849 ]
Official Product Homepage [
http://timeclock.sourceforge.net ]
Product Reference [
https://sourceforge.net/projects/timeclock/files/PHP%20= Timeclock/PHP%20Timeclock%201.04/ ]
VulnCheck Advisory: PHP Timeclock 1.04 SQL Injection via login.php [ https:= //www.vulncheck.com/advisories/php-timeclock-sql-injection-via-login-php ] =C2=A0 Textpattern--TextPattern CMS TextPattern CMS 4.9.0-dev contains a re= mote code execution vulnerability that allows authenticated attackers to up= load arbitrary PHP files by exploiting the plugin upload functionality. Att= ackers can authenticate, retrieve a CSRF token from the plugin event page, = and upload malicious PHP files to the textpattern/tmp/ directory for code e= xecution. 2026-05-16 8.8 CVE-2021-47976 [
https://www.cve.org/CVERecord?id= =3DCVE-2021-47976 ] ExploitDB-50095 [
https://www.exploit-db.com/exploits/5= 0095 ]
Official Product Homepage [
https://textpattern.com/ ]
Product Reference [
https://github.com/textpattern/textpattern ]
VulnCheck Advisory: TextPattern CMS 4.9.0-dev Authenticated Remote Code Exe= cution via Plugin Upload [
https://www.vulncheck.com/advisories/textpattern= -cms-dev-authenticated-remote-code-execution-via-plugin-upload ]
=C2=A0 Miniorange--Backup and Restore WordPress Plugin Backup and Restore 1= .0.3 contains an arbitrary file deletion vulnerability that allows authenti= cated attackers to delete files by manipulating parameters in AJAX requests=
. Attackers can send POST requests to admin-ajax.php with crafted file_name=
and folder_name parameters to delete arbitrary files from the WordPress in= stallation directory. 2026-05-16 8.8 CVE-2021-47979 [
https://www.cve.org/C= VERecord?id=3DCVE-2021-47979 ] ExploitDB-50503 [
https://www.exploit-db.com= /exploits/50503 ]
Official Product Homepage [
https://www.miniorange.com/ ]
Product Reference [
https://wordpress.org/plugins/backup-and-restore-for-wp=
/ ]
VulnCheck Advisory: WordPress Plugin Backup and Restore 1.0.3 Arbitrary Fil=
e Deletion [
https://www.vulncheck.com/advisories/wordpress-plugin-backup-a= nd-restore-arbitrary-file-deletion ]
=C2=A0 WSO2--WSO2 Identity Server The Magic Link authentication flow accept=
s multiple invalid authentication requests without adequate rate limiting o=
r resource control, leading to uncontrolled memory usage growth. This vulne= rability can result in a denial-of-service condition, causing service unava= ilability for deployments that utilize the Magic Link authenticator. The im= pact is limited to these specific deployments and requires repeated invalid=
authentication attempts to trigger. 2026-05-11 8.6 CVE-2025-10470 [ https:= //www.cve.org/CVERecord?id=3DCVE-2025-10470 ]
https://security.docs.wso2.co= m/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4469/ =C2=A0 APPYAP Technology and Information Inc.--Yaay Social Media App Author= ization bypass through User-Controlled key vulnerability in APPYAP Technolo=
gy and Information Inc. Yaay Social Media App allows Accessing Functionalit=
y Not Properly Constrained by ACLs. This issue affects Yaay Social Media Ap=
p: from 3.8.0 through 24102025. 2026-05-14 8.8 CVE-2025-12008 [
https://www= .cve.org/CVERecord?id=3DCVE-2025-12008 ]
https://siberguvenlik.gov.tr/guven= lik-bildirimleri/detay/tr-26-0238
=C2=A0 Yordam Information Technology Consulting, Training and Electronic Sy= stems Industry and Trade Inc.--Library Automation System Incorrect Authoriz= ation vulnerability in Yordam Information Technology Consulting, Training a=
nd Electronic Systems Industry and Trade Inc. Library Automation System all= ows Exploiting Incorrectly Configured Access Control Security Levels. This = issue affects Library Automation System: from v.19.5 before v.22.1. 2026-05= -14 8.8 CVE-2025-15023 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15023 =
]
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240
=C2=A0 Yordam Information Technology Consulting, Training and Electronic Sy= stems Industry and Trade Inc.--Library Automation System Improper Control o=
f Generation of Code ('Code Injection') vulnerability in Yordam Information=
Technology Consulting, Training and Electronic Systems Industry and Trade = Inc. Library Automation System allows Remote Code Inclusion. This issue aff= ects Library Automation System: from v.19.5 before v.22.1. 2026-05-14 8.8 C= VE-2025-15024 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15024 ] https:/= /siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240
=C2=A0 Yordam Information Technology Consulting, Training and Electronic Sy= stems Industry and Trade Inc.--Library Automation System Authorization bypa=
ss through User-Controlled key vulnerability in Yordam Information Technolo=
gy Consulting, Training and Electronic Systems Industry and Trade Inc. Libr= ary Automation System allows Exploitation of Trusted Identifiers. This issu=
e affects Library Automation System: from v.21.6 before v.22.1. 2026-05-14 = 8.8 CVE-2025-15025 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15025 ] ht= tps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240
=C2=A0 wende60--Redaxo CMS Addon MyEvents Redaxo CMS Addon MyEvents 2.2.1 c= ontains an SQL injection vulnerability that allows authenticated attackers =
to manipulate database queries by injecting SQL code through the myevents_i=
d parameter. Attackers can send GET requests to the event_add.php page with=
malicious myevents_id values to extract or modify sensitive database infor= mation. 2026-05-17 7.1 CVE-2018-25319 [
https://www.cve.org/CVERecord?id=3D= CVE-2018-25319 ] ExploitDB-44261 [
https://www.exploit-db.com/exploits/4426=
1 ]
Official Product Homepage [
http://www.github.com/wende60/myevents ]
VulnCheck Advisory: Redaxo CMS Addon MyEvents 2.2.1 SQL Injection via event= _add.php [
https://www.vulncheck.com/advisories/redaxo-cms-addon-myevents-s= ql-injection-via-event-add-php ]
=C2=A0 woocommerce-csvimport--WooCommerce CSV-Importer Woocommerce CSV Impo= rter 3.3.6 contains a path traversal vulnerability that allows any register=
ed user to delete arbitrary files by submitting unescaped filenames through=
the delete_export_file AJAX action. Attackers can craft POST requests with=
directory traversal sequences in the filename parameter to delete sensitiv=
e files like wp-config.php outside the intended export directory. 2026-05-1=
7 7.5 CVE-2018-25325 [
https://www.cve.org/CVERecord?id=3DCVE-2018-25325 ] = ExploitDB-44433 [
https://www.exploit-db.com/exploits/44433 ]
Official Product Homepage [
http://lenonleite.com.br/ ]
VulnCheck Advisory: Woocommerce CSV Importer 3.3.6 Path Traversal File Dele= tion [
https://www.vulncheck.com/advisories/woocommerce-csv-importer-path-t= raversal-file-deletion ]
=C2=A0 wp-google-drive--Google Drive Google Drive for WordPress 2.2 contain=
s a path traversal vulnerability that allows unauthenticated attackers to r= ead arbitrary files by injecting directory traversal sequences in the file_= name parameter. Attackers can send POST requests to gdrive-ajaxs.php with t=
he ajaxstype parameter set to del_fl_bkp and file_name containing traversal=
sequences ../../wp-config.php to access sensitive configuration files. 202= 6-05-17 7.5 CVE-2018-25326 [
https://www.cve.org/CVERecord?id=3DCVE-2018-25= 326 ] ExploitDB-44435 [
https://www.exploit-db.com/exploits/44435 ]
Official Product Homepage [
http://lenonleite.com.br/ ]
VulnCheck Advisory: Google Drive for WordPress 2.2 Path Traversal RCE via g= drive-ajaxs.php [
https://www.vulncheck.com/advisories/google-drive-for-wor= dpress-path-traversal-rce-via-gdrive-ajaxs-php ]
=C2=A0 wp-with-spritz--WP with Spritz WordPress Plugin WP with Spritz 1.0 c= ontains a remote file inclusion vulnerability that allows unauthenticated a= ttackers to read arbitrary files by injecting file paths into the url param= eter. Attackers can send GET requests to wp.spritz.content.filter.php with = malicious url values to access sensitive files like system configuration an=
d credentials. 2026-05-17 7.5 CVE-2018-25329 [
https://www.cve.org/CVERecor= d?id=3DCVE-2018-25329 ] ExploitDB-44544 [
https://www.exploit-db.com/exploi= ts/44544 ]
Product Reference [
https://downloads.wordpress.org/plugin/wp-with-spritz.z=
ip ]
VulnCheck Advisory: WordPress Plugin WP with Spritz 1.0 Remote File Inclusi=
on [
https://www.vulncheck.com/advisories/wordpress-plugin-wp-with-spritz-r= emote-file-inclusion ]
=C2=A0 Fabrikar--com_fabrik Joomla com_fabrik 3.9.11 contains a directory t= raversal vulnerability that allows unauthenticated attackers to list arbitr= ary files by manipulating the folder parameter. Attackers can send GET requ= ests to the onAjax_files method with path traversal sequences to enumerate = files in system directories outside the intended web root. 2026-05-13 7.5 C= VE-2020-37219 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37219 ] Exploit= DB-48263 [
https://www.exploit-db.com/exploits/48263 ]
Official Product Homepage [
https://fabrikar.com/ ]
Product Reference [
https://fabrikar.com/downloads ]
VulnCheck Advisory: Joomla com_fabrik 3.9.11 Directory Traversal via image.= php [
https://www.vulncheck.com/advisories/joomla-com-fabrik-directory-trav= ersal-via-image-php ]
=C2=A0 www.huawei.com--Huawei HG630 Router Huawei HG630 V2 router contains =
an authentication bypass vulnerability that allows unauthenticated attacker=
s to obtain administrative access by retrieving the device serial number. A= ttackers can query the /api/system/deviceinfo endpoint without authenticati=
on to extract the SerialNumber field, then use the last 8 characters as the=
default password to login to the router. 2026-05-13 7.5 CVE-2020-37220 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2020-37220 ] ExploitDB-48310 [ https:= //www.exploit-db.com/exploits/48310 ]
Reference [
https://www.youtube.com/watch?v=3DvOrIL7L_cVc ]
VulnCheck Advisory: Huawei HG630 V2 Router Authentication Bypass via Serial=
Number [
https://www.vulncheck.com/advisories/huawei-hg630-v2-router-authe= ntication-bypass-via-serial-number ]
=C2=A0 Kuicms--Kuicms Php EE Kuicms Php EE 2.0 contains a persistent cross-= site scripting vulnerability that allows unauthenticated attackers to injec=
t malicious scripts by submitting crafted content through the bbs reply end= point. Attackers can send POST requests to /web/?c=3Dbbs&a=3Dreply with HTM=
L and JavaScript payloads in the content parameter to execute arbitrary scr= ipts in users' browsers. 2026-05-13 7.2 CVE-2020-37222 [
https://www.cve.or= g/CVERecord?id=3DCVE-2020-37222 ] ExploitDB-48526 [
https://www.exploit-db.= com/exploits/48526 ]
Official Product Homepage [
https://kuicms.com ]
Product Reference [
https://kuicms.com/kuicms.zip ]
VulnCheck Advisory: Kuicms Php EE 2.0 Persistent Cross-Site Scripting via b=
bs reply [
https://www.vulncheck.com/advisories/kuicms-php-ee-persistent-cr= oss-site-scripting-via-bbs-reply ]
=C2=A0 Iobit--IObit Uninstaller IObit Uninstaller 9.5.0.15 contains an unqu= oted service path vulnerability in the IObitUnSvr service that allows local=
attackers to escalate privileges to SYSTEM level. Attackers can place a ma= licious executable named IObit.exe in the C:\Program Files (x86)\IObit dire= ctory and restart the service to execute code with SYSTEM privileges. 2026-= 05-13 7.8 CVE-2020-37223 [
https://www.cve.org/CVERecord?id=3DCVE-2020-3722=
3 ] ExploitDB-48543 [
https://www.exploit-db.com/exploits/48543 ]
Official Product Homepage [
https://www.iobit.com ]
Product Reference [
https://www.iobit.com/en/advanceduninstaller.php ] VulnCheck Advisory: IObit Uninstaller 9.5.0.15 Unquoted Service Path Privil= ege Escalation [
https://www.vulncheck.com/advisories/iobit-uninstaller-unq= uoted-service-path-privilege-escalation ]
=C2=A0 Joomsky--J2 JOBS Joomla J2 JOBS 1.3.0 contains an authenticated SQL = injection vulnerability that allows authenticated attackers to manipulate d= atabase queries by injecting SQL code through the 'sortby' parameter. Attac= kers can send POST requests to the administrator index with malicious 'sort= by' values to extract sensitive database information. 2026-05-13 7.1 CVE-20= 20-37224 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37224 ] ExploitDB-48= 648 [
https://www.exploit-db.com/exploits/48648 ]
Official Product Homepage [
https://joomsky.com/ ]
Product Reference [
https://joomsky.com/products/js-jobs-pro.html ]
VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via so= rtby [
https://www.vulncheck.com/advisories/joomla-j2-jobs-authenticated-sq= l-injection-via-sortby ]
=C2=A0 Joomsky--J2 JOBS Joomla J2 JOBS 1.3.0 contains an authenticated SQL = injection vulnerability that allows authenticated attackers to manipulate d= atabase queries by injecting SQL code through the 'sortby' parameter. Attac= kers can send POST requests to the administrator index with malicious 'sort= by' values to extract sensitive database information using automated tools.=
2026-05-13 7.1 CVE-2020-37226 [
https://www.cve.org/CVERecord?id=3DCVE-202= 0-37226 ] ExploitDB-48670 [
https://www.exploit-db.com/exploits/48670 ] Official Product Homepage [
https://joomsky.com/ ]
Product Reference [
https://joomsky.com/products/js-jobs-pro.html ]
VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via so= rtby [
https://www.vulncheck.com/advisories/joomla-j2-jobs-authenticated-sq= l-injection-via-sortby-2 ]
=C2=A0 Oki--OKI sPSV Port Manager OKI sPSV Port Manager 1.0.41 contains an = unquoted service path vulnerability in the sPSVOpLclSrv service that allows=
local attackers to escalate privileges by inserting executable files into = the unquoted path. Attackers can place a malicious executable in a director=
y within the service path that will execute with LocalSystem privileges whe=
n the service restarts or the system reboots. 2026-05-16 7.8 CVE-2020-37229=
[
https://www.cve.org/CVERecord?id=3DCVE-2020-37229 ] ExploitDB-49005 [ ht= tps://www.exploit-db.com/exploits/49005 ]
Official Product Homepage [
https://www.oki.com/ ]
Product Reference [
https://www.oki.com/mx/printing/download/sPSV_010041_2_= 270910.exe ]
VulnCheck Advisory: OKI sPSV Port Manager 1.0.41 Unquoted Service Path Priv= ilege Escalation [
https://www.vulncheck.com/advisories/oki-spsv-port-manag= er-unquoted-service-path-privilege-escalation ]
=C2=A0 Syncplify--Syncplify.me Server! Syncplify.me Server! 5.0.37 contains=
an unquoted service path vulnerability in the SMWebRestServicev5 service t= hat allows local attackers to escalate privileges by exploiting the unquote=
d binary path. Attackers can insert a malicious executable into the service=
path and execute it with LocalSystem privileges when the service restarts =
or the system reboots. 2026-05-16 7.8 CVE-2020-37230 [
https://www.cve.org/= CVERecord?id=3DCVE-2020-37230 ] ExploitDB-49009 [
https://www.exploit-db.co= m/exploits/49009 ]
Official Product Homepage [
https://www.syncplify.me/ ]
Product Reference [
https://download.syncplify.me/SMServer_Setup.exe ] VulnCheck Advisory: Syncplify.me Server! 5.0.37 Unquoted Service Path Privi= lege Escalation [
https://www.vulncheck.com/advisories/syncplify-me-server-= unquoted-service-path-privilege-escalation ]
=C2=A0 Cybertronsoft--Privacy Drive Privacy Drive 3.17.0 contains an unquot=
ed service path vulnerability in the pdsvc.exe service binary that allows l= ocal attackers to escalate privileges by exploiting the service startup pro= cess. Attackers can place malicious executables in the unquoted path direct= ories to execute arbitrary code with LocalSystem privileges during service = startup or system reboot. 2026-05-16 7.8 CVE-2020-37231 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2020-37231 ] ExploitDB-49023 [
https://www.exploit-db= .com/exploits/49023 ]
Official Product Homepage [
https://www.cybertronsoft.com/ ]
Product Reference [
https://www.cybertronsoft.com/download/privacy-drive-se= tup.exe ]
VulnCheck Advisory: Privacy Drive 3.17.0 Unquoted Service Path Privilege Es= calation [
https://www.vulncheck.com/advisories/privacy-drive-unquoted-serv= ice-path-privilege-escalation ]
=C2=A0 Iobit--Advanced System Care Service Advanced System Care Service 13.= 0.0.157 contains an unquoted service path vulnerability in the AdvancedSyst= emCareService13 service binary path that allows local attackers to escalate=
privileges. Attackers can place malicious executables in the system root p= ath that will be executed with LocalSystem privileges during service startu=
p or system reboot. 2026-05-16 7.8 CVE-2020-37232 [
https://www.cve.org/CVE= Record?id=3DCVE-2020-37232 ] ExploitDB-49049 [
https://www.exploit-db.com/e= xploits/49049 ]
Official Product Homepage [
https://www.iobit.com ]
Product Reference [
https://www.iobit.com/es/advancedsystemcarepro.php ] VulnCheck Advisory: Advanced System Care Service 13.0.0.157 Unquoted Servic=
e Path Privilege Escalation [
https://www.vulncheck.com/advisories/advanced= -system-care-service-unquoted-service-path-privilege-escalation ]
=C2=A0 Supsystic--Digital Publications Supsystic Digital Publications 1.6.9=
contains a path traversal vulnerability in the Folder input field that all= ows attackers to access files outside the web root by injecting directory t= raversal sequences. Additionally, the plugin fails to sanitize input fields=
in publication settings, allowing stored cross-site scripting attacks thro= ugh script injection in parameters like Area Width and Publication Width th=
at execute when publications are viewed or edited. 2026-05-16 7.5 CVE-2020-= 37245 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37245 ] ExploitDB-49542=
[
https://www.exploit-db.com/exploits/49542 ]
Official Product Homepage [
https://supsystic.com/ ]
Product Reference [
https://downloads.wordpress.org/plugin/digital-publicat= ions-by-supsystic.1.6.9.zip ]
VulnCheck Advisory: WordPress Plugin Supsystic Digital Publications 1.6.9 P= ath Traversal XSS [
https://www.vulncheck.com/advisories/wordpress-plugin-s= upsystic-digital-publications-path-traversal-xss ]
=C2=A0 Kite--Kite Kite 4.2.0.1 U1 contains an unquoted service path vulnera= bility in the KiteService Windows service that allows local attackers to es= calate privileges by exploiting the service binary path. Attackers can plac=
e a malicious executable in the Program Files directory to be executed with=
LocalSystem privileges when the service starts. 2026-05-16 7.8 CVE-2020-37= 247 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37247 ] ExploitDB-50975 [=
https://www.exploit-db.com/exploits/50975 ]
Official Product Homepage [
https://www.kite.com/ ]
VulnCheck Advisory: Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalat= ion [
https://www.vulncheck.com/advisories/kite-u1-unquoted-service-path-pr= ivilege-escalation ]
=C2=A0 Home-Assistant--Home Assistant Community Store (HACS) Home Assistant=
Community Store (HACS) 1.10.0 contains a path traversal vulnerability that=
allows unauthenticated attackers to read sensitive files by traversing dir= ectories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/= auth file containing user credentials and refresh tokens, then craft valid = JWT tokens to gain administrative access to Home Assistant instances. 2026-= 05-16 7.5 CVE-2021-47942 [
https://www.cve.org/CVERecord?id=3DCVE-2021-4794=
2 ] ExploitDB-49495 [
https://www.exploit-db.com/exploits/49495 ]
Official Product Homepage [
https://www.home-assistant.io/ ]
Product Reference [
https://github.com/hacs/integration ]
VulnCheck Advisory: Home Assistant Community Store 1.10.0 Path Traversal Ac= count Takeover [
https://www.vulncheck.com/advisories/home-assistant-commun= ity-store-path-traversal-account-takeover ]
=C2=A0 Wpgraphql--WPGraphQL WordPress Plugin WPGraphQL 1.3.5 contains a den= ial of service vulnerability that allows unauthenticated attackers to exhau=
st server resources by sending batched GraphQL queries with duplicated fiel= ds. Attackers can send POST requests to the GraphQL endpoint with amplified=
field duplication payloads to trigger server out-of-memory conditions and = MySQL connection errors. 2026-05-15 7.5 CVE-2021-47959 [
https://www.cve.or= g/CVERecord?id=3DCVE-2021-47959 ] ExploitDB-49807 [
https://www.exploit-db.= com/exploits/49807 ]
Official Product Homepage [
https://www.wpgraphql.com/ ]
VulnCheck Advisory: WordPress Plugin WPGraphQL 1.3.5 Denial of Service [ ht= tps://www.vulncheck.com/advisories/wordpress-plugin-wpgraphql-denial-of-ser= vice ]
=C2=A0 AnotherNote--Anote Anote 1.0 contains a persistent cross-site script= ing vulnerability that allows attackers to execute arbitrary code by inject= ing malicious payloads into markdown files stored within the application. A= ttackers can craft malicious markdown files with embedded JavaScript that e= xecutes system commands when opened, enabling remote code execution on the = victim's computer. 2026-05-15 7.2 CVE-2021-47963 [
https://www.cve.org/CVER= ecord?id=3DCVE-2021-47963 ] ExploitDB-49836 [
https://www.exploit-db.com/ex= ploits/49836 ]
Official Product Homepage [
https://github.com/AnotherNote/anote ]
VulnCheck Advisory: Anote 1.0 Persistent Cross-Site Scripting Remote Code E= xecution [
https://www.vulncheck.com/advisories/anote-persistent-cross-site= -scripting-remote-code-execution ]
=C2=A0 color-notes--Color Notes Color Notes 1.4 contains a denial of servic=
e vulnerability that allows attackers to crash the application by pasting e= xcessively long character strings into note fields. Attackers can generate =
a payload containing 350,000 repeated characters and paste it twice into a = new note to cause the application to stop responding. 2026-05-16 7.5 CVE-20= 21-47969 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47969 ] ExploitDB-49= 952 [
https://www.exploit-db.com/exploits/49952 ]
VulnCheck Advisory: Color Notes 1.4 Denial of Service via Long Character St= ring [
https://www.vulncheck.com/advisories/color-notes-denial-of-service-v= ia-long-character-string ]
=C2=A0 macaron-notes-great-notebook--Macaron Notes Gear Notebook Macaron No= tes 5.5 contains a denial of service vulnerability that allows attackers to=
crash the application by creating notes with excessively long character st= rings. Attackers can generate a payload containing 350000 repeated characte=
rs and paste it into a note field to trigger application crash and stop fun= ctionality. 2026-05-16 7.5 CVE-2021-47970 [
https://www.cve.org/CVERecord?i= d=3DCVE-2021-47970 ] ExploitDB-49953 [
https://www.exploit-db.com/exploits/= 49953 ]
VulnCheck Advisory: Macaron Notes 5.5 Denial of Service via Buffer Overflow=
[
https://www.vulncheck.com/advisories/macaron-notes-denial-of-service-via= -buffer-overflow ]
=C2=A0 my-notes-safe--My Notes Safe My Notes Safe 5.3 contains a denial of = service vulnerability that allows attackers to crash the application by pas= ting excessively long character strings into note fields. Attackers can gen= erate a payload containing 350000 repeated characters and paste it twice in=
to a new note to trigger an application crash. 2026-05-16 7.5 CVE-2021-4797=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47971 ] ExploitDB-49954 [ h= ttps://www.exploit-db.com/exploits/49954 ]
VulnCheck Advisory: My Notes Safe 5.3 Denial of Service via Buffer Overflow=
[
https://www.vulncheck.com/advisories/my-notes-safe-denial-of-service-via= -buffer-overflow ]
=C2=A0 sticky-notes-color-widgets--Sticky Notes Color Widgets Sticky Notes =
& Color Widgets 1.4.2 contains a denial of service vulnerability that allow=
s attackers to crash the application by creating notes with excessively lon=
g character strings. Attackers can paste large payloads of repeated charact= ers into note fields to trigger application crashes and make the applicatio=
n stop responding. 2026-05-16 7.5 CVE-2021-47972 [
https://www.cve.org/CVER= ecord?id=3DCVE-2021-47972 ] ExploitDB-49957 [
https://www.exploit-db.com/ex= ploits/49957 ]
VulnCheck Advisory: Sticky Notes & Color Widgets 1.4.2 Denial of Service [ =
https://www.vulncheck.com/advisories/sticky-notes-color-widgets-denial-of-s= ervice ]
=C2=A0 sticky-notes--Sticky Notes Widget Sticky Notes Widget 3.0.6 contains=
a denial of service vulnerability that allows attackers to crash the appli= cation by pasting excessively long character strings into note fields. Atta= ckers can generate a payload containing 350000 repeated characters and past=
e it twice into a new note to trigger an application crash on iOS devices. = 2026-05-16 7.5 CVE-2021-47973 [
https://www.cve.org/CVERecord?id=3DCVE-2021= -47973 ] ExploitDB-49978 [
https://www.exploit-db.com/exploits/49978 ] VulnCheck Advisory: Sticky Notes Widget 3.0.6 Denial of Service via Buffer = Overflow [
https://www.vulncheck.com/advisories/sticky-notes-widget-denial-= of-service-via-buffer-overflow ]
=C2=A0 Vxsearch--VX Search VX Search 13.5.28 contains an unquoted service p= ath vulnerability in both VX Search Server and VX Search Enterprise service=
s that allows local attackers to escalate privileges. Attackers can place m= alicious executables in unquoted path directories like C:\Program Files\VX = Search to execute arbitrary code with LocalSystem privileges when services = restart. 2026-05-16 7.8 CVE-2021-47974 [
https://www.cve.org/CVERecord?id= =3DCVE-2021-47974 ] ExploitDB-50026 [
https://www.exploit-db.com/exploits/5= 0026 ]
Official Product Homepage [
https://www.vxsearch.com ]
VulnCheck Advisory: VX Search 13.5.28 Unquoted Service Path Privilege Escal= ation [
https://www.vulncheck.com/advisories/vx-search-unquoted-service-pat= h-privilege-escalation ]
=C2=A0 Wplearnmanager--WP Learn Manager WP Learn Manager 1.1.2 contains a s= tored cross-site scripting vulnerability that allows unauthenticated attack= ers to inject malicious scripts through the fieldtitle parameter. Attackers=
can submit POST requests to the jslm_fieldordering page with XSS payloads =
in the fieldtitle field to execute arbitrary JavaScript when administrators=
view the field ordering interface. 2026-05-16 7.2 CVE-2021-47975 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2021-47975 ] ExploitDB-50086 [
https://www.= exploit-db.com/exploits/50086 ]
Official Product Homepage [
https://wplearnmanager.com/ ]
Product Reference [
https://wordpress.org/plugins/learn-manager/ ]
VulnCheck Advisory: WordPress Plugin WP Learn Manager 1.1.2 Stored XSS [ ht= tps://www.vulncheck.com/advisories/wordpress-plugin-wp-learn-manager-stored= -xss ]
=C2=A0 Gotmls--Malware Security and Bruteforce Firewall WordPress Plugin An= ti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory tr= aversal vulnerability that allows unauthenticated attackers to read arbitra=
ry files by manipulating the file parameter. Attackers can send requests to=
the duplicator_download action via admin-ajax.php with path traversal sequ= ences to access sensitive system files outside the intended directory. 2026= -05-16 7.5 CVE-2021-47977 [
https://www.cve.org/CVERecord?id=3DCVE-2021-479=
77 ] ExploitDB-50107 [
https://www.exploit-db.com/exploits/50107 ]
Official Product Homepage [
https://gotmls.net/ ]
Product Reference [
https://gotmls.net/downloads/ ]
VulnCheck Advisory: WordPress Anti-Malware Security Bruteforce Firewall 4.2= 0.59 Directory Traversal [
https://www.vulncheck.com/advisories/wordpress-a= nti-malware-security-bruteforce-firewall-directory-traversal ]
=C2=A0 Getfuelcms--Fuel CMS Fuel CMS 1.4.13 contains a blind SQL injection = vulnerability that allows authenticated attackers to manipulate database qu= eries by injecting SQL code through the 'col' parameter in the Activity Log=
interface. Attackers can send requests to the logs endpoint with malicious=
SQL payloads in the 'col' parameter to extract database information based =
on response time delays. 2026-05-16 7.1 CVE-2021-47980 [
https://www.cve.or= g/CVERecord?id=3DCVE-2021-47980 ] ExploitDB-50523 [
https://www.exploit-db.= com/exploits/50523 ]
Official Product Homepage [
https://www.getfuelcms.com/ ]
Product Reference [
https://github.com/daylightstudio/FUEL-CMS/archive/1.4.= 13.zip ]
VulnCheck Advisory: Fuel CMS 1.4.13 Blind SQL Injection via col Parameter [=
https://www.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-= parameter ]
=C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 b= efore 18.11.3 that could have allowed an unauthenticated user to cause deni=
al of service by sending specially crafted payloads on certain API endpoint=
s. 2026-05-14 7.5 CVE-2025-14869 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-14869 ] HackerOne Bug Bounty Report #3447146 [
https://hackerone.com/re= ports/3447146 ]
https://gitlab.com/gitlab-org/gitlab/-/work_items/584489 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
=C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 b= efore 18.11.3 that could have allowed an unauthenticated user to cause deni=
al of service by sending specially crafted JSON payloads due to insufficien=
t input validation. 2026-05-14 7.5 CVE-2025-14870 [
https://www.cve.org/CVE= Record?id=3DCVE-2025-14870 ] HackerOne Bug Bounty Report #3446641 [ https:/= /hackerone.com/reports/3446641 ]
https://gitlab.com/gitlab-org/gitlab/-/work_items/584490 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
=C2=A0=20
Back to top [ #top ]
Medium Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info Patch Info S= imple-Fields--Simple Fields Simple Fields 0.2 through 0.3.5 WordPress Plugi=
n contains a local file inclusion vulnerability that allows unauthenticated=
attackers to read arbitrary files by injecting null bytes into the wp_absp= ath parameter on PHP versions before 5.3.4. Attackers can supply malicious = wp_abspath values to simple_fields.php to include files like /etc/passwd or=
inject PHP code into Apache logs for remote code execution when allow_url_= include is enabled. 2026-05-17 6.2 CVE-2018-25324 [
https://www.cve.org/CVE= Record?id=3DCVE-2018-25324 ] ExploitDB-44425 [
https://www.exploit-db.com/e= xploits/44425 ]
Official Product Homepage [
http://simple-fields.com ]
Product Reference [
https://downloads.wordpress.org/plugin/simple-fields.0.= 3.5.zip ]
VulnCheck Advisory: Simple Fields 0.2-0.3.5 Local File Inclusion via wp_abs= path [
https://www.vulncheck.com/advisories/simple-fields-local-file-inclus= ion-via-wp-abspath ]
=C2=A0 zenar--Zenar Content Management System Zenar Content Management Syst=
em contains a cross-site scripting vulnerability that allows unauthenticate=
d attackers to inject malicious scripts by manipulating form parameters in = POST requests. Attackers can inject script tags through the current_page pa= rameter sent to the ajax.php endpoint, which reflects unsanitized user inpu=
t in the response HTML to execute arbitrary JavaScript in victim browsers. = 2026-05-17 6.1 CVE-2018-25331 [
https://www.cve.org/CVERecord?id=3DCVE-2018= -25331 ] ExploitDB-44664 [
https://www.exploit-db.com/exploits/44664 ]
Official Product Homepage [
http://demo.zenar.io ]
Product Reference [
https://zenar.io/ ]
VulnCheck Advisory: Zenar Content Management System Cross-Site Scripting vi=
a ajax.php [
https://www.vulncheck.com/advisories/zenar-content-management-= system-cross-site-scripting-via-ajax-php ]
=C2=A0 Powie--WHOIS Domain Check Powie's WHOIS Domain Check 0.9.31 contains=
a persistent cross-site scripting vulnerability that allows authenticated = attackers to inject arbitrary JavaScript by exploiting unsanitized input fi= elds in plugin settings. Attackers can submit malicious payloads through te= xtarea and input elements in the pwhois_settings.php configuration page to = execute JavaScript in the admin context and escalate privileges. 2026-05-13=
6.4 CVE-2020-37225 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37225 ] E= xploitDB-48656 [
https://www.exploit-db.com/exploits/48656 ]
Official Product Homepage [
https://powie.de ]
Official Product Homepage [
https://blog.haao.sh ]
Product Reference [
https://wordpress.org/plugins/powies-whois/ ]
VulnCheck Advisory: Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site=
Scripting [
https://www.vulncheck.com/advisories/powie-s-whois-domain-chec= k-persistent-cross-site-scripting ]
=C2=A0 Wordpress--Buddypress WordPress Plugin Buddypress 6.2.0 contains a p= ersistent cross-site scripting vulnerability that allows authenticated atta= ckers with moderator privileges to inject malicious script code through the=
figure parameter in wp:html blocks. Attackers can inject iframe elements w= ith event handlers like onload that execute when administrators or privileg=
ed users preview or view the affected page content, enabling session hijack= ing and persistent phishing attacks. 2026-05-16 6.4 CVE-2020-37233 [ https:= //www.cve.org/CVERecord?id=3DCVE-2020-37233 ] ExploitDB-49061 [
https://www= .exploit-db.com/exploits/49061 ]
Official Product Homepage [
https://wordpress.org/plugins/buddypress/ ] VulnCheck Advisory: WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site=
Scripting [
https://www.vulncheck.com/advisories/wordpress-plugin-buddypre= ss-persistent-cross-site-scripting ]
=C2=A0 Internetdownloadmanager--Internet Download Manager Internet Download=
Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler = component that allows local attackers to crash the application by supplying=
oversized input. Attackers can paste malicious data exceeding 5000 bytes i= nto the 'Open the following file when done' field to trigger a denial of se= rvice condition. 2026-05-16 6.2 CVE-2020-37234 [
https://www.cve.org/CVERec= ord?id=3DCVE-2020-37234 ] ExploitDB-49083 [
https://www.exploit-db.com/expl= oits/49083 ]
Official Product Homepage [
http://www.internetdownloadmanager.com/ ]
Product Reference [
http://www.internetdownloadmanager.com/download.html ] VulnCheck Advisory: Internet Download Manager 6.38.12 Scheduler Buffer Over= flow [
https://www.vulncheck.com/advisories/internet-download-manager-sched= uler-buffer-overflow ]
=C2=A0 themeftc--Theme Wibar WordPress Theme Wibar 1.1.8 contains a stored = cross-site scripting vulnerability in the Brand component that allows authe= nticated users to inject malicious scripts by manipulating the Logo URL par= ameter. Attackers with editor, administrator, contributor, or author privil= eges can inject base64-encoded script payloads through the ftc_brand_url in= put field to execute arbitrary JavaScript when users visit the brand page. = 2026-05-16 6.4 CVE-2020-37235 [
https://www.cve.org/CVERecord?id=3DCVE-2020= -37235 ] ExploitDB-49107 [
https://www.exploit-db.com/exploits/49107 ]
Official Product Homepage [
http://demo.themeftc.com/wibar ]
Product Reference [
https://themeforest.net/item/wibar-responsive-woocommer= ce-wordpress-theme/20994798 ]
VulnCheck Advisory: WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting=
via Brand Component [
https://www.vulncheck.com/advisories/wordpress-theme= -wibar-stored-cross-site-scripting-via-brand-component ]
=C2=A0 Netartmedia--NewsLister NewsLister contains an authenticated persist= ent cross-site scripting vulnerability that allows authenticated administra= tors to inject malicious scripts through the title parameter in the news ad= dition interface. Attackers can inject JavaScript payloads via the title fi= eld in the admin panel that execute when news items are viewed by other use= rs. 2026-05-16 6.4 CVE-2020-37236 [
https://www.cve.org/CVERecord?id=3DCVE-= 2020-37236 ] ExploitDB-49160 [
https://www.exploit-db.com/exploits/49160 ] Official Product Homepage [
https://www.netartmedia.net/newslister.html ] VulnCheck Advisory: NewsLister Authenticated Persistent Cross-Site Scriptin=
g via Admin Panel [
https://www.vulncheck.com/advisories/newslister-authent= icated-persistent-cross-site-scripting-via-admin-panel ]
=C2=A0 Compo--Composr CMS Composr CMS 10.0.34 contains a persistent cross-s= ite scripting vulnerability that allows authenticated administrators to inj= ect malicious scripts through the banner management interface. Attackers wi=
th admin credentials can inject XSS payloads in the Description field of th=
e Add banner functionality, which execute for all website visitors when the=
y access the home page. 2026-05-16 6.4 CVE-2020-37237 [
https://www.cve.org= /CVERecord?id=3DCVE-2020-37237 ] ExploitDB-49190 [
https://www.exploit-db.c= om/exploits/49190 ]
Official Product Homepage [
https://compo.sr/ ]
Product Reference [
https://compo.sr/download.htm ]
VulnCheck Advisory: Composr CMS 10.0.34 Persistent Cross-Site Scripting via=
banners [
https://www.vulncheck.com/advisories/composr-cms-persistent-cros= s-site-scripting-via-banners ]
=C2=A0 Cmsmadesimple--CMS Made Simple CMS Made Simple 2.2.15 contains a sto= red cross-site scripting vulnerability that allows authenticated users with=
Content Manager access to inject malicious scripts through SVG file upload=
s. Attackers can upload SVG files containing embedded JavaScript to the fil=
e manager, which executes when other authenticated users access the uploade=
d file, enabling cookie theft and session hijacking. 2026-05-16 6.4 CVE-202= 0-37238 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37238 ] ExploitDB-491=
99 [
https://www.exploit-db.com/exploits/49199 ]
Official Product Homepage [
https://www.cmsmadesimple.org/ ]
Product Reference [
https://www.cmsmadesimple.org/downloads ]
VulnCheck Advisory: CMS Made Simple 2.2.15 Stored XSS via SVG File Upload [=
https://www.vulncheck.com/advisories/cms-made-simple-stored-xss-via-svg-fi= le-upload ]
=C2=A0 Codekernel--Queue Management System Queue Management System 4.0.0 co= ntains a stored cross-site scripting vulnerability that allows authenticate=
d administrators to inject malicious scripts through user creation fields. = Attackers can insert JavaScript payloads in the First Name, Last Name, and = Email fields during user creation, which execute when viewing the User List=
page. 2026-05-16 6.4 CVE-2020-37240 [
https://www.cve.org/CVERecord?id=3DC= VE-2020-37240 ] ExploitDB-49296 [
https://www.exploit-db.com/exploits/49296=
]
Official Product Homepage [
http://codekernel.net/ ]
Product Reference [
https://codecanyon.net/item/queue-management-system/220= 29961 ]
VulnCheck Advisory: Queue Management System 4.0.0 Stored XSS via Add User [=
https://www.vulncheck.com/advisories/queue-management-system-stored-xss-vi= a-add-user ]
=C2=A0 Supsystic--Backup Supsystic Backup 2.3.9 contains a local file inclu= sion vulnerability that allows unauthenticated attackers to read and delete=
arbitrary files by manipulating the download path parameter. Attackers can=
modify the download parameter in admin.php requests with directory travers=
al sequences to access sensitive files like /etc/passwd or delete files via=
the removeAction parameter. 2026-05-16 6.2 CVE-2020-37246 [
https://www.cv= e.org/CVERecord?id=3DCVE-2020-37246 ] ExploitDB-49545 [
https://www.exploit= -db.com/exploits/49545 ]
Official Product Homepage [
https://supsystic.com/ ]
Product Reference [
https://downloads.wordpress.org/plugin/backup-by-supsys= tic.zip ]
VulnCheck Advisory: WordPress Plugin Supsystic Backup 2.3.9 Local File Incl= usion [
https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-bac= kup-local-file-inclusion ]
=C2=A0 Cookielawinfo--Cookie Law Bar Cookie Law Bar 1.2.1 contains a stored=
cross-site scripting vulnerability that allows authenticated attackers to = inject malicious scripts by submitting unsanitized input to the Bar Message=
field. Attackers can inject script payloads through the plugin settings pa=
ge that execute in the browsers of all WordPress users viewing the site, en= abling cookie theft and sensitive data exfiltration. 2026-05-16 6.4 CVE-202= 1-47957 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47957 ] ExploitDB-499=
05 [
https://www.exploit-db.com/exploits/49905 ]
Official Product Homepage [
https://www.cookielawinfo.com/wordpress-plugin/=
]
Product Reference [
https://wordpress.org/plugins/cookie-law-bar/ ]
VulnCheck Advisory: WordPress Plugin Cookie Law Bar 1.2.1 Stored XSS via cl= b_bar_msg [
https://www.vulncheck.com/advisories/wordpress-plugin-cookie-la= w-bar-stored-xss-via-clb-bar-msg ]
=C2=A0 savsofts--Savsoft Quiz Savsoft Quiz 5.0 contains a persistent cross-= site scripting vulnerability in the user account settings page that allows = authenticated attackers to inject malicious HTML and JavaScript code. Attac= kers can inject script payloads into user profile fields at the edit_user e= ndpoint, which execute in the browsers of users viewing the affected profil=
e after submission. 2026-05-15 6.4 CVE-2021-47962 [
https://www.cve.org/CVE= Record?id=3DCVE-2021-47962 ] ExploitDB-49825 [
https://www.exploit-db.com/e= xploits/49825 ]
Official Product Homepage [
https://savsoftquiz.com ]
Product Reference [
https://github.com/savsofts/savsoftquiz_v5 ]
VulnCheck Advisory: Savsoft Quiz 5.0 Persistent Cross-Site Scripting via Us=
er Settings [
https://www.vulncheck.com/advisories/savsoft-quiz-persistent-= cross-site-scripting-via-user-settings ]
=C2=A0 Timeclock--PHP Timeclock PHP Timeclock 1.04 contains multiple cross-= site scripting vulnerabilities that allow unauthenticated attackers to inje=
ct arbitrary JavaScript by manipulating URL paths and POST parameters. Atta= ckers can append malicious payloads to login.php, timeclock.php, audit.php,=
and timerpt.php endpoints, or inject code through from_date and to_date pa= rameters in report requests to execute scripts in user browsers. 2026-05-15=
6.1 CVE-2021-47967 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47967 ] E= xploitDB-49853 [
https://www.exploit-db.com/exploits/49853 ]
Official Product Homepage [
http://timeclock.sourceforge.net ]
Product Reference [
https://sourceforge.net/projects/timeclock/files/PHP%20= Timeclock/PHP%20Timeclock%201.04/ ]
VulnCheck Advisory: PHP Timeclock 1.04 Multiple Cross-Site Scripting via Pa= rameters [
https://www.vulncheck.com/advisories/php-timeclock-multiple-cros= s-site-scripting-via-parameters ]
=C2=A0 Podcastgenerator--Podcast Generator Podcast Generator 3.1 contains a=
persistent cross-site scripting vulnerability that allows authenticated at= tackers to inject malicious scripts by submitting unfiltered JavaScript cod=
e in the long_description parameter. Attackers can inject script tags throu=
gh episode creation or editing requests to execute arbitrary JavaScript whe=
n other users view the episode details. 2026-05-15 6.4 CVE-2021-47968 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2021-47968 ] ExploitDB-49866 [
https://= www.exploit-db.com/exploits/49866 ]
Official Product Homepage [
https://podcastgenerator.net/demoV2/ ]
Product Reference [
https://podcastgenerator.net/download ]
VulnCheck Advisory: Podcast Generator 3.1 Persistent Cross-Site Scripting v=
ia long_description [
https://www.vulncheck.com/advisories/podcast-generato= r-persistent-cross-site-scripting-via-long-description ]
=C2=A0 Processmaker--ProcessMaker ProcessMaker 3.5.4 contains a local file = inclusion vulnerability that allows unauthenticated attackers to read arbit= rary files by exploiting improper path traversal validation. Attackers can = send requests with directory traversal sequences to access sensitive system=
files like /etc/passwd without authentication. 2026-05-16 6.2 CVE-2021-479=
78 [
https://www.cve.org/CVERecord?id=3DCVE-2021-47978 ] ExploitDB-50229 [ =
https://www.exploit-db.com/exploits/50229 ]
Official Product Homepage [
https://www.processmaker.com/ ]
VulnCheck Advisory: ProcessMaker 3.5.4 Local File Inclusion via Path Traver= sal [
https://www.vulncheck.com/advisories/processmaker-local-file-inclusio= n-via-path-traversal ]
=C2=A0 interactivegeomaps--MapGeo Interactive Geo Maps The MapGeo - Interac= tive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Sc= ripting via the 'map' parameter in the display-map shortcode in all version=
s up to, and including, 1.6.27 due to insufficient input sanitization and o= utput escaping. This makes it possible for unauthenticated attackers to inj= ect arbitrary web scripts in pages that execute if they can successfully tr= ick a user into performing an action such as clicking on a link. 2026-05-14=
6.1 CVE-2025-15345 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15345 ] h= ttps://www.wordfence.com/threat-intel/vulnerabilities/id/bfccbf41-c861-4bf1= -b400-7858cb255b9a?source=3Dcve
https://research.cleantalk.org/cve-2025-15345 https://plugins.trac.wordpress.org/changeset?old_path=3D/interactive-geo-ma= ps/tags/1.6.27/src/Plugin/Map.php&new_path=3D/interactive-geo-maps/tags/1.6= .28/src/Plugin/Map.php
=C2=A0 hwk-fr--Advanced Custom Fields: Extended The The Advanced Custom Fie= lds: Extended plugin for WordPress is vulnerable to arbitrary shortcode exe= cution in all versions up to, and including, 0.9.2.3. This is due to the so= ftware allowing users to execute an action that does not properly validate =
a value before running do_shortcode. This makes it possible for unauthentic= ated attackers to execute arbitrary shortcodes. 2026-05-12 6.5 CVE-2025-154=
63 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15463 ]
https://www.wordfe= nce.com/threat-intel/vulnerabilities/id/f8544784-1994-47e2-be39-568d0ab9ee0= 0?source=3Dcve
https://plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includ= es/modules/form/module-form-action-email.php#L111
https://plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includ= es/modules/form/module-form-front-render.php#L35
=C2=A0 Joomsky--JS Jobs Joomla! Component Js Jobs 1.2.0 contains a cross-si=
te request forgery vulnerability that allows attackers to perform state-cha= nging actions without token validation. Attackers can craft malicious HTML = forms targeting administrative endpoints like job.jobenforcedelete to delet=
e job entries or modify component settings when administrators visit attack= er-controlled pages. 2026-05-17 5.3 CVE-2018-25327 [
https://www.cve.org/CV= ERecord?id=3DCVE-2018-25327 ] ExploitDB-44492 [
https://www.exploit-db.com/= exploits/44492 ]
Official Product Homepage [
https://www.joomsky.com ]
Product Reference [
https://extensions.joomla.org/extension/js-jobs/ ] VulnCheck Advisory: Joomla! Component Js Jobs 1.2.0 Cross-Site Request Forg= ery [
https://www.vulncheck.com/advisories/joomla-component-js-jobs-cross-s= ite-request-forgery ]
=C2=A0 Bylancer--Zechat Zechat 1.5 contains a Cross-Site Request Forgery (C= SRF) vulnerability that allows an attacker to change a user's information b=
y bypassing anti-CSRF protections. The application uses a CSRF token, but a=
n attacker can use the hashtag parameter to inject an encoded payload and b= ypass the CSRF protection, allowing for unauthorized changes to user data. = This can be exploited by tricking a user into submitting a crafted form or =
by using a script to obtain and set the CSRF token. 2026-05-17 5.4 CVE-2018= -25334 [
https://www.cve.org/CVERecord?id=3DCVE-2018-25334 ] ExploitDB-4468=
5 [
https://www.exploit-db.com/exploits/44685 ]
Official Product Homepage [
https://bylancer.com ]
VulnCheck Advisory: Zechat 1.5 Cross-Site Request Forgery (CSRF) via hashta=
g parameter [
https://www.vulncheck.com/advisories/zechat-cross-site-reques= t-forgery-csrf-via-hashtag-parameter ]
=C2=A0 Joomlaextensions--Joomla! extension jCart for OpenCart Joomla jCart = for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability th=
at allows attackers to modify user account information without authenticati= on. Attackers can craft malicious HTML forms targeting endpoints , and to c= hange user credentials, passwords, and affiliate account details when victi=
ms visit the attacker-controlled page. 2026-05-17 5.3 CVE-2018-25336 [ http= s://www.cve.org/CVERecord?id=3DCVE-2018-25336 ] ExploitDB-44788 [
https://w= ww.exploit-db.com/exploits/44788 ]
Official Product Homepage [
https://www.joomlaextensions.co.in/ ]
Product Reference [
https://extensions.joomla.org/extensions/extension/e-co= mmerce/e-commerce-integrations/jcart-for-opencart/ ]
VulnCheck Advisory: Joomla jCart for OpenCart 2.3.0.2 Cross-Site Request Fo= rgery [
https://www.vulncheck.com/advisories/joomla-jcart-for-opencart-cros= s-site-request-forgery ]
=C2=A0 Ultimate Member--ultimate-member WordPress Plugin ultimate-member 2.= 1.3 contains a local file inclusion vulnerability that allows authenticated=
attackers to include arbitrary files by manipulating the pack parameter in=
class-admin-upgrade.php. Attackers can send POST requests with malicious p= ack values to include unintended PHP files from the packages directory and = execute arbitrary code. 2026-05-13 5.5 CVE-2020-37169 [
https://www.cve.org= /CVERecord?id=3DCVE-2020-37169 ] ExploitDB-48065 [
https://www.exploit-db.c= om/exploits/48065 ]
VulnCheck Advisory: WordPress Plugin ultimate-member 2.1.3 Local File Inclu= sion [
https://www.vulncheck.com/advisories/wordpress-plugin-ultimate-membe= r-local-file-inclusion ]
=C2=A0 HUSKY--Products Filter Professional for WooCommerce WOOF Products Fi= lter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulne= rability that allows authenticated attackers to inject malicious scripts by=
entering XSS payloads in design tab textfields. Attackers can inject JavaS= cript code through fields like 'Text for block toggle' and 'Custom front cs=
s styles' that executes on frontend pages when saved, affecting all site vi= sitors. 2026-05-13 5.5 CVE-2020-37174 [
https://www.cve.org/CVERecord?id=3D= CVE-2020-37174 ] ExploitDB-48088 [
https://www.exploit-db.com/exploits/4808=
8 ]
Official Product Homepage [
https://products-filter.com/ ]
Product Reference [
https://wordpress.org/plugins/woocommerce-products-filt= er/ ]
VulnCheck Advisory: WOOF Products Filter for WooCommerce 1.2.3 Persistent X=
SS [
https://www.vulncheck.com/advisories/woof-products-filter-for-woocomme= rce-persistent-xss ]
=C2=A0 Bloofox--bloofoxCMS bloofoxCMS 0.5.2.1 contains a cross-site request=
forgery vulnerability that allows attackers to perform administrative acti= ons by tricking logged-in users into visiting malicious pages. Attackers ca=
n craft hidden forms targeting the admin user creation endpoint to add new = administrative accounts with arbitrary credentials without requiring explic=
it user consent. 2026-05-16 5.3 CVE-2020-37241 [
https://www.cve.org/CVERec= ord?id=3DCVE-2020-37241 ] ExploitDB-49507 [
https://www.exploit-db.com/expl= oits/49507 ]
Official Product Homepage [
https://www.bloofox.com/ ]
Product Reference [
https://github.com/alexlang24/bloofoxCMS/releases/tag/0= .5.2.1 ]
VulnCheck Advisory: bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user = add [
https://www.vulncheck.com/advisories/bloofoxcms-cross-site-request-fo= rgery-via-user-add ]
=C2=A0 MyBB--MyBB Timeline Plugin MyBB Timeline Plugin 1.0 contains cross-s= ite scripting vulnerabilities that allow attackers to inject malicious scri= pts through thread titles, post content, and user profile fields like Locat= ion and Bio. Attackers can also exploit a cross-site request forgery vulner= ability in the timeline.php profile action to change a user's cover picture=
by crafting malicious forms that execute when victims visit affected profi= les. 2026-05-16 5.3 CVE-2021-47934 [
https://www.cve.org/CVERecord?id=3DCVE= -2021-47934 ] ExploitDB-49467 [
https://www.exploit-db.com/exploits/49467 ] Product Reference [
https://community.mybb.com/mods.php?action=3Dview&pid= =3D1428 ]
VulnCheck Advisory: MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF =
[
https://www.vulncheck.com/advisories/mybb-timeline-plugin-cross-site-scri= pting-and-csrf ]
=C2=A0 CouchCMS--CouchCMS CouchCMS 2.2.1 contains a cross-site scripting vu= lnerability that allows authenticated attackers to execute arbitrary JavaSc= ript by uploading malicious SVG files through the file upload functionality=
. Attackers can upload SVG files containing embedded script tags to the bro= wse.php endpoint, which are then executed in users' browsers when the files=
are accessed or previewed. 2026-05-16 5.4 CVE-2021-47955 [
https://www.cve= .org/CVERecord?id=3DCVE-2021-47955 ] ExploitDB-49636 [
https://www.exploit-= db.com/exploits/49636 ]
Official Product Homepage [
https://github.com/CouchCMS/CouchCMS ]
VulnCheck Advisory: CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload=
[
https://www.vulncheck.com/advisories/couchcms-cross-site-scripting-via-s= vg-file-upload ]
=C2=A0 Opensolution--Quick.CMS Quick.CMS 6.7 contains a cross-site scriptin=
g vulnerability in the sliders form that allows authenticated attackers to = inject malicious scripts by submitting XSS payloads through the sDescriptio=
n parameter. Attackers can craft CSRF forms targeting the admin.php?p=3Dsli= ders-form endpoint to execute arbitrary JavaScript in victim browsers when = the form is submitted. 2026-05-16 5.4 CVE-2021-47981 [
https://www.cve.org/= CVERecord?id=3DCVE-2021-47981 ] ExploitDB-50530 [
https://www.exploit-db.co= m/exploits/50530 ]
Official Product Homepage [
https://opensolution.org/ ]
Product Reference [
https://opensolution.org/download/home.html?sFile=3DQui= ck.Cms_v6.7-en.zip ]
VulnCheck Advisory: Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders = Form [
https://www.vulncheck.com/advisories/quick-cms-cross-site-scripting-= via-csrf-to-sliders-form ]
=C2=A0 WSO2--WSO2 Identity Server The check user account lock states featur=
e within the email OTP flow fails to validate user input, allowing an attac= ker to infer the existence of registered user accounts. The discovery of va= lid usernames can increase the risk of brute-force and social engineering a= ttacks. Attackers can leverage this information to craft targeted phishing = campaigns or other malicious activities aimed at tricking users into divulg= ing sensitive data, potentially damaging the organization's reputation and = leading to regulatory non-compliance and financial consequences. 2026-05-11=
5.3 CVE-2024-0391 [
https://www.cve.org/CVERecord?id=3DCVE-2024-0391 ] htt= ps://security.docs.wso2.com/en/latest/security-announcements/security-advis= ories/2026/WSO2-2024-3115/
=C2=A0 Siemens--SIPROTEC 5 6MD84 (CP300) A vulnerability has been identifie=
d in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP2= 00) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >=3D V7.80 < V11= .0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All=
versions >=3D V7.80 < V11.0), SIPROTEC 5 6MD89 (CP300) (All versions >=3D = V7.80 < V11.0), SIPROTEC 5 6MU85 (CP300) (All versions >=3D V7.80 < V11.0),=
SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All ver= sions >=3D V7.80 < V11.0), SIPROTEC 5 7SA82 (CP100) (All versions >=3D V7.8= 0), SIPROTEC 5 7SA82 (CP150) (All versions < V11.0), SIPROTEC 5 7SA84 (CP20=
0) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA8=
6 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SA87 (CP200) (All = versions), SIPROTEC 5 7SA87 (CP300) (All versions >=3D V7.80 < V11.0), SIPR= OTEC 5 7SD82 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SD82 (CP150) (A=
ll versions < V11.0), SIPROTEC 5 7SD84 (CP200) (All versions), SIPROTEC 5 7= SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions >=3D V7= .80 < V11.0), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP= 300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SJ81 (CP100) (All versi= ons >=3D V7.80), SIPROTEC 5 7SJ81 (CP150) (All versions < V11.0), SIPROTEC =
5 7SJ82 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SJ82 (CP150) (All ve= rsions < V11.0), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 = (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SJ86 (CP200) (All ve= rsions), SIPROTEC 5 7SJ86 (CP300) (All versions >=3D V7.80 < V11.0), SIPROT=
EC 5 7SK82 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SK82 (CP150) (All=
versions < V11.0), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK=
85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SL82 (CP100) (All=
versions >=3D V7.80), SIPROTEC 5 7SL82 (CP150) (All versions < V11.0), SIP= ROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All version=
s >=3D V7.80 < V11.0), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 = 7SL87 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SS85 (CP200) (= All versions), SIPROTEC 5 7SS85 (CP300) (All versions >=3D V7.80 < V11.0), = SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All vers= ions >=3D V7.80 < V11.0), SIPROTEC 5 7ST86 (CP300) (All versions < V11.0), = SIPROTEC 5 7SX82 (CP150) (All versions < V11.0), SIPROTEC 5 7SX85 (CP300) (= All versions < V11.0), SIPROTEC 5 7SY82 (CP150) (All versions < V11.0), SIP= ROTEC 5 7UM85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT82 (= CP100) (All versions >=3D V7.80), SIPROTEC 5 7UT82 (CP150) (All versions < = V11.0), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (= All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT86 (CP200) (All versions), = SIPROTEC 5 7UT86 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT8=
7 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions >=3D V7.80=
< V11.0), SIPROTEC 5 7VE85 (CP300) (All versions >=3D V7.80 < V11.0), SIPR= OTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions=
=3D V7.80 < V11.0), SIPROTEC 5 7VU85 (CP300) (All versions < V11.0), SIPR= OTEC 5 Compact 7SX800 (CP050) (All versions < V11.0). Affected devices do n=
ot use sufficiently random values to create session identifiers. This could=
allow an unauthenticated remote attacker to brute force a session identifi=
er and gain read access to limited information from the web server without = authorization. 2026-05-12 5.3 CVE-2024-54017 [
https://www.cve.org/CVERecor= d?id=3DCVE-2024-54017 ]
https://cert-portal.siemens.com/productcert/html/ss= a-786884.html
=C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 = before 18.11.3 that could have allowed an authenticated user to inject HTML=
and JavaScript into email notifications sent to other users due to imprope=
r input sanitization. 2026-05-14 5.4 CVE-2025-12669 [
https://www.cve.org/C= VERecord?id=3DCVE-2025-12669 ] HackerOne Bug Bounty Report #3368096 [ https= ://hackerone.com/reports/3368096 ]
https://gitlab.com/gitlab-org/gitlab/-/work_items/579385 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
=C2=A0 ghera74--ilGhera Support System for WooCommerce The ilGhera Support = System for WooCommerce plugin for WordPress is vulnerable to unauthorized a= ccess of data due to a missing capability check on the 'get_ticket_content_= callback' function in all versions up to, and including, 1.3.0. This makes =
it possible for unauthenticated attackers to view any support ticket conten=
t, including sensitive customer information and private communications, by = providing a ticket ID. 2026-05-13 5.3 CVE-2025-14033 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-14033 ]
https://www.wordfence.com/threat-intel/vuln= erabilities/id/40ceea17-ec60-4775-8495-e2f7643d1b7c?source=3Dcve
https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes= /class-wc-support-system.php#L68
https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/inc= ludes/class-wc-support-system.php#L68
https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes= /class-wc-support-system.php#L643
https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/inc= ludes/class-wc-support-system.php#L643
https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.3.1/inc= ludes/class-wc-support-system.php#L780
=C2=A0 stylemix--Cost Calculator Builder The Cost Calculator Builder plugin=
for WordPress is vulnerable to Unauthenticated Price Manipulation and Inse= cure Direct Object Reference (IDOR) in all versions up to, and including, 4= .0.1 only when used in combination with Cost Calculator Builder PRO. This i=
s due to the ccb_woocommerce_payment AJAX action being registered via wp_aj= ax_nopriv, making it accessible to unauthenticated users, and the renderWoo= CommercePayment() function passing user-controlled data directly to CCBWooC= heckout::init() without authorization checks. This makes it possible for un= authenticated attackers to add WooCommerce products to their cart with atta= cker-controlled prices. 2026-05-13 5.3 CVE-2025-14755 [
https://www.cve.org= /CVERecord?id=3DCVE-2025-14755 ]
https://www.wordfence.com/threat-intel/vul= nerabilities/id/fe684f43-8442-4b29-84a8-da8c6863e62b?source=3Dcve
https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6= .7/includes/classes/CCBOrderController.php#L484
https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6= .7/includes/classes/CCBAjaxAction.php#L99
=C2=A0 wpclever--WPC Badge Management for WooCommerce The WPC Badge Managem= ent for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site=
Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in=
all versions up to, and including, 3.1.6 due to insufficient input sanitiz= ation and output escaping. This makes it possible for authenticated attacke= rs, with Shop Manager-level access and above, to inject arbitrary web scrip=
ts in pages that will execute whenever a user accesses an injected page. 20= 26-05-13 5.5 CVE-2025-14767 [
https://www.cve.org/CVERecord?id=3DCVE-2025-1= 4767 ]
https://www.wordfence.com/threat-intel/vulnerabilities/id/bf02edc9-2= bb6-4ceb-b2a1-63f95c8becb3?source=3Dcve
https://wordpress.org/plugins/wpc-badge-management https://plugins.trac.wordpress.org/browser/wpc-badge-management/trunk/inclu= des/class-shortcode.php#L98
https://plugins.trac.wordpress.org/changeset/3519100/
=C2=A0 Tp-link--TL-WR720NMbps Wireless N Router TP-Link TL-WR720N wireless = router contains a cross-site request forgery vulnerability that allows atta= ckers to perform unauthorized administrative actions by crafting malicious = web requests. Attackers can modify port forwarding rules via VirtualServerR= pm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking=
authenticated users into visiting attacker-controlled pages. 2026-05-17 4.=
3 CVE-2018-25321 [
https://www.cve.org/CVERecord?id=3DCVE-2018-25321 ] Expl= oitDB-44335 [
https://www.exploit-db.com/exploits/44335 ]
Official Product Homepage [
https://www.tp-link.com/ ]
Product Reference [
https://static.tp-link.com/resources/software/TL-WR720N= _V1_130719.zip ]
VulnCheck Advisory: TP-Link TL-WR720N All Versions CSRF via Administrative = Interfaces [
https://www.vulncheck.com/advisories/tp-link-tl-wr720n-all-ver= sions-csrf-via-administrative-interfaces ]
=C2=A0 Joomlaextensions--Joomla! extension JoomOCShop Joomla JoomOCShop 1.0=
contains a cross-site request forgery vulnerability that allows attackers =
to perform unauthorized actions on behalf of authenticated users. Attackers=
can craft malicious HTML forms targeting account endpoints like /joomoc2/?= route=3Daccount/edit and to modify user information or reset passwords with= out user consent. 2026-05-17 4.3 CVE-2018-25337 [
https://www.cve.org/CVERe= cord?id=3DCVE-2018-25337 ] ExploitDB-44789 [
https://www.exploit-db.com/exp= loits/44789 ]
Official Product Homepage [
https://www.joomlaextensions.co.in/ ]
Product Reference [
https://extensions.joomla.org/extensions/extension/e-co= mmerce/e-commerce-integrations/joomocshop/ ]
VulnCheck Advisory: Joomla JoomOCShop 1.0 Cross-Site Request Forgery [ http= s://www.vulncheck.com/advisories/joomla-joomocshop-cross-site-request-forge=
ry ]
=C2=A0 Easy2pilot-v7--Easy2Pilot Easy2Pilot 7 contains a cross-site request=
forgery vulnerability that allows attackers to add unauthorized user accou= nts by tricking authenticated administrators into visiting malicious pages.=
Attackers can craft HTML forms targeting the admin.php?action=3Dadd_user e= ndpoint with POST requests containing username and password parameters to c= reate new administrative accounts without explicit user consent. 2026-05-13=
4.3 CVE-2020-37217 [
https://www.cve.org/CVERecord?id=3DCVE-2020-37217 ] E= xploitDB-48099 [
https://www.exploit-db.com/exploits/48099 ]
Official Product Homepage [
http://easy2pilot-v7.com/ ]
VulnCheck Advisory: Easy2Pilot 7 Cross-Site Request Forgery via admin.php [=
https://www.vulncheck.com/advisories/easy2pilot-7-cross-site-request-forge= ry-via-admin-php ]
=C2=A0 CouchCMS--CouchCMS CouchCMS 2.2.1 contains a server-side request for= gery vulnerability that allows authenticated attackers to make arbitrary HT=
TP requests by uploading malicious SVG files. Attackers can upload SVG file=
s containing external entity references through the browse.php endpoint to = access internal services and resources. 2026-05-15 4.3 CVE-2021-47958 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2021-47958 ] ExploitDB-49675 [
https://= www.exploit-db.com/exploits/49675 ]
Official Product Homepage [
https://github.com/CouchCMS/CouchCMS ]
VulnCheck Advisory: CouchCMS 2.2.1 Server-Side Request Forgery via SVG uplo=
ad [
https://www.vulncheck.com/advisories/couchcms-server-side-request-forg= ery-via-svg-upload ]
=C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 b= efore 18.11.3 that could have allowed an authenticated user with Guest perm= issions to view issues in projects they were not authorized to access. 2026= -05-14 4.3 CVE-2025-13874 [
https://www.cve.org/CVERecord?id=3DCVE-2025-138=
74 ] HackerOne Bug Bounty Report #3445398 [
https://hackerone.com/reports/3= 445398 ]
https://gitlab.com/gitlab-org/gitlab/-/work_items/582634 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
=C2=A0=20
Back to top [ #top ]
Low Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info Patch Info T= here were no low vulnerabilities recorded this week.=20
Back to top [ #top ]
Severity Not Yet Assigned
Primary
Vendor -- Product Description Published CVSS Score Source Info Patch Info A= MD--AMD Ryzen 5000 Series Desktop Processors with Radeon Graphics A comprom= ised Trusted OS (TOS) driver could issue a malformed call that could potent= ially allow memory access outside the intended range resulting in loss of i= ntegrity. 2026-05-15 not yet calculated CVE-2021-26380 [
https://www.cve.or= g/CVERecord?id=3DCVE-2021-26380 ]
https://www.amd.com/en/resources/product-= security/bulletin/AMD-SB-4017.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 AMD--AMD Ryzen 3000 Series Mobile Processors with Radeon Graphics A = TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow a=
n attacker to load registers repeatedly creating a race condition potential=
ly leading to a loss of integrity. 2026-05-15 not yet calculated CVE-2022-2= 3826 [
https://www.cve.org/CVERecord?id=3DCVE-2022-23826 ]
https://www.amd.= com/en/resources/product-security/bulletin/AMD-SB-4017.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 KMX--Alien::FreeImage Alien::FreeImage versions through 1.001 for Pe=
rl contains several vulnerable libraries. Alien::FreeImage contains version=
3.17.0 of the FreeImage library from 2017, which has known vulnerabilities=
such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images = libraries that also have known vulnerabilities. 2026-05-11 not yet calculat=
ed CVE-2022-4988 [
https://www.cve.org/CVERecord?id=3DCVE-2022-4988 ] https= ://freeimage.sourceforge.io/
https://metacpan.org/release/KMX/Alien-FreeImage-1.001/source/src/Source https://nvd.nist.gov/vuln/detail/CVE-2015-0852 https://nvd.nist.gov/vuln/detail/CVE-2025-65803 https://github.com/kmx/alien-freeimage/issues/4 https://github.com/kmx/alien-freeimage/issues/5
=C2=A0 n/a--MK-Auth 23.01K4.9 An arbitrary file upload vulnerability in MK-= Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c= rafted PHP file. 2026-05-12 not yet calculated CVE-2023-27753 [
https://www= .cve.org/CVERecord?id=3DCVE-2023-27753 ]
https://github.com/yueslly/MKAUTH-= RCE/blob/main/README.md
https://github.com/yueslly/MKAUTH-RCE
=C2=A0 n/a--MK-Auth 23.01K4.9 An insecure direct object reference in MK-Aut=
h 23.01K4.9 allows attackers to access and send support calls for other use=
rs via manipulation of the chamado parameter through a crafted GET request.=
2026-05-12 not yet calculated CVE-2023-30059 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2023-30059 ]
https://github.com/yueslly/MKAUTH-IDOR
=C2=A0 AMD[.]com--AMD Radeon RX 6000 Series Graphics Products Improper vali= dation in Power Management Firmware (PMFW) may allow an attacker with privi= leges to pass malformed workload arguments when exporting table data from S=
MU to DRAM potentially resulting in a loss of confidentiality and/or availa= bility. 2026-05-15 not yet calculated CVE-2023-31309 [
https://www.cve.org/= CVERecord?id=3DCVE-2023-31309 ]
https://www.amd.com/en/resources/product-se= curity/bulletin/AMD-SB-6027.html
=C2=A0 AMD[.]com--AMD Ryzen 5000 Series Mobile Processors with Radeon Graph= ics Improperly preserved integrity of hardware configuration state during a=
power save/restore operation in the AMD Secure Processor (ASP) could allow=
an attacker with the ability to write outside the trusted memory range (TM=
R) to change the execution flow of the Video Core Next (VCN) firmware poten= tially impacting confidentiality, integrity, or availability. 2026-05-15 no=
t yet calculated CVE-2023-31316 [
https://www.cve.org/CVERecord?id=3DCVE-20= 23-31316 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 AMD[.]com--AMD Radeon RX 6000 Series Graphics Products Improper rest= riction of operations within the bounds of a memory buffer in the AMD secur=
e processer (ASP) could allow an attacker to read or write to protected mem= ory potentially resulting in arbitrary code execution. 2026-05-15 not yet c= alculated CVE-2023-31317 [
https://www.cve.org/CVERecord?id=3DCVE-2023-3131=
7 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.= html
=C2=A0 AMD[.]com--AMD Instinct MI300X An out of bounds read in the remote m= anagement firmware could allow a privileged attacker read a limited section=
of memory outside of established bounds potentially resulting in loss of c= onfidentiality or availability. 2026-05-15 not yet calculated CVE-2024-2195=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2024-21950 ]
https://www.amd.com= /en/resources/product-security/bulletin/AMD-SB-6027.html
=C2=A0 AMD[.]com--AMD EPYC 4005 Series Processors Improper Input Validation=
in the AMD RAID driver could allow an attacker to point to an arbitrary me= mory location potentially resulting in privilege escalation and arbitrary c= ode execution. 2026-05-15 not yet calculated CVE-2024-21962 [
https://www.c= ve.org/CVERecord?id=3DCVE-2024-21962 ]
https://www.amd.com/en/resources/pro= duct-security/bulletin/AMD-SB-4016.html
=C2=A0 AMD[.]com--AMD EPYC Series 9004 Processors Improper enforcement of t=
he LFENCE serialization property may allow an attacker to bypass speculatio=
n barriers and potentially disclose sensitive information, potentially resu= lting in loss of confidentiality. 2026-05-13 not yet calculated CVE-2024-36= 315 [
https://www.cve.org/CVERecord?id=3DCVE-2024-36315 ]
https://www.amd.c= om/en/resources/product-security/bulletin/AMD-SB-3030.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html =C2=A0 AMD[.]com--AMD Radeon RX 7000 Series Graphics Products Improper isol= ation of VCN-JPEG HW register space could allow a malicious Guest Virtual M= achine (VM) or a process to perform unauthorized access to the register spa=
ce of the JPEG cores assigned a victim VM/process, potentially gaining arbi= trary read/write access to the victim VM/process data. 2026-05-15 not yet c= alculated CVE-2024-36323 [
https://www.cve.org/CVERecord?id=3DCVE-2024-3632=
3 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.= html
=C2=A0 AMD[.]com--AMD Radeon PRO V710 Improper isolation of GPU HW register=
space could allow a privileged attacker in malicious Guest Virtual Machine=
(VM) to perform unauthorized access to specific victim range of GPU MMIO r= egister space, potentially causing the host OS to reboot and creating a Den= ial of Service (DOS) condition. 2026-05-15 not yet calculated CVE-2024-3633=
2 [
https://www.cve.org/CVERecord?id=3DCVE-2024-36332 ]
https://www.amd.com= /en/resources/product-security/bulletin/AMD-SB-6027.html
=C2=A0 AMD[.]com--AMD Radeon RX 5000 Series Graphics Products A DLL hijacki=
ng vulnerability in the AMD Cleanup Utility could allow an attacker to achi= eve privilege escalation potentially resulting in arbitrary code execution.=
2026-05-15 not yet calculated CVE-2024-36333 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2024-36333 ]
https://www.amd.com/en/resources/product-security/= bulletin/AMD-SB-6027.html
=C2=A0 AMD[.]com--AMD Radeon RX 7000 Series Graphics Products Improper veri= fication of cryptographic signature in the Radeon RGB tool could allow a ma= licious file placed in the installation directory to be run with elevated p= rivileges potentially leading to arbitrary code execution. 2026-05-15 not y=
et calculated CVE-2024-36334 [
https://www.cve.org/CVERecord?id=3DCVE-2024-= 36334 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6= 027.html
=C2=A0 AMD[.]com--AMD EPYC 4004 Improper input validation in the AMD OverDr= ive (AOD) System Management Mode (SMM) module could allow a privileged atta= cker to perform an out-of-bounds read, potentially resulting in loss of con= fidentiality. 2026-05-15 not yet calculated CVE-2024-36345 [
https://www.cv= e.org/CVERecord?id=3DCVE-2024-36345 ]
https://www.amd.com/en/resources/prod= uct-security/bulletin/AMD-SB-3030.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html =C2=A0 Checkmk GmbH--Checkmk Privilege escalation in the mk_mysql agent plu= gin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a lo= cal unprivileged user able to create a Windows service whose name matches '= MySQL' or 'MariaDB' (or with write access to a binary referenced by such a = service) to execute arbitrary code in the context of the Checkmk agent serv= ice, which typically runs as SYSTEM. 2026-05-13 not yet calculated CVE-2024= -47091 [
https://www.cve.org/CVERecord?id=3DCVE-2024-47091 ]
https://checkm= k.com/werk/19198
=C2=A0 n/a--Ardupilot Buffer Overflow vulnerability in Ardupilot rover comm=
it v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to ca= use a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover,=
ADIS1647x Sensor component. 2026-05-13 not yet calculated CVE-2024-48519 [=
https://www.cve.org/CVERecord?id=3DCVE-2024-48519 ]
https://github.com/Ard= uPilot/ardupilot/issues/27937
=C2=A0 n/a--Ardupilot Buffer Overflow vulnerability in Ardupiot Copter Late=
st commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker =
to cause a denial of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp compo= nents. 2026-05-13 not yet calculated CVE-2024-51394 [
https://www.cve.org/C= VERecord?id=3DCVE-2024-51394 ]
https://github.com/ArduPilot/ardupilot/issue= s/28458
=C2=A0 n/a--Ardupilot Buffer Overflow vulnerability in Ardupiot Copter Late=
st commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker =
to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio, AP= _SmartAudio.cpp components. 2026-05-13 not yet calculated CVE-2024-51395 [ =
https://www.cve.org/CVERecord?id=3DCVE-2024-51395 ]
https://github.com/Ardu= Pilot/ardupilot/issues/28374
=C2=A0 n/a--FMT-Firmware Firmament-Autopilot FMT-Firmware commit de5aec was=
discovered to contain a buffer overflow via the task_mavobc_entry function=
at /comm/task_comm.c. 2026-05-13 not yet calculated CVE-2024-55045 [ https= ://www.cve.org/CVERecord?id=3DCVE-2024-55045 ]
https://github.com/Firmament= -Autopilot/FMT-Firmware/issues/133
=C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An unchecked return value within the AMD Pl= atform Management Framework (PMF) could allow an attacker to read or modify=
an arbitrary address potentially resulting in loss of confidentiality, int= egrity, or availability. 2026-05-15 not yet calculated CVE-2025-0028 [ http= s://www.cve.org/CVERecord?id=3DCVE-2025-0028 ]
https://www.amd.com/en/resou= rces/product-security/bulletin/AMD-SB-4015.html
=C2=A0 AMD[.]com--AMD Ryzen 7040 Series Mobile Processors with Radeon Graph= ics Improper access control between the Joint Test Action Group (JTAG) and = Advanced Extensible Interface (AXI) could allow an attacker with physical a= ccess to read or overwrite the contents of cross-chip debug (XCD) registers=
potentially resulting in loss of data integrity or confidentiality. 2026-0= 5-15 not yet calculated CVE-2025-0040 [
https://www.cve.org/CVERecord?id=3D= CVE-2025-0040 ]
https://www.amd.com/en/resources/product-security/bulletin/= AMD-SB-4017.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 AMD[.]com--AMD Ryzen Al Max+ An out-of-bounds read in power manageme=
nt firmware by a malicious local attacker with low privileges could potenti= ally lead to a partial loss of confidentiality and availability. 2026-05-15=
not yet calculated CVE-2025-0044 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-0044 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-= SB-6027.html
=C2=A0 AMD[.]com--Athlon 3000 Series Mobile Processors with Radeon Graphics=
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may=
allow a local attacker to create a buffer overflow condition, potentially = resulting in a crash or denial of service 2026-05-15 not yet calculated CVE= -2025-0045 [
https://www.cve.org/CVERecord?id=3DCVE-2025-0045 ]
https://www= .amd.com/en/resources/product-security/bulletin/AMD-SB-4015.html
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3047.html =C2=A0 WSO2--WSO2 Identity Server Due to a lack of user account state valid= ation during authentication, locked user accounts can be successfully authe= nticated using Magic Link or Pass Key methods. This bypasses the intended s= ecurity control that should prevent access to accounts that have been locke=
d. This vulnerability may allow unauthorized access to applications and sen= sitive data associated with accounts that should have been restricted via t=
he account lock mechanism. It also undermines the effectiveness of the acco= unt lock mechanism intended to prevent further login attempts. 2026-05-11 n=
ot yet calculated CVE-2025-10908 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-10908 ]
https://security.docs.wso2.com/en/latest/security-announcements= /security-advisories/2026/WSO2-2025-4388/
=C2=A0 Siemens--Simcenter Femap The affected applications contains a memory=
corruption vulnerability while parsing specially crafted IPT files. This c= ould allow an attacker to execute code in the context of the current proces=
s. (ZDI-CAN-27349, ZDI-CAN-27389) 2026-05-12 not yet calculated CVE-2025-12= 659 [
https://www.cve.org/CVERecord?id=3DCVE-2025-12659 ]
https://cert-port= al.siemens.com/productcert/html/ssa-870926.html
=C2=A0 silabs.com--Simplicity SDK * Countermeasures for DPA within SYMCRYPT=
O engine on SixG301xxx devices are not sufficiently random and will eventua= lly repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerabili= ty. 2026-05-15 not yet calculated CVE-2025-14972 [
https://www.cve.org/CVER= ecord?id=3DCVE-2025-14972 ]
https://community.silabs.com/068Vm00000M3cAX
=C2=A0 n/a--Intel(R) Ethernet 800 series Use after free for some Linux kern=
el driver for the Intel(R) Ethernet 800 series before version 2.3.14 within=
Ring 0: Kernel may allow a denial of service. Unprivileged software advers= ary with an authenticated user combined with a low complexity attack may en= able denial of service. This result may potentially occur via local access = when attack requirements are present without special internal knowledge and=
requires no user interaction. The potential vulnerability may impact the c= onfidentiality (none), integrity (none) and availability (high) of the vuln= erable system, resulting in subsequent system confidentiality (none), integ= rity (none) and availability (high) impacts. 2026-05-12 not yet calculated = CVE-2025-27723 [
https://www.cve.org/CVERecord?id=3DCVE-2025-27723 ] https:= //intel.com/content/www/us/en/security-center/advisory/intel-sa-01426.html =C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
DU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics p= ackage containing symlinks is uploaded, the web server follows the supplied=
links when serving content. No mechanisms to restrict those link targets t=
o a specific area of the filesystem is enabled. This allows an attacker to = retrieve arbitrary files from the device. 2026-05-13 not yet calculated CVE= -2025-27850 [
https://www.cve.org/CVERecord?id=3DCVE-2025-27850 ]
https://g= armin.com
https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
=C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
DU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking att= ack. Among other uses, the WDU utilizes WebSockets to control settings, inc= luding administrative settings. This allows a network attacker to take full=
control of a WDU. To initiate an exploit of this vulnerability, the victim=
must (1) be utilizing a web browser on a multihomed host that has local in= terfaces on the Garmin Marine Network as well as another network, and (2) a= ccess a malicious third party website created by the attacker. 2026-05-13 n=
ot yet calculated CVE-2025-27851 [
https://www.cve.org/CVERecord?id=3DCVE-2= 025-27851 ]
https://garmin.com https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
=C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
DU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) atta= ck. This allows an attacker on the local network segment to execute arbitra=
ry JavaScript code within the context of the WDU webpage. Full administrato=
r level access to the device is possible. To initiate an exploit of this vu= lnerability, the victim must execute two actions: (1) view a specific URL s= erved by the WDU, and (2) click an element on the rendered page. 2026-05-13=
not yet calculated CVE-2025-27852 [
https://www.cve.org/CVERecord?id=3DCVE= -2025-27852 ]
https://garmin.com https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
=C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
DU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU = web site only performs authentication with the client within the client's b= rowser. The WebSockets used to communicate with the WDU server do not enfor=
ce any authentication. An attacker may bypass all authentication mechanisms=
by directly utilizing the remote APIs available on the websocket. 2026-05-=
13 not yet calculated CVE-2025-27853 [
https://www.cve.org/CVERecord?id=3DC= VE-2025-27853 ]
https://garmin.com https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
=C2=A0 ThreadReadButtons--ThreadReadButtons striso-control-firmware 54c9722=
is vulnerable to Buffer Overflow in function ThreadReadButtons. 2026-05-13=
not yet calculated CVE-2025-28343 [
https://www.cve.org/CVERecord?id=3DCVE= -2025-28343 ]
https://github.com/striso/striso-control-firmware/issues/5
=C2=A0 AuxJack--AuxJack striso-control-firmware 54c9722 is vulnerable to Bu= ffer Overflow in function AuxJack. 2026-05-13 not yet calculated CVE-2025-2= 8344 [
https://www.cve.org/CVERecord?id=3DCVE-2025-28344 ]
https://github.c= om/striso/striso-control-firmware/issues/6
=C2=A0 NXP[.]com--NXP NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17= .92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overf= low via the mod_para parameter in the woal_init_module_param function. 2026= -05-13 not yet calculated CVE-2025-29338 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-29338 ]
https://www.nxp.com/docs/en/release-note/RN00104.pdf https://github.com/masjadaan/CVE-2025-29338
=C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An out of bounds write within the AMD Platf= orm Management Framework (PMF) could allow an attacker to execute arbitrary=
code at an elevated privilege level potentially leading to loss of confide= ntiality integrity, or availability. 2026-05-15 not yet calculated CVE-2025= -29935 [
https://www.cve.org/CVERecord?id=3DCVE-2025-29935 ]
https://www.am= d.com/en/resources/product-security/bulletin/AMD-SB-4015.html
=C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") Improper input validation within the AMD Pl= atform Management Framework (PMF) could allow an attacker to unmap arbitrar=
y memory pages potentially impacting integrity and availability, or allowin=
g privilege escalation resulting in loss of confidentiality. 2026-05-15 not=
yet calculated CVE-2025-29936 [
https://www.cve.org/CVERecord?id=3DCVE-202= 5-29936 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB= -4015.html
=C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An out of bounds read within the AMD Platfo=
rm Management Framework (PMF) could allow an attacker to trigger a read of =
an arbitrary memory location potentially resulting in loss of availability =
or confidentiality. 2026-05-15 not yet calculated CVE-2025-29937 [
https://= www.cve.org/CVERecord?id=3DCVE-2025-29937 ]
https://www.amd.com/en/resource= s/product-security/bulletin/AMD-SB-4015.html
=C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An unchecked return value within the AMD Pl= atform Management Framework (PMF) could allow an attacker to write to an ar= bitrary memory address resulting in denial of service or arbitrary code exe= cution. 2026-05-15 not yet calculated CVE-2025-29938 [
https://www.cve.org/= CVERecord?id=3DCVE-2025-29938 ]
https://www.amd.com/en/resources/product-se= curity/bulletin/AMD-SB-4015.html
=C2=A0 AMD[.]com--AMD Ryzen 4000 Series Mobile Processors with Radeon Graph= ics (formerly codenamed "Renoir") A buffer overflow vulnerability within AM=
D Sensor Fusion Hub Driver can allow a local attacker to write out of bound=
s, potentially resulting in denial of service or crash 2026-05-15 not yet c= alculated CVE-2025-29944 [
https://www.cve.org/CVERecord?id=3DCVE-2025-2994=
4 ]
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4015.= html
=C2=A0 Significant-Gravitas--AutoGPT AutoGPT is a platform that allows user=
s to create, deploy, and manage continuous artificial intelligence agents t= hat automate complex workflows. In AutoGPT, the execution process is record=
ed to the console (stdout/stderr), and deployed in container mode, which is=
automatically captured by Docker and stored as "container logs". However, = prior to 0.6.32, there is no limit on the log size when the container is de= ployed. When the number of user accesses is too large, the log on the serve=
r disk will be too large, causing disk resource exhaustion and eventually c= ausing DoS. autogpt-platform-beta-v0.6.32 fixes the issue. 2026-05-13 not y=
et calculated CVE-2025-32425 [
https://www.cve.org/CVERecord?id=3DCVE-2025-= 32425 ]
https://github.com/Significant-Gravitas/AutoGPT/security/advisories= /GHSA-vw3v-whvp-33v5
https://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be1873= 8c6ae8bb41085c71e266
https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b31245495= 43b45d933d16f622d2/autogpt_platform/autogpt_libs/autogpt_libs/logging/confi= g.py#L83-L102
https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b31245495= 43b45d933d16f622d2/autogpt_platform/docker-compose.platform.yml#L102-L142 =C2=A0 Intel[.]com--Intel(R) Server Firmware Update Utility Software Uncont= rolled search path for some Intel(R) Server Firmware Update Utility Softwar=
e before version 16.0.12. within Ring 3: User Applications may allow an esc= alation of privilege. System software adversary with an authenticated user = combined with a high complexity attack may enable escalation of privilege. = This result may potentially occur via local access when attack requirements=
are present without special internal knowledge and requires active user in= teraction. The potential vulnerability may impact the confidentiality (high=
), integrity (high) and availability (high) of the vulnerable system, resul= ting in subsequent system confidentiality (none), integrity (none) and avai= lability (none) impacts. 2026-05-12 not yet calculated CVE-2025-35969 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2025-35969 ]
https://intel.com/content/= www/us/en/security-center/advisory/intel-sa-01410.html
=C2=A0 Intel[.]com--Intel(R) Processors Exposure of sensitive information c= aused by shared microarchitectural predictor state that influences transien=
t execution for some Intel(R) Processors within VMX non-root (guest) operat= ion may allow an information disclosure. Unprivileged software adversary wi=
th an authenticated user combined with a high complexity attack may enable = data exposure. This result may potentially occur via local access when atta=
ck requirements are present without special internal knowledge and requires=
no user interaction. The potential vulnerability may impact the confidenti= ality (high), integrity (none) and availability (none) of the vulnerable sy= stem, resulting in subsequent system confidentiality (high), integrity (non=
e) and availability (none) impacts. 2026-05-12 not yet calculated CVE-2025-= 35979 [
https://www.cve.org/CVERecord?id=3DCVE-2025-35979 ]
https://intel.c= om/content/www/us/en/security-center/advisory/intel-sa-01420.html
=C2=A0 Intel[.]com--Intel Endpoint Management Assistant (EMA) software Impr= oper input validation for some Intel Endpoint Management Assistant (EMA) so= ftware before version 1.14.5 within Ring 3: User Applications may allow an = escalation of privilege. Unprivileged software adversary with an unauthenti= cated user combined with a low complexity attack may enable escalation of p= rivilege. This result may potentially occur via adjacent access when attack=
requirements are not present without special internal knowledge and requir=
es no user interaction. The potential vulnerability may impact the confiden= tiality (high), integrity (high) and availability (high) of the vulnerable = system, resulting in subsequent system confidentiality (none), integrity (n= one) and availability (none) impacts. 2026-05-12 not yet calculated CVE-202= 5-35990 [
https://www.cve.org/CVERecord?id=3DCVE-2025-35990 ]
https://intel= .com/content/www/us/en/security-center/advisory/intel-sa-01434.html
=C2=A0 Intel[.]com--Intel platforms Improper initialization in the UEFI fir= mware for some Intel platforms within Ring 0: Bare Metal OS may allow an in= formation disclosure. System software adversary with a privileged user comb= ined with a high complexity attack may enable data exposure. This result ma=
y potentially occur via local access when attack requirements are present w= ithout special internal knowledge and requires no user interaction. The pot= ential vulnerability may impact the confidentiality (high), integrity (none=
) and availability (none) of the vulnerable system, resulting in subsequent=
system confidentiality (none), integrity (none) and availability (none) im= pacts. 2026-05-12 not yet calculated CVE-2025-35991 [
https://www.cve.org/C= VERecord?id=3DCVE-2025-35991 ]
https://intel.com/content/www/us/en/security= -center/advisory/intel-sa-01413.html
=C2=A0 Intel[.]com--Display Virtualization for Windows OS driver software I= mproper buffer restrictions for some Display Virtualization for Windows OS = driver software within Ring 2: Device Drivers may allow a denial of service=
. Unprivileged software adversary with an authenticated user combined with =
a low complexity attack may enable denial of service. This result may poten= tially occur via local access when attack requirements are not present with= out special internal knowledge and requires no user interaction. The potent= ial vulnerability may impact the confidentiality (none), integrity (none) a=
nd availability (high) of the vulnerable system, resulting in subsequent sy= stem confidentiality (none), integrity (none) and availability (none) impac= ts. 2026-05-12 not yet calculated CVE-2025-36510 [
https://www.cve.org/CVER= ecord?id=3DCVE-2025-36510 ]
https://intel.com/content/www/us/en/security-ce= nter/advisory/intel-sa-01430.html
=C2=A0 Intel[.]com--AI Playground software Uncontrolled search path for som=
e AI Playground software before version 3.0.0 alpha within Ring 3: User App= lications may allow an escalation of privilege. Unprivileged software adver= sary with an authenticated user combined with a high complexity attack may = enable escalation of privilege. This result may potentially occur via local=
access when attack requirements are present without special internal knowl= edge and requires active user interaction. The potential vulnerability may = impact the confidentiality (high), integrity (high) and availability (high)=
of the vulnerable system, resulting in subsequent system confidentiality (= none), integrity (none) and availability (none) impacts. 2026-05-12 not yet=
calculated CVE-2025-36515 [
https://www.cve.org/CVERecord?id=3DCVE-2025-36= 515 ]
https://intel.com/content/www/us/en/security-center/advisory/intel-sa= -01438.html
=C2=A0=20
Back to top [ #top ]
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/417e991 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using GovDelivery Communica= tions Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency=
=C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ =
https://subscriberhelp.granicus.com/ ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============7146585765089518506==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> Vulnerability Summary for the Week of May 11, 2026
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Vulnerability Bulletins for Cybersecurity and In= frastructure Security Agency. This information has recently been updated an=
d is now available.</p>
<p>The CISA Vulnerability Bulletin provides a summary of new vulnerabilitie=
s that have been recorded in the past week. In some cases, the vulnerabilit= ies in the bulletin may not yet have assigned CVSS scores.</p> <p>Vulnerabilities are based on the=C2=A0<a href=3D"
https://www.cve.org/" t= arget=3D"_blank" class=3D"ext" data-extlink=3D"" rel=3D"noopener">Common Vu= lnerabilities and Exposures</a>=C2=A0(CVE) vulnerability naming standard an=
d are organized according to severity, determined by the=C2=A0<a href=3D"ht= tps://www.cve.org/about/relatedefforts" target=3D"_blank" rel=3D"noopener">= Common Vulnerability Scoring System</a>=C2=A0(CVSS) standard. The division =
of high, medium, and low severities correspond to the following scores:</p>
<strong>High</strong>: vulnerabilities with a CVSS base score of 7.0=E2=80= =9310.0</li>
<strong>Medium</strong>: vulnerabilities with a CVSS base score of 4.0=E2= =80=936.9</li>
<strong>Low</strong>: vulnerabilities with a CVSS base score of 0.0=E2=80= =933.9</li>
</ul>
<p>Entries may include additional information provided by organizations and=
efforts sponsored by CISA. This information may include identifying inform= ation, values, definitions, and related links. Patch information is provide=
d when available. Please note that some of the information in the bulletin =
is compiled from external, open-source reports and is not a direct result o=
f CISA analysis.</p>
<p>=C2=A0</p>
<div class=3D"rss_item" style=3D"margin-bottom: 2em;">
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/news-events/bull= etins/sb26-138">Vulnerability Summary for the Week of May 11, 2026</a></div=
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">05/18/2026 05:00 PM EDT</div>
<div class=3D"rss_description" style=3D"margin: 0 0 0.3em; padding: 0;">
<div id=3D"high_v">
<h2 id=3D"high_v_title">High Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"High Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
<th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">acl--ACL Analytics</td>
<td>ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary cod=
e execution vulnerability that allows attackers to execute arbitrary comman=
ds by leveraging the EXECUTE function. Attackers can use bitsadmin to downl= oad malicious PowerShell scripts and execute them with system privileges to=
establish reverse shells and gain complete system control.</td> <td>2026-05-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25320" target=3D= "_blank" rel=3D"noopener">CVE-2018-25320</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44281" target=3D"_blank" rel= =3D"noopener">ExploitDB-44281</a><br><a href=3D"
https://www.acl.com" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://www.acl.com/products/acl-analytics/" target=3D"_blank" rel=3D"noopene= r">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories= /acl-analytics-11-x-arbitrary-code-execution" target=3D"_blank" rel=3D"noop= ener">VulnCheck Advisory: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Ex= ecution</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">gitbucket--GitBucket</td>
<td>GitBucket 4.23.1 contains an unauthenticated remote code execution vuln= erability that allows attackers to execute arbitrary commands by exploiting=
weak secret token generation and insecure file upload functionality. Attac= kers can brute-force the Blowfish encryption key, upload a malicious JAR pl= ugin via the git-lfs endpoint, and execute system commands through an expos=
ed exploit endpoint.</td>
<td>2026-05-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25332" target=3D= "_blank" rel=3D"noopener">CVE-2018-25332</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44668" target=3D"_blank" rel= =3D"noopener">ExploitDB-44668</a><br><a href=3D"
https://security.szurek.pl/=
" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"
https://github.com/gitbucket/gitbucket" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisor= ies/gitbucket-unauthenticated-remote-code-execution" target=3D"_blank" rel= =3D"noopener">VulnCheck Advisory: GitBucket 4.23.1 Unauthenticated Remote C= ode Execution</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">peugeot-music-plugin--Peugeot Music</td> <td>WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vu= lnerability that allows unauthenticated attackers to upload malicious files=
by sending POST requests to the upload.php endpoint. Attackers can upload = files with arbitrary extensions by manipulating the 'name' parameter to exe= cute code from the uploads directory.</td>
<td>2026-05-17</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25335" target=3D= "_blank" rel=3D"noopener">CVE-2018-25335</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44737" target=3D"_blank" rel= =3D"noopener">ExploitDB-44737</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/wordpress-plugin-peugeot-music-arbitrary-file-upload" target=3D"_= blank" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin Peugeot Music = 1.0 Arbitrary File Upload</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Paiement--Ecommerce Systempay</td>
<td>Ecommerce Systempay 1.0 contains a weak cryptographic implementation vu= lnerability that allows attackers to brute force the 16-character productio=
n secret key used for payment signature generation. Attackers can extract p= ayment form data and signatures from POST requests to the payment endpoint,=
then use SHA1 hash comparison to iteratively test key candidates until dis= covering the correct production key, enabling them to forge valid payment s= ignatures and manipulate transaction amounts.</td>
<td>2026-05-13</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37168" target=3D= "_blank" rel=3D"noopener">CVE-2020-37168</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48017" target=3D"_blank" rel= =3D"noopener">ExploitDB-48017</a><br><a href=3D"
https://paiement.systempay.= fr/doc/fr-FR/" target=3D"_blank" rel=3D"noopener">Official Product Homepage= </a><br><a href=3D"
https://paiement.systempay.fr/doc/fr-FR/module-de-paieme= nt-gratuit/" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a=
href=3D"
https://www.vulncheck.com/advisories/ecommerce-systempay-productio= n-key-brute-force" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: E= commerce Systempay 1.0 Production Key Brute Force</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Yerootech--iDS6 DSSPro Digital Signage System<=
<td>iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypa=
ss vulnerability that allows attackers to bypass authentication by requesti=
ng the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA cod=
es via the login endpoint and use them to perform brute-force attacks again=
st user accounts.</td>
<td>2026-05-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37228" target=3D= "_blank" rel=3D"noopener">CVE-2020-37228</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48991" target=3D"_blank" rel= =3D"noopener">ExploitDB-48991</a><br><a href=3D"
https://www.zeroscience.mk/= en/vulnerabilities/ZSL-2020-5607.php" target=3D"_blank" rel=3D"noopener">Vu= lnerability Advisory</a><br><a href=3D"
http://www.yerootech.com" target=3D"= _blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"https:= //www.vulncheck.com/advisories/ids6-dsspro-digital-signage-system-captcha-s= ecurity-bypass" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: iDS6=
DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Gegl--libbabl</td>
<td>libbabl 0.1.62 contains a broken double free detection vulnerability th=
at allows attackers to bypass memory safety checks by exploiting signature = overwriting in freed chunks. Attackers can call babl_free() twice on the sa=
me pointer without triggering detection, as libc's malloc metadata overwrit=
es babl's signature field upon freeing, enabling potential memory corruptio=
n and code execution.</td>
<td>2026-05-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37239" target=3D= "_blank" rel=3D"noopener">CVE-2020-37239</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49259" target=3D"_blank" rel= =3D"noopener">ExploitDB-49259</a><br><a href=3D"
https://www.gegl.org" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.gegl.org/babl/" target=3D"_blank" rel=3D"noopener">Product Refer= ence</a><br><a href=3D"
https://www.vulncheck.com/advisories/libbabl-broken-= double-free-detection-memory-safety" target=3D"_blank" rel=3D"noopener">Vul= nCheck Advisory: libbabl 0.1.62 Broken Double Free Detection Memory Safety<= /a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Jsonpickle--python jsonpickle</td>
<td>python jsonpickle 2.0.0 contains a remote code execution vulnerability = that allows attackers to execute arbitrary Python commands by deserializing=
malicious JSON payloads containing py/repr objects. Attackers can craft JS=
ON strings with py/repr directives that invoke the eval function during des= erialization to execute system commands and arbitrary code.</td> <td>2026-05-16</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47952" target=3D= "_blank" rel=3D"noopener">CVE-2021-47952</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49585" target=3D"_blank" rel= =3D"noopener">ExploitDB-49585</a><br><a href=3D"
https://jsonpickle.github.i=
o" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a h= ref=3D"
https://github.com/jsonpickle/jsonpickle" target=3D"_blank" rel=3D"n= oopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advi= sories/python-jsonpickle-remote-code-execution-via-py-repr" target=3D"_blan=
k" rel=3D"noopener">VulnCheck Advisory: python jsonpickle 2.0.0 Remote Code=
Execution via py/repr</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">wp-super-edit--WP Super Edit</td>
<td>WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestrict=
ed file upload vulnerability in the FCKeditor component that allows attacke=
rs to upload dangerous file types without validation. Attackers can upload = arbitrary files through the filemanager upload endpoint to achieve remote c= ode execution and complete system compromise.</td>
<td>2026-05-15</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47965" target=3D= "_blank" rel=3D"noopener">CVE-2021-47965</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49839" target=3D"_blank" rel= =3D"noopener">ExploitDB-49839</a><br><a href=3D"
https://wordpress.org" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"=
https://wordpress.org/plugins/wp-super-edit/" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisor= ies/wordpress-plugin-wp-super-edit-unrestricted-file-upload" target=3D"_bla= nk" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin WP Super Edit 2.5=
.4 Unrestricted File Upload</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Akilli Commerce Software Technologies Ltd. Co.= --E-Commerce Website</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Akilli Commerce Software Technologies Ltd. C=
o. E-Commerce Website allows Blind SQL Injection. This issue affects E-Comm= erce Website: before 4.5.001.</td>
<td>2026-05-14</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-11024" target=3D= "_blank" rel=3D"noopener">CVE-2025-11024</a></td>
<a href=3D"
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 222" target=3D"_blank" rel=3D"noopener">
https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0222</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Hitachi Vantara--Pentaho Data Integration and = Analytics</td>
<td>Hitachi Vantara Pentaho Data Integration & Analytics of all version=
s contain a JDBC driver for H2 databases which is vulnerable to external sc= ript execution when a new connection is created by a=C2=A0data source admin= istrator.</td>
<td>2026-05-13</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-11159" target=3D= "_blank" rel=3D"noopener">CVE-2025-11159</a></td>
<a href=3D"
https://support.pentaho.com/hc/en-us/articles/39954640408077--Re= solved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Dependency-on-Vul= nerable-Third-Party-Component-Versions-before-10-2-0-7-and-11-0-0-0-Impacte= d-CVE-2025-11159" target=3D"_blank" rel=3D"noopener">
https://support.pentah= o.com/hc/en-us/articles/39954640408077--Resolved-Hitachi-Vantara-Pentaho-Da= ta-Integration-Analytics-Dependency-on-Vulnerable-Third-Party-Component-Ver= sions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2025-11159</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">alloksoft--Fast AVI MPEG Splitter</td>
<td>Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow=
vulnerability that allows local attackers to execute arbitrary code by sup= plying a malicious license name string. Attackers can craft a payload with = 780 bytes of junk data followed by structured shellcode and place it in the=
License Name field to trigger the overflow and execute code with applicati=
on privileges.</td>
<td>2026-05-17</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25322" target=3D= "_blank" rel=3D"noopener">CVE-2018-25322</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44341" target=3D"_blank" rel= =3D"noopener">ExploitDB-44341</a><br><a href=3D"
http://www.alloksoft.com" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
http://www.alloksoft.com/allok_vconverter.exe" target=3D"_blank" rel=3D= "noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/ad= visories/allok-fast-avi-mpeg-splitter-stack-based-buffer-overflow" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Allok Fast AVI MPEG Splitt=
er 1.2 Stack Based Buffer Overflow</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Alloksoft--Allok AVI DivX MPEG to DVD Converte= r</td>
<td>Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exc= eption handler buffer overflow vulnerability that allows local attackers to=
execute arbitrary code by supplying a malicious payload. Attackers can cra=
ft a text file with a specially crafted buffer containing shellcode and SEH=
chain overwrite values, then paste the contents into the License Name fiel=
d to trigger code execution.</td>
<td>2026-05-17</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25323" target=3D= "_blank" rel=3D"noopener">CVE-2018-25323</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44363" target=3D"_blank" rel= =3D"noopener">ExploitDB-44363</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/allok-avi-divx-mpeg-to-dvd-converter-buffer-overflow-seh" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Allok AVI DivX MPEG to DVD=
Converter 2.6.1217 Buffer Overflow SEH</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">vxsearch--VX Search</td>
<td>VX Search 10.6.18 contains a local buffer overflow vulnerability that a= llows attackers to overwrite the instruction pointer by supplying an oversi= zed string in the directory field. Attackers can craft a malicious input fi=
le containing 271 bytes of junk data followed by a return address to execut=
e arbitrary code with application privileges.</td>
<td>2026-05-17</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25328" target=3D= "_blank" rel=3D"noopener">CVE-2018-25328</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44494" target=3D"_blank" rel= =3D"noopener">ExploitDB-44494</a><br><a href=3D"
https://www.7elements.co.uk=
" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"
http://www.vxsearch.com" target=3D"_blank" rel=3D"noopener">Official = Product Homepage</a><br><a href=3D"
https://www.vulncheck.com/advisories/vx-= search-local-buffer-overflow-via-directory-field" target=3D"_blank" rel=3D"= noopener">VulnCheck Advisory: VX Search 10.6.18 Local Buffer Overflow via D= irectory Field</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Joomlaextensions--Joomla! extension EkRishta</=
<td>Joomla! extension EkRishta 2.10 contains persistent cross-site scriptin=
g and SQL injection vulnerabilities that allow attackers to inject maliciou=
s code through profile fields and POST parameters. Attackers can inject scr= ipt payloads in profile information fields like Address that execute when u= sers visit the profile, or submit SQL injection payloads via the phone_no p= arameter to the user_setting endpoint to manipulate database queries.</td> <td>2026-05-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25330" target=3D= "_blank" rel=3D"noopener">CVE-2018-25330</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44660" target=3D"_blank" rel= =3D"noopener">ExploitDB-44660</a><br><a href=3D"
https://www.joomlaextension= s.co.in/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><= br><a href=3D"
https://extensions.joomla.org/extensions/extension/living/dat= ing-a-relationships/ek-rishta/" target=3D"_blank" rel=3D"noopener">Product = Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories/joomla-ekr= ishta-persistent-xss-and-sql-injection" target=3D"_blank" rel=3D"noopener">= VulnCheck Advisory: Joomla! EkRishta 2.10 Persistent XSS and SQL Injection<= /a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">nordex-online--N149 Wind Turbine Web Server</t=
<td>Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injecti=
on vulnerability that allows unauthenticated attackers to execute arbitrary=
SQL queries by injecting malicious code through the login parameter in log= in.php. Attackers can submit crafted POST requests with SQL injection paylo= ads in the login field to extract sensitive database information and bypass=
authentication mechanisms.</td>
<td>2026-05-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25333" target=3D= "_blank" rel=3D"noopener">CVE-2018-25333</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44684" target=3D"_blank" rel= =3D"noopener">ExploitDB-44684</a><br><a href=3D"
http://www.nordex-online.co=
m" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a h= ref=3D"
https://www.vulncheck.com/advisories/nordex-n149-wind-turbine-web-se= rver-sql-injection" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: = Nordex N149/4.0-4.5 Wind Turbine Web Server SQL Injection</a><br>=C2=A0</td=
</tr>
<td class=3D"vendor-product">Bylancer--Zechat</td>
<td>Zechat 1.5 contains a SQL injection vulnerability in the hashtag parame= ter that allows unauthenticated attackers to extract database information u= sing union-based techniques. Attackers can exploit the hashtag parameter wi=
th union-based payloads to retrieve table and column names.</td> <td>2026-05-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25338" target=3D= "_blank" rel=3D"noopener">CVE-2018-25338</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44685" target=3D"_blank" rel= =3D"noopener">ExploitDB-44685</a><br><a href=3D"
https://bylancer.com" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/zechat-sql-injection-via-hashtag-parame= ter" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Zechat 1.5 SQL = Injection via hashtag parameter</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Bylancer--Zechat</td>
<td>Zechat 1.5 contains a SQL injection vulnerability in the v parameter th=
at allows unauthenticated attackers to extract database information using t= ime-based blind techniques. Attackers can exploit the v parameter with slee= p-based blind injection to confirm vulnerability and extract data.</td> <td>2026-05-17</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25339" target=3D= "_blank" rel=3D"noopener">CVE-2018-25339</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44685" target=3D"_blank" rel= =3D"noopener">ExploitDB-44685</a><br><a href=3D"
https://bylancer.com" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/zechat-sql-injection-via-v-parameter-ti= me-based-blind" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Zech=
at 1.5 SQL Injection via v parameter (time-based blind)</a><br>=C2=A0</td> </tr>
<td class=3D"vendor-product">Hdwplayer--com_hdwplayer</td>
<td>Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the=
search.php file that allows unauthenticated attackers to execute arbitrary=
SQL queries by injecting malicious code through the hdwplayersearch parame= ter. Attackers can submit POST requests with crafted SQL payloads in the hd= wplayersearch parameter to extract sensitive database information from the = hdwplayer_videos table.</td>
<td>2026-05-13</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37218" target=3D= "_blank" rel=3D"noopener">CVE-2020-37218</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48242" target=3D"_blank" rel= =3D"noopener">ExploitDB-48242</a><br><a href=3D"
https://www.hdwplayer.com/"=
target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hre= f=3D"
https://www.hdwplayer.com/download/" target=3D"_blank" rel=3D"noopener= ">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories/= joomla-com-hdwplayer-sql-injection-via-search-php" target=3D"_blank" rel=3D= "noopener">VulnCheck Advisory: Joomla com_hdwplayer 4.2 SQL Injection via s= earch.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Drive-software--Atomic Alarm Clock</td>
<td>Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that all= ows local attackers to execute arbitrary code by supplying a malicious stri=
ng to the display name textbox in the Time Zones Clock configuration. Attac= kers can craft a buffer with structured exception handling overwrite and en= coded shellcode to bypass SafeSEH protections and execute arbitrary command=
s with application privileges.</td>
<td>2026-05-13</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37221" target=3D= "_blank" rel=3D"noopener">CVE-2020-37221</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48346" target=3D"_blank" rel= =3D"noopener">ExploitDB-48346</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/atomic-alarm-clock-stack-overflow-via-seh-unicode" target=3D"_bla= nk" rel=3D"noopener">VulnCheck Advisory: Atomic Alarm Clock 6.3 Stack Overf= low via SEH Unicode</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Heliossolutions--HS Brand Logo Slider</td>
<td>HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerabi= lity that allows authenticated users to bypass client-side file extension v= alidation by uploading arbitrary files. Attackers can intercept upload requ= ests to the logoupload parameter in the admin interface and rename files to=
executable extensions .php to achieve remote code execution.</td> <td>2026-05-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37227" target=3D= "_blank" rel=3D"noopener">CVE-2020-37227</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48913" target=3D"_blank" rel= =3D"noopener">ExploitDB-48913</a><br><a href=3D"
https://www.heliossolutions= .co/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><=
a href=3D"
https://ms.wordpress.org/plugins/hs-brand-logo-slider/" target=3D= "_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://www.v= ulncheck.com/advisories/wordpress-plugin-hs-brand-logo-slider-unrestricted-= file-upload" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPre=
ss Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload</a><br>=C2=A0</=
</tr>
<td class=3D"vendor-product">Supsystic--Ultimate Maps</td>
<td>Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability = that allows unauthenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the 'sidx' GET parameter. Attackers can sen=
d crafted requests to the getListForTbl action with boolean-based blind or = time-based blind SQL injection payloads to extract sensitive database infor= mation.</td>
<td>2026-05-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37242" target=3D= "_blank" rel=3D"noopener">CVE-2020-37242</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49532" target=3D"_blank" rel= =3D"noopener">ExploitDB-49532</a><br><a href=3D"
https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "
https://downloads.wordpress.org/plugin/ultimate-maps-by-supsystic.1.1.12.z= ip" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"=
https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-ultimate-ma= ps-sql-injection-via-sidx" target=3D"_blank" rel=3D"noopener">VulnCheck Adv= isory: WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via si= dx</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Supsystic--Pricing Table</td>
<td>Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability i=
n the 'sidx' GET parameter that allows unauthenticated attackers to execute=
arbitrary SQL queries through the getListForTbl action. The plugin also co= ntains stored cross-site scripting vulnerabilities in the 'Edit name' and '= Edit HTML' fields that execute malicious scripts when viewing pricing table= s.</td>
<td>2026-05-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37243" target=3D= "_blank" rel=3D"noopener">CVE-2020-37243</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49533" target=3D"_blank" rel= =3D"noopener">ExploitDB-49533</a><br><a href=3D"
https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "
https://downloads.wordpress.org/plugin/pricing-table-by-supsystic.1.8.7.zi=
p" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/wordpress-plugin-supsystic-pricing-tabl= e-sql-injection-xss" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory:=
WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS</a><br>= =C2=A0</td>
</tr>
<td class=3D"vendor-product">Supsystic--Membership</td>
<td>Supsystic Membership 1.4.7 contains an SQL injection vulnerability that=
allows unauthenticated attackers to execute arbitrary SQL queries by injec= ting malicious code through the 'search' and 'sidx' parameters. Attackers c=
an send GET requests to the badges module with crafted payloads to extract = sensitive database information using time-based blind or UNION-based SQL in= jection techniques.</td>
<td>2026-05-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37244" target=3D= "_blank" rel=3D"noopener">CVE-2020-37244</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49540" target=3D"_blank" rel= =3D"noopener">ExploitDB-49540</a><br><a href=3D"
https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "
https://downloads.wordpress.org/plugin/membership-by-supsystic.1.4.7.zip" = target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"http= s://www.vulncheck.com/advisories/wordpress-plugin-supsystic-membership-sql-= injection-via-sidx" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: = WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx</a><br>= =C2=A0</td>
</tr>
<td class=3D"vendor-product">LayerBB--LayerBB</td>
<td>LayerBB 1.1.4 contains an SQL injection vulnerability that allows unaut= henticated attackers to manipulate database queries by injecting SQL code t= hrough the search_query parameter. Attackers can send POST requests to /sea= rch.php with malicious search_query values using CASE WHEN statements to ex= tract sensitive database information.</td>
<td>2026-05-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47954" target=3D= "_blank" rel=3D"noopener">CVE-2021-47954</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49593" target=3D"_blank" rel= =3D"noopener">ExploitDB-49593</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/layerbb-sql-injection-via-search-query-parameter" target=3D"_blan=
k" rel=3D"noopener">VulnCheck Advisory: LayerBB 1.1.4 SQL Injection via sea= rch_query Parameter</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Egavilanmedia--EgavilanMedia PHPCRUD</td> <td>EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that = allows unauthenticated attackers to manipulate database queries by injectin=
g SQL code through the firstname parameter. Attackers can send POST request=
s to insert.php with malicious firstname values to extract sensitive databa=
se information.</td>
<td>2026-05-16</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47956" target=3D= "_blank" rel=3D"noopener">CVE-2021-47956</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49878" target=3D"_blank" rel= =3D"noopener">ExploitDB-49878</a><br><a href=3D"
https://egavilanmedia.com" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://egavilanmedia.com/crud-operation-with-php-mysql-bootstrap-and-d= ompdf/" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href= =3D"
https://www.vulncheck.com/advisories/egavilanmedia-phpcrud-sql-injectio= n-via-firstname" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Ega= vilanMedia PHPCRUD 1.0 SQL Injection via firstname</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Schlix--Schlix CMS</td>
<td>Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that = allows authenticated attackers to execute arbitrary PHP code by uploading m= alicious extension packages through the block manager. Attackers can upload=
a crafted ZIP file containing PHP code in the packageinfo.inc file and tri= gger execution by accessing the About tab of the installed extension.</td> <td>2026-05-15</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47964" target=3D= "_blank" rel=3D"noopener">CVE-2021-47964</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49838" target=3D"_blank" rel= =3D"noopener">ExploitDB-49838</a><br><a href=3D"
https://www.schlix.com/" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://www.schlix.com/downloads/schlix-cms/schlix-cms-v2.2.6-6.zip" ta= rget=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:= //www.vulncheck.com/advisories/schlix-cms-6-remote-code-execution-via-core-= blockmanager" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Schlix=
CMS 2.2.6-6 Remote Code Execution via core.blockmanager</a><br>=C2=A0</td> </tr>
<td class=3D"vendor-product">Timeclock--PHP Timeclock</td>
<td>PHP Timeclock 1.04 contains time-based and boolean-based blind SQL inje= ction vulnerabilities in the login_userid parameter of login.php that allow=
s unauthenticated attackers to extract database contents. Attackers can sub= mit crafted POST requests with SQL payloads using SLEEP functions or RLIKE = conditional statements to dump sensitive database information including emp= loyee names and credentials.</td>
<td>2026-05-15</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47966" target=3D= "_blank" rel=3D"noopener">CVE-2021-47966</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49849" target=3D"_blank" rel= =3D"noopener">ExploitDB-49849</a><br><a href=3D"
http://timeclock.sourceforg= e.net" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br>=
<a href=3D"
https://sourceforge.net/projects/timeclock/files/PHP%20Timeclock= /PHP%20Timeclock%201.04/" target=3D"_blank" rel=3D"noopener">Product Refere= nce</a><br><a href=3D"
https://www.vulncheck.com/advisories/php-timeclock-sq= l-injection-via-login-php" target=3D"_blank" rel=3D"noopener">VulnCheck Adv= isory: PHP Timeclock 1.04 SQL Injection via login.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Textpattern--TextPattern CMS</td>
<td>TextPattern CMS 4.9.0-dev contains a remote code execution vulnerabilit=
y that allows authenticated attackers to upload arbitrary PHP files by expl= oiting the plugin upload functionality. Attackers can authenticate, retriev=
e a CSRF token from the plugin event page, and upload malicious PHP files t=
o the textpattern/tmp/ directory for code execution.</td>
<td>2026-05-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47976" target=3D= "_blank" rel=3D"noopener">CVE-2021-47976</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50095" target=3D"_blank" rel= =3D"noopener">ExploitDB-50095</a><br><a href=3D"
https://textpattern.com/" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://github.com/textpattern/textpattern" target=3D"_blank" rel=3D"no= opener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advis= ories/textpattern-cms-dev-authenticated-remote-code-execution-via-plugin-up= load" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: TextPattern CM=
S 4.9.0-dev Authenticated Remote Code Execution via Plugin Upload</a><br>= =C2=A0</td>
</tr>
<td class=3D"vendor-product">Miniorange--Backup and Restore</td>
<td>WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file de= letion vulnerability that allows authenticated attackers to delete files by=
manipulating parameters in AJAX requests. Attackers can send POST requests=
to admin-ajax.php with crafted file_name and folder_name parameters to del= ete arbitrary files from the WordPress installation directory.</td> <td>2026-05-16</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47979" target=3D= "_blank" rel=3D"noopener">CVE-2021-47979</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50503" target=3D"_blank" rel= =3D"noopener">ExploitDB-50503</a><br><a href=3D"
https://www.miniorange.com/=
" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"
https://wordpress.org/plugins/backup-and-restore-for-wp/" target=3D"_= blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://www.vul= ncheck.com/advisories/wordpress-plugin-backup-and-restore-arbitrary-file-de= letion" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPress Pl= ugin Backup and Restore 1.0.3 Arbitrary File Deletion</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
<td>The Magic Link authentication flow accepts multiple invalid authenticat= ion requests without adequate rate limiting or resource control, leading to=
uncontrolled memory usage growth. This vulnerability can result in a denia= l-of-service condition, causing service unavailability for deployments that=
utilize the Magic Link authenticator. The impact is limited to these speci= fic deployments and requires repeated invalid authentication attempts to tr= igger.</td>
<td>2026-05-11</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-10470" target=3D= "_blank" rel=3D"noopener">CVE-2025-10470</a></td>
<a href=3D"
https://security.docs.wso2.com/en/latest/security-announcements/= security-advisories/2026/WSO2-2025-4469/" target=3D"_blank" rel=3D"noopener= ">
https://security.docs.wso2.com/en/latest/security-announcements/security-= advisories/2026/WSO2-2025-4469/</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">APPYAP Technology and Information Inc.--Yaay S= ocial Media App</td>
<td>Authorization bypass through User-Controlled key vulnerability in APPYA=
P Technology and Information Inc. Yaay Social Media App allows Accessing Fu= nctionality Not Properly Constrained by ACLs. This issue affects Yaay Socia=
l Media App: from 3.8.0 through 24102025.</td>
<td>2026-05-14</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12008" target=3D= "_blank" rel=3D"noopener">CVE-2025-12008</a></td>
<a href=3D"
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 238" target=3D"_blank" rel=3D"noopener">
https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0238</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Automation Sys= tem</td>
<td>Incorrect Authorization vulnerability in Yordam Information Technology = Consulting, Training and Electronic Systems Industry and Trade Inc. Library=
Automation System allows Exploiting Incorrectly Configured Access Control = Security Levels. This issue affects Library Automation System: from v.19.5 = before v.22.1.</td>
<td>2026-05-14</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15023" target=3D= "_blank" rel=3D"noopener">CVE-2025-15023</a></td>
<a href=3D"
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 240" target=3D"_blank" rel=3D"noopener">
https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0240</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Automation Sys= tem</td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability=
in Yordam Information Technology Consulting, Training and Electronic Syste=
ms Industry and Trade Inc. Library Automation System allows Remote Code Inc= lusion. This issue affects Library Automation System: from v.19.5 before v.= 22.1.</td>
<td>2026-05-14</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15024" target=3D= "_blank" rel=3D"noopener">CVE-2025-15024</a></td>
<a href=3D"
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 240" target=3D"_blank" rel=3D"noopener">
https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0240</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Automation Sys= tem</td>
<td>Authorization bypass through User-Controlled key vulnerability in Yorda=
m Information Technology Consulting, Training and Electronic Systems Indust=
ry and Trade Inc. Library Automation System allows Exploitation of Trusted = Identifiers. This issue affects Library Automation System: from v.21.6 befo=
re v.22.1.</td>
<td>2026-05-14</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15025" target=3D= "_blank" rel=3D"noopener">CVE-2025-15025</a></td>
<a href=3D"
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 240" target=3D"_blank" rel=3D"noopener">
https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0240</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">wende60--Redaxo CMS Addon MyEvents</td>
<td>Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability=
that allows authenticated attackers to manipulate database queries by inje= cting SQL code through the myevents_id parameter. Attackers can send GET re= quests to the event_add.php page with malicious myevents_id values to extra=
ct or modify sensitive database information.</td>
<td>2026-05-17</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25319" target=3D= "_blank" rel=3D"noopener">CVE-2018-25319</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44261" target=3D"_blank" rel= =3D"noopener">ExploitDB-44261</a><br><a href=3D"
http://www.github.com/wende= 60/myevents" target=3D"_blank" rel=3D"noopener">Official Product Homepage</= a><br><a href=3D"
https://www.vulncheck.com/advisories/redaxo-cms-addon-myev= ents-sql-injection-via-event-add-php" target=3D"_blank" rel=3D"noopener">Vu= lnCheck Advisory: Redaxo CMS Addon MyEvents 2.2.1 SQL Injection via event_a= dd.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">woocommerce-csvimport--WooCommerce CSV-Importe= r</td>
<td>Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability = that allows any registered user to delete arbitrary files by submitting une= scaped filenames through the delete_export_file AJAX action. Attackers can = craft POST requests with directory traversal sequences in the filename para= meter to delete sensitive files like wp-config.php outside the intended exp= ort directory.</td>
<td>2026-05-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25325" target=3D= "_blank" rel=3D"noopener">CVE-2018-25325</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44433" target=3D"_blank" rel= =3D"noopener">ExploitDB-44433</a><br><a href=3D"
http://lenonleite.com.br/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://www.vulncheck.com/advisories/woocommerce-csv-importer-path-trav= ersal-file-deletion" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory:=
Woocommerce CSV Importer 3.3.6 Path Traversal File Deletion</a><br>=C2=A0<=
</tr>
<td class=3D"vendor-product">wp-google-drive--Google Drive</td>
<td>Google Drive for WordPress 2.2 contains a path traversal vulnerability = that allows unauthenticated attackers to read arbitrary files by injecting = directory traversal sequences in the file_name parameter. Attackers can sen=
d POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del= _fl_bkp and file_name containing traversal sequences ../../wp-config.php to=
access sensitive configuration files.</td>
<td>2026-05-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25326" target=3D= "_blank" rel=3D"noopener">CVE-2018-25326</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44435" target=3D"_blank" rel= =3D"noopener">ExploitDB-44435</a><br><a href=3D"
http://lenonleite.com.br/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://www.vulncheck.com/advisories/google-drive-for-wordpress-path-tr= aversal-rce-via-gdrive-ajaxs-php" target=3D"_blank" rel=3D"noopener">VulnCh= eck Advisory: Google Drive for WordPress 2.2 Path Traversal RCE via gdrive-= ajaxs.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">wp-with-spritz--WP with Spritz</td>
<td>WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vu= lnerability that allows unauthenticated attackers to read arbitrary files b=
y injecting file paths into the url parameter. Attackers can send GET reque= sts to wp.spritz.content.filter.php with malicious url values to access sen= sitive files like system configuration and credentials.</td> <td>2026-05-17</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25329" target=3D= "_blank" rel=3D"noopener">CVE-2018-25329</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44544" target=3D"_blank" rel= =3D"noopener">ExploitDB-44544</a><br><a href=3D"
https://downloads.wordpress= .org/plugin/wp-with-spritz.zip" target=3D"_blank" rel=3D"noopener">Product = Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories/wordpress-= plugin-wp-with-spritz-remote-file-inclusion" target=3D"_blank" rel=3D"noope= ner">VulnCheck Advisory: WordPress Plugin WP with Spritz 1.0 Remote File In= clusion</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Fabrikar--com_fabrik</td>
<td>Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability t= hat allows unauthenticated attackers to list arbitrary files by manipulatin=
g the folder parameter. Attackers can send GET requests to the onAjax_files=
method with path traversal sequences to enumerate files in system director= ies outside the intended web root.</td>
<td>2026-05-13</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37219" target=3D= "_blank" rel=3D"noopener">CVE-2020-37219</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48263" target=3D"_blank" rel= =3D"noopener">ExploitDB-48263</a><br><a href=3D"
https://fabrikar.com/" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"=
https://fabrikar.com/downloads" target=3D"_blank" rel=3D"noopener">Product = Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories/joomla-com= -fabrik-directory-traversal-via-image-php" target=3D"_blank" rel=3D"noopene= r">VulnCheck Advisory: Joomla com_fabrik 3.9.11 Directory Traversal via ima= ge.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">www.huawei.com--Huawei HG630 Router</td> <td>Huawei HG630 V2 router contains an authentication bypass vulnerability = that allows unauthenticated attackers to obtain administrative access by re= trieving the device serial number. Attackers can query the /api/system/devi= ceinfo endpoint without authentication to extract the SerialNumber field, t= hen use the last 8 characters as the default password to login to the route= r.</td>
<td>2026-05-13</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37220" target=3D= "_blank" rel=3D"noopener">CVE-2020-37220</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48310" target=3D"_blank" rel= =3D"noopener">ExploitDB-48310</a><br><a href=3D"
https://www.youtube.com/wat= ch?v=3DvOrIL7L_cVc" target=3D"_blank" rel=3D"noopener">Reference</a><br><a = href=3D"
https://www.vulncheck.com/advisories/huawei-hg630-v2-router-authent= ication-bypass-via-serial-number" target=3D"_blank" rel=3D"noopener">VulnCh= eck Advisory: Huawei HG630 V2 Router Authentication Bypass via Serial Numbe= r</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Kuicms--Kuicms Php EE</td>
<td>Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerabil= ity that allows unauthenticated attackers to inject malicious scripts by su= bmitting crafted content through the bbs reply endpoint. Attackers can send=
POST requests to /web/?c=3Dbbs&a=3Dreply with HTML and JavaScript payl= oads in the content parameter to execute arbitrary scripts in users' browse= rs.</td>
<td>2026-05-13</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37222" target=3D= "_blank" rel=3D"noopener">CVE-2020-37222</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48526" target=3D"_blank" rel= =3D"noopener">ExploitDB-48526</a><br><a href=3D"
https://kuicms.com" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://kuicms.com/kuicms.zip" target=3D"_blank" rel=3D"noopener">Product Ref= erence</a><br><a href=3D"
https://www.vulncheck.com/advisories/kuicms-php-ee= -persistent-cross-site-scripting-via-bbs-reply" target=3D"_blank" rel=3D"no= opener">VulnCheck Advisory: Kuicms Php EE 2.0 Persistent Cross-Site Scripti=
ng via bbs reply</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Iobit--IObit Uninstaller</td>
<td>IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerabil= ity in the IObitUnSvr service that allows local attackers to escalate privi= leges to SYSTEM level. Attackers can place a malicious executable named IOb= it.exe in the C:\Program Files (x86)\IObit directory and restart the servic=
e to execute code with SYSTEM privileges.</td>
<td>2026-05-13</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37223" target=3D= "_blank" rel=3D"noopener">CVE-2020-37223</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48543" target=3D"_blank" rel= =3D"noopener">ExploitDB-48543</a><br><a href=3D"
https://www.iobit.com" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"=
https://www.iobit.com/en/advanceduninstaller.php" target=3D"_blank" rel=3D"= noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/adv= isories/iobit-uninstaller-unquoted-service-path-privilege-escalation" targe= t=3D"_blank" rel=3D"noopener">VulnCheck Advisory: IObit Uninstaller 9.5.0.1=
5 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Joomsky--J2 JOBS</td>
<td>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerabil= ity that allows authenticated attackers to manipulate database queries by i= njecting SQL code through the 'sortby' parameter. Attackers can send POST r= equests to the administrator index with malicious 'sortby' values to extrac=
t sensitive database information.</td>
<td>2026-05-13</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37224" target=3D= "_blank" rel=3D"noopener">CVE-2020-37224</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48648" target=3D"_blank" rel= =3D"noopener">ExploitDB-48648</a><br><a href=3D"
https://joomsky.com/" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://joomsky.com/products/js-jobs-pro.html" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisor= ies/joomla-j2-jobs-authenticated-sql-injection-via-sortby" target=3D"_blank=
" rel=3D"noopener">VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated S=
QL Injection via sortby</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Joomsky--J2 JOBS</td>
<td>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerabil= ity that allows authenticated attackers to manipulate database queries by i= njecting SQL code through the 'sortby' parameter. Attackers can send POST r= equests to the administrator index with malicious 'sortby' values to extrac=
t sensitive database information using automated tools.</td> <td>2026-05-13</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37226" target=3D= "_blank" rel=3D"noopener">CVE-2020-37226</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48670" target=3D"_blank" rel= =3D"noopener">ExploitDB-48670</a><br><a href=3D"
https://joomsky.com/" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://joomsky.com/products/js-jobs-pro.html" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisor= ies/joomla-j2-jobs-authenticated-sql-injection-via-sortby-2" target=3D"_bla= nk" rel=3D"noopener">VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated=
SQL Injection via sortby</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Oki--OKI sPSV Port Manager</td>
<td>OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerab= ility in the sPSVOpLclSrv service that allows local attackers to escalate p= rivileges by inserting executable files into the unquoted path. Attackers c=
an place a malicious executable in a directory within the service path that=
will execute with LocalSystem privileges when the service restarts or the = system reboots.</td>
<td>2026-05-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37229" target=3D= "_blank" rel=3D"noopener">CVE-2020-37229</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49005" target=3D"_blank" rel= =3D"noopener">ExploitDB-49005</a><br><a href=3D"
https://www.oki.com/" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.oki.com/mx/printing/download/sPSV_010041_2_270910.exe" target=3D= "_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://www.v= ulncheck.com/advisories/oki-spsv-port-manager-unquoted-service-path-privile= ge-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: OKI s= PSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation</a><br>= =C2=A0</td>
</tr>
<td class=3D"vendor-product">Syncplify--Syncplify.me Server!</td> <td>Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerabi= lity in the SMWebRestServicev5 service that allows local attackers to escal= ate privileges by exploiting the unquoted binary path. Attackers can insert=
a malicious executable into the service path and execute it with LocalSyst=
em privileges when the service restarts or the system reboots.</td> <td>2026-05-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37230" target=3D= "_blank" rel=3D"noopener">CVE-2020-37230</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49009" target=3D"_blank" rel= =3D"noopener">ExploitDB-49009</a><br><a href=3D"
https://www.syncplify.me/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://download.syncplify.me/SMServer_Setup.exe" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com= /advisories/syncplify-me-server-unquoted-service-path-privilege-escalation"=
target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Syncplify.me Server=
! 5.0.37 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Cybertronsoft--Privacy Drive</td>
<td>Privacy Drive 3.17.0 contains an unquoted service path vulnerability in=
the pdsvc.exe service binary that allows local attackers to escalate privi= leges by exploiting the service startup process. Attackers can place malici= ous executables in the unquoted path directories to execute arbitrary code = with LocalSystem privileges during service startup or system reboot.</td> <td>2026-05-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37231" target=3D= "_blank" rel=3D"noopener">CVE-2020-37231</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49023" target=3D"_blank" rel= =3D"noopener">ExploitDB-49023</a><br><a href=3D"
https://www.cybertronsoft.c= om/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
href=3D"
https://www.cybertronsoft.com/download/privacy-drive-setup.exe" ta= rget=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:= //www.vulncheck.com/advisories/privacy-drive-unquoted-service-path-privileg= e-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Privac=
y Drive 3.17.0 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td=
</tr>
<td class=3D"vendor-product">Iobit--Advanced System Care Service</td> <td>Advanced System Care Service 13.0.0.157 contains an unquoted service pa=
th vulnerability in the AdvancedSystemCareService13 service binary path tha=
t allows local attackers to escalate privileges. Attackers can place malici= ous executables in the system root path that will be executed with LocalSys= tem privileges during service startup or system reboot.</td> <td>2026-05-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37232" target=3D= "_blank" rel=3D"noopener">CVE-2020-37232</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49049" target=3D"_blank" rel= =3D"noopener">ExploitDB-49049</a><br><a href=3D"
https://www.iobit.com" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"=
https://www.iobit.com/es/advancedsystemcarepro.php" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com= /advisories/advanced-system-care-service-unquoted-service-path-privilege-es= calation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Advanced S= ystem Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation</a= ><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Supsystic--Digital Publications</td>
<td>Supsystic Digital Publications 1.6.9 contains a path traversal vulnerab= ility in the Folder input field that allows attackers to access files outsi=
de the web root by injecting directory traversal sequences. Additionally, t=
he plugin fails to sanitize input fields in publication settings, allowing = stored cross-site scripting attacks through script injection in parameters = like Area Width and Publication Width that execute when publications are vi= ewed or edited.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37245" target=3D= "_blank" rel=3D"noopener">CVE-2020-37245</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49542" target=3D"_blank" rel= =3D"noopener">ExploitDB-49542</a><br><a href=3D"
https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "
https://downloads.wordpress.org/plugin/digital-publications-by-supsystic.1= .6.9.zip" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a hr= ef=3D"
https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-digit= al-publications-path-traversal-xss" target=3D"_blank" rel=3D"noopener">Vuln= Check Advisory: WordPress Plugin Supsystic Digital Publications 1.6.9 Path = Traversal XSS</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Kite--Kite</td>
<td>Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the = KiteService Windows service that allows local attackers to escalate privile= ges by exploiting the service binary path. Attackers can place a malicious = executable in the Program Files directory to be executed with LocalSystem p= rivileges when the service starts.</td>
<td>2026-05-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37247" target=3D= "_blank" rel=3D"noopener">CVE-2020-37247</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50975" target=3D"_blank" rel= =3D"noopener">ExploitDB-50975</a><br><a href=3D"
https://www.kite.com/" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"=
https://www.vulncheck.com/advisories/kite-u1-unquoted-service-path-privileg= e-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Kite 4= .2.0.1 U1 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Home-Assistant--Home Assistant Community Store=
(HACS)</td>
<td>Home Assistant Community Store (HACS) 1.10.0 contains a path traversal = vulnerability that allows unauthenticated attackers to read sensitive files=
by traversing directories via the /hacsfiles/ endpoint. Attackers can retr= ieve the .storage/auth file containing user credentials and refresh tokens,=
then craft valid JWT tokens to gain administrative access to Home Assistan=
t instances.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47942" target=3D= "_blank" rel=3D"noopener">CVE-2021-47942</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49495" target=3D"_blank" rel= =3D"noopener">ExploitDB-49495</a><br><a href=3D"
https://www.home-assistant.= io/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
href=3D"
https://github.com/hacs/integration" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisor= ies/home-assistant-community-store-path-traversal-account-takeover" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Home Assistant Community S= tore 1.10.0 Path Traversal Account Takeover</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Wpgraphql--WPGraphQL</td>
<td>WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerabi= lity that allows unauthenticated attackers to exhaust server resources by s= ending batched GraphQL queries with duplicated fields. Attackers can send P= OST requests to the GraphQL endpoint with amplified field duplication paylo= ads to trigger server out-of-memory conditions and MySQL connection errors.= </td>
<td>2026-05-15</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47959" target=3D= "_blank" rel=3D"noopener">CVE-2021-47959</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49807" target=3D"_blank" rel= =3D"noopener">ExploitDB-49807</a><br><a href=3D"
https://www.wpgraphql.com/"=
target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hre= f=3D"
https://www.vulncheck.com/advisories/wordpress-plugin-wpgraphql-denial= -of-service" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPre=
ss Plugin WPGraphQL 1.3.5 Denial of Service</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AnotherNote--Anote</td>
<td>Anote 1.0 contains a persistent cross-site scripting vulnerability that=
allows attackers to execute arbitrary code by injecting malicious payloads=
into markdown files stored within the application. Attackers can craft mal= icious markdown files with embedded JavaScript that executes system command=
s when opened, enabling remote code execution on the victim's computer.</td=
<td>2026-05-15</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47963" target=3D= "_blank" rel=3D"noopener">CVE-2021-47963</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49836" target=3D"_blank" rel= =3D"noopener">ExploitDB-49836</a><br><a href=3D"
https://github.com/AnotherN= ote/anote" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"
https://www.vulncheck.com/advisories/anote-persistent-cross-= site-scripting-remote-code-execution" target=3D"_blank" rel=3D"noopener">Vu= lnCheck Advisory: Anote 1.0 Persistent Cross-Site Scripting Remote Code Exe= cution</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">color-notes--Color Notes</td>
<td>Color Notes 1.4 contains a denial of service vulnerability that allows = attackers to crash the application by pasting excessively long character st= rings into note fields. Attackers can generate a payload containing 350,000=
repeated characters and paste it twice into a new note to cause the applic= ation to stop responding.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47969" target=3D= "_blank" rel=3D"noopener">CVE-2021-47969</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49952" target=3D"_blank" rel= =3D"noopener">ExploitDB-49952</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/color-notes-denial-of-service-via-long-character-string" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Color Notes 1.4 Denial of = Service via Long Character String</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">macaron-notes-great-notebook--Macaron Notes Ge=
ar Notebook</td>
<td>Macaron Notes 5.5 contains a denial of service vulnerability that allow=
s attackers to crash the application by creating notes with excessively lon=
g character strings. Attackers can generate a payload containing 350000 rep= eated characters and paste it into a note field to trigger application cras=
h and stop functionality.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47970" target=3D= "_blank" rel=3D"noopener">CVE-2021-47970</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49953" target=3D"_blank" rel= =3D"noopener">ExploitDB-49953</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/macaron-notes-denial-of-service-via-buffer-overflow" target=3D"_b= lank" rel=3D"noopener">VulnCheck Advisory: Macaron Notes 5.5 Denial of Serv= ice via Buffer Overflow</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">my-notes-safe--My Notes Safe</td>
<td>My Notes Safe 5.3 contains a denial of service vulnerability that allow=
s attackers to crash the application by pasting excessively long character = strings into note fields. Attackers can generate a payload containing 35000=
0 repeated characters and paste it twice into a new note to trigger an appl= ication crash.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47971" target=3D= "_blank" rel=3D"noopener">CVE-2021-47971</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49954" target=3D"_blank" rel= =3D"noopener">ExploitDB-49954</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/my-notes-safe-denial-of-service-via-buffer-overflow" target=3D"_b= lank" rel=3D"noopener">VulnCheck Advisory: My Notes Safe 5.3 Denial of Serv= ice via Buffer Overflow</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">sticky-notes-color-widgets--Sticky Notes Color=
Widgets</td>
<td>Sticky Notes & Color Widgets 1.4.2 contains a denial of service vul= nerability that allows attackers to crash the application by creating notes=
with excessively long character strings. Attackers can paste large payload=
s of repeated characters into note fields to trigger application crashes an=
d make the application stop responding.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47972" target=3D= "_blank" rel=3D"noopener">CVE-2021-47972</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49957" target=3D"_blank" rel= =3D"noopener">ExploitDB-49957</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/sticky-notes-color-widgets-denial-of-service" target=3D"_blank" r= el=3D"noopener">VulnCheck Advisory: Sticky Notes & Color Widgets 1.4.2 = Denial of Service</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">sticky-notes--Sticky Notes Widget</td>
<td>Sticky Notes Widget 3.0.6 contains a denial of service vulnerability th=
at allows attackers to crash the application by pasting excessively long ch= aracter strings into note fields. Attackers can generate a payload containi=
ng 350000 repeated characters and paste it twice into a new note to trigger=
an application crash on iOS devices.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47973" target=3D= "_blank" rel=3D"noopener">CVE-2021-47973</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49978" target=3D"_blank" rel= =3D"noopener">ExploitDB-49978</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/sticky-notes-widget-denial-of-service-via-buffer-overflow" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Sticky Notes Widget 3.0.6 = Denial of Service via Buffer Overflow</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Vxsearch--VX Search</td>
<td>VX Search 13.5.28 contains an unquoted service path vulnerability in bo=
th VX Search Server and VX Search Enterprise services that allows local att= ackers to escalate privileges. Attackers can place malicious executables in=
unquoted path directories like C:\Program Files\VX Search to execute arbit= rary code with LocalSystem privileges when services restart.</td> <td>2026-05-16</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47974" target=3D= "_blank" rel=3D"noopener">CVE-2021-47974</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50026" target=3D"_blank" rel= =3D"noopener">ExploitDB-50026</a><br><a href=3D"
https://www.vxsearch.com" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://www.vulncheck.com/advisories/vx-search-unquoted-service-path-pr= ivilege-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: =
VX Search 13.5.28 Unquoted Service Path Privilege Escalation</a><br>=C2=A0<=
</tr>
<td class=3D"vendor-product">Wplearnmanager--WP Learn Manager</td>
<td>WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerabi= lity that allows unauthenticated attackers to inject malicious scripts thro= ugh the fieldtitle parameter. Attackers can submit POST requests to the jsl= m_fieldordering page with XSS payloads in the fieldtitle field to execute a= rbitrary JavaScript when administrators view the field ordering interface.<=
<td>2026-05-16</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47975" target=3D= "_blank" rel=3D"noopener">CVE-2021-47975</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50086" target=3D"_blank" rel= =3D"noopener">ExploitDB-50086</a><br><a href=3D"
https://wplearnmanager.com/=
" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"
https://wordpress.org/plugins/learn-manager/" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com= /advisories/wordpress-plugin-wp-learn-manager-stored-xss" target=3D"_blank"=
rel=3D"noopener">VulnCheck Advisory: WordPress Plugin WP Learn Manager 1.1=
.2 Stored XSS</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Gotmls--Malware Security and Bruteforce Firewa= ll</td>
<td>WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 = contains a directory traversal vulnerability that allows unauthenticated at= tackers to read arbitrary files by manipulating the file parameter. Attacke=
rs can send requests to the duplicator_download action via admin-ajax.php w= ith path traversal sequences to access sensitive system files outside the i= ntended directory.</td>
<td>2026-05-16</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47977" target=3D= "_blank" rel=3D"noopener">CVE-2021-47977</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50107" target=3D"_blank" rel= =3D"noopener">ExploitDB-50107</a><br><a href=3D"
https://gotmls.net/" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://gotmls.net/downloads/" target=3D"_blank" rel=3D"noopener">Product Ref= erence</a><br><a href=3D"
https://www.vulncheck.com/advisories/wordpress-ant= i-malware-security-bruteforce-firewall-directory-traversal" target=3D"_blan=
k" rel=3D"noopener">VulnCheck Advisory: WordPress Anti-Malware Security Bru= teforce Firewall 4.20.59 Directory Traversal</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Getfuelcms--Fuel CMS</td>
<td>Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allow=
s authenticated attackers to manipulate database queries by injecting SQL c= ode through the 'col' parameter in the Activity Log interface. Attackers ca=
n send requests to the logs endpoint with malicious SQL payloads in the 'co=
l' parameter to extract database information based on response time delays.= </td>
<td>2026-05-16</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47980" target=3D= "_blank" rel=3D"noopener">CVE-2021-47980</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50523" target=3D"_blank" rel= =3D"noopener">ExploitDB-50523</a><br><a href=3D"
https://www.getfuelcms.com/=
" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"
https://github.com/daylightstudio/FUEL-CMS/archive/1.4.13.zip" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://ww= w.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-parameter" = target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Fuel CMS 1.4.13 Blin=
d SQL Injection via col Parameter</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that=
could have allowed an unauthenticated user to cause denial of service by s= ending specially crafted payloads on certain API endpoints.</td> <td>2026-05-14</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14869" target=3D= "_blank" rel=3D"noopener">CVE-2025-14869</a></td>
<a href=3D"
https://hackerone.com/reports/3447146" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3447146</a><br><a href=3D"
https://gi= tlab.com/gitlab-org/gitlab/-/work_items/584489" target=3D"_blank" rel=3D"no= opener">
https://gitlab.com/gitlab-org/gitlab/-/work_items/584489</a><br><a = href=3D"
https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">
https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that=
could have allowed an unauthenticated user to cause denial of service by s= ending specially crafted JSON payloads due to insufficient input validation= .</td>
<td>2026-05-14</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14870" target=3D= "_blank" rel=3D"noopener">CVE-2025-14870</a></td>
<a href=3D"
https://hackerone.com/reports/3446641" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3446641</a><br><a href=3D"
https://gi= tlab.com/gitlab-org/gitlab/-/work_items/584490" target=3D"_blank" rel=3D"no= opener">
https://gitlab.com/gitlab-org/gitlab/-/work_items/584490</a><br><a = href=3D"
https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">
https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"medium_v">
<h2 id=3D"medium_v_title">Medium Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Medium Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
<th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">Simple-Fields--Simple Fields</td>
<td>Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file = inclusion vulnerability that allows unauthenticated attackers to read arbit= rary files by injecting null bytes into the wp_abspath parameter on PHP ver= sions before 5.3.4. Attackers can supply malicious wp_abspath values to sim= ple_fields.php to include files like /etc/passwd or inject PHP code into Ap= ache logs for remote code execution when allow_url_include is enabled.</td> <td>2026-05-17</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25324" target=3D= "_blank" rel=3D"noopener">CVE-2018-25324</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44425" target=3D"_blank" rel= =3D"noopener">ExploitDB-44425</a><br><a href=3D"
http://simple-fields.com" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://downloads.wordpress.org/plugin/simple-fields.0.3.5.zip" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://ww= w.vulncheck.com/advisories/simple-fields-local-file-inclusion-via-wp-abspat=
h" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Simple Fields 0.2= -0.3.5 Local File Inclusion via wp_abspath</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">zenar--Zenar Content Management System</td> <td>Zenar Content Management System contains a cross-site scripting vulnera= bility that allows unauthenticated attackers to inject malicious scripts by=
manipulating form parameters in POST requests. Attackers can inject script=
tags through the current_page parameter sent to the ajax.php endpoint, whi=
ch reflects unsanitized user input in the response HTML to execute arbitrar=
y JavaScript in victim browsers.</td>
<td>2026-05-17</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25331" target=3D= "_blank" rel=3D"noopener">CVE-2018-25331</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44664" target=3D"_blank" rel= =3D"noopener">ExploitDB-44664</a><br><a href=3D"
http://demo.zenar.io" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://zenar.io/" target=3D"_blank" rel=3D"noopener">Product Reference</a><= br><a href=3D"
https://www.vulncheck.com/advisories/zenar-content-management= -system-cross-site-scripting-via-ajax-php" target=3D"_blank" rel=3D"noopene= r">VulnCheck Advisory: Zenar Content Management System Cross-Site Scripting=
via ajax.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Powie--WHOIS Domain Check</td>
<td>Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scri= pting vulnerability that allows authenticated attackers to inject arbitrary=
JavaScript by exploiting unsanitized input fields in plugin settings. Atta= ckers can submit malicious payloads through textarea and input elements in = the pwhois_settings.php configuration page to execute JavaScript in the adm=
in context and escalate privileges.</td>
<td>2026-05-13</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37225" target=3D= "_blank" rel=3D"noopener">CVE-2020-37225</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48656" target=3D"_blank" rel= =3D"noopener">ExploitDB-48656</a><br><a href=3D"
https://powie.de" target=3D= "_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"https= ://blog.haao.sh" target=3D"_blank" rel=3D"noopener">Official Product Homepa= ge</a><br><a href=3D"
https://wordpress.org/plugins/powies-whois/" target=3D= "_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://www.v= ulncheck.com/advisories/powie-s-whois-domain-check-persistent-cross-site-sc= ripting" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Powie's WHO=
IS Domain Check 0.9.31 Persistent Cross-Site Scripting</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Wordpress--Buddypress</td>
<td>WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scri= pting vulnerability that allows authenticated attackers with moderator priv= ileges to inject malicious script code through the figure parameter in wp:h= tml blocks. Attackers can inject iframe elements with event handlers like o= nload that execute when administrators or privileged users preview or view = the affected page content, enabling session hijacking and persistent phishi=
ng attacks.</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37233" target=3D= "_blank" rel=3D"noopener">CVE-2020-37233</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49061" target=3D"_blank" rel= =3D"noopener">ExploitDB-49061</a><br><a href=3D"
https://wordpress.org/plugi= ns/buddypress/" target=3D"_blank" rel=3D"noopener">Official Product Homepag= e</a><br><a href=3D"
https://www.vulncheck.com/advisories/wordpress-plugin-b= uddypress-persistent-cross-site-scripting" target=3D"_blank" rel=3D"noopene= r">VulnCheck Advisory: WordPress Plugin Buddypress 6.2.0 Persistent Cross-S= ite Scripting</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Internetdownloadmanager--Internet Download Man= ager</td>
<td>Internet Download Manager 6.38.12 contains a buffer overflow vulnerabil= ity in the Scheduler component that allows local attackers to crash the app= lication by supplying oversized input. Attackers can paste malicious data e= xceeding 5000 bytes into the 'Open the following file when done' field to t= rigger a denial of service condition.</td>
<td>2026-05-16</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37234" target=3D= "_blank" rel=3D"noopener">CVE-2020-37234</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49083" target=3D"_blank" rel= =3D"noopener">ExploitDB-49083</a><br><a href=3D"
http://www.internetdownload= manager.com/" target=3D"_blank" rel=3D"noopener">Official Product Homepage<= /a><br><a href=3D"
http://www.internetdownloadmanager.com/download.html" tar= get=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:/= /www.vulncheck.com/advisories/internet-download-manager-scheduler-buffer-ov= erflow" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Internet Dow= nload Manager 6.38.12 Scheduler Buffer Overflow</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">themeftc--Theme Wibar</td>
<td>WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vuln= erability in the Brand component that allows authenticated users to inject = malicious scripts by manipulating the Logo URL parameter. Attackers with ed= itor, administrator, contributor, or author privileges can inject base64-en= coded script payloads through the ftc_brand_url input field to execute arbi= trary JavaScript when users visit the brand page.</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37235" target=3D= "_blank" rel=3D"noopener">CVE-2020-37235</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49107" target=3D"_blank" rel= =3D"noopener">ExploitDB-49107</a><br><a href=3D"
http://demo.themeftc.com/wi= bar" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
href=3D"
https://themeforest.net/item/wibar-responsive-woocommerce-wordpres= s-theme/20994798" target=3D"_blank" rel=3D"noopener">Product Reference</a><= br><a href=3D"
https://www.vulncheck.com/advisories/wordpress-theme-wibar-st= ored-cross-site-scripting-via-brand-component" target=3D"_blank" rel=3D"noo= pener">VulnCheck Advisory: WordPress Theme Wibar 1.1.8 Stored Cross-Site Sc= ripting via Brand Component</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Netartmedia--NewsLister</td>
<td>NewsLister contains an authenticated persistent cross-site scripting vu= lnerability that allows authenticated administrators to inject malicious sc= ripts through the title parameter in the news addition interface. Attackers=
can inject JavaScript payloads via the title field in the admin panel that=
execute when news items are viewed by other users.</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37236" target=3D= "_blank" rel=3D"noopener">CVE-2020-37236</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49160" target=3D"_blank" rel= =3D"noopener">ExploitDB-49160</a><br><a href=3D"
https://www.netartmedia.net= /newslister.html" target=3D"_blank" rel=3D"noopener">Official Product Homep= age</a><br><a href=3D"
https://www.vulncheck.com/advisories/newslister-authe= nticated-persistent-cross-site-scripting-via-admin-panel" target=3D"_blank"=
rel=3D"noopener">VulnCheck Advisory: NewsLister Authenticated Persistent C= ross-Site Scripting via Admin Panel</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Compo--Composr CMS</td>
<td>Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerab= ility that allows authenticated administrators to inject malicious scripts = through the banner management interface. Attackers with admin credentials c=
an inject XSS payloads in the Description field of the Add banner functiona= lity, which execute for all website visitors when they access the home page= .</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37237" target=3D= "_blank" rel=3D"noopener">CVE-2020-37237</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49190" target=3D"_blank" rel= =3D"noopener">ExploitDB-49190</a><br><a href=3D"
https://compo.sr/" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://compo.sr/download.htm" target=3D"_blank" rel=3D"noopener">Product Ref= erence</a><br><a href=3D"
https://www.vulncheck.com/advisories/composr-cms-p= ersistent-cross-site-scripting-via-banners" target=3D"_blank" rel=3D"noopen= er">VulnCheck Advisory: Composr CMS 10.0.34 Persistent Cross-Site Scripting=
via banners</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Cmsmadesimple--CMS Made Simple</td>
<td>CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerabi= lity that allows authenticated users with Content Manager access to inject = malicious scripts through SVG file uploads. Attackers can upload SVG files = containing embedded JavaScript to the file manager, which executes when oth=
er authenticated users access the uploaded file, enabling cookie theft and = session hijacking.</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37238" target=3D= "_blank" rel=3D"noopener">CVE-2020-37238</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49199" target=3D"_blank" rel= =3D"noopener">ExploitDB-49199</a><br><a href=3D"
https://www.cmsmadesimple.o= rg/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
href=3D"
https://www.cmsmadesimple.org/downloads" target=3D"_blank" rel=3D"= noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/adv= isories/cms-made-simple-stored-xss-via-svg-file-upload" target=3D"_blank" r= el=3D"noopener">VulnCheck Advisory: CMS Made Simple 2.2.15 Stored XSS via S=
VG File Upload</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Codekernel--Queue Management System</td>
<td>Queue Management System 4.0.0 contains a stored cross-site scripting vu= lnerability that allows authenticated administrators to inject malicious sc= ripts through user creation fields. Attackers can insert JavaScript payload=
s in the First Name, Last Name, and Email fields during user creation, whic=
h execute when viewing the User List page.</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37240" target=3D= "_blank" rel=3D"noopener">CVE-2020-37240</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49296" target=3D"_blank" rel= =3D"noopener">ExploitDB-49296</a><br><a href=3D"
http://codekernel.net/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "
https://codecanyon.net/item/queue-management-system/22029961" target=3D"_b= lank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://www.vuln= check.com/advisories/queue-management-system-stored-xss-via-add-user" targe= t=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Queue Management System 4= .0.0 Stored XSS via Add User</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Supsystic--Backup</td>
<td>Supsystic Backup 2.3.9 contains a local file inclusion vulnerability th=
at allows unauthenticated attackers to read and delete arbitrary files by m= anipulating the download path parameter. Attackers can modify the download = parameter in admin.php requests with directory traversal sequences to acces=
s sensitive files like /etc/passwd or delete files via the removeAction par= ameter.</td>
<td>2026-05-16</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37246" target=3D= "_blank" rel=3D"noopener">CVE-2020-37246</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49545" target=3D"_blank" rel= =3D"noopener">ExploitDB-49545</a><br><a href=3D"
https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "
https://downloads.wordpress.org/plugin/backup-by-supsystic.zip" target=3D"= _blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://www.vu= lncheck.com/advisories/wordpress-plugin-supsystic-backup-local-file-inclusi= on" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin=
Supsystic Backup 2.3.9 Local File Inclusion</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Cookielawinfo--Cookie Law Bar</td>
<td>Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerabili=
ty that allows authenticated attackers to inject malicious scripts by submi= tting unsanitized input to the Bar Message field. Attackers can inject scri=
pt payloads through the plugin settings page that execute in the browsers o=
f all WordPress users viewing the site, enabling cookie theft and sensitive=
data exfiltration.</td>
<td>2026-05-16</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47957" target=3D= "_blank" rel=3D"noopener">CVE-2021-47957</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49905" target=3D"_blank" rel= =3D"noopener">ExploitDB-49905</a><br><a href=3D"
https://www.cookielawinfo.c= om/wordpress-plugin/" target=3D"_blank" rel=3D"noopener">Official Product H= omepage</a><br><a href=3D"
https://wordpress.org/plugins/cookie-law-bar/" ta= rget=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:= //www.vulncheck.com/advisories/wordpress-plugin-cookie-law-bar-stored-xss-v= ia-clb-bar-msg" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Word= Press Plugin Cookie Law Bar 1.2.1 Stored XSS via clb_bar_msg</a><br>=C2=A0<=
</tr>
<td class=3D"vendor-product">savsofts--Savsoft Quiz</td>
<td>Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerabili=
ty in the user account settings page that allows authenticated attackers to=
inject malicious HTML and JavaScript code. Attackers can inject script pay= loads into user profile fields at the edit_user endpoint, which execute in = the browsers of users viewing the affected profile after submission.</td> <td>2026-05-15</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47962" target=3D= "_blank" rel=3D"noopener">CVE-2021-47962</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49825" target=3D"_blank" rel= =3D"noopener">ExploitDB-49825</a><br><a href=3D"
https://savsoftquiz.com" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://github.com/savsofts/savsoftquiz_v5" target=3D"_blank" rel=3D"no= opener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advis= ories/savsoft-quiz-persistent-cross-site-scripting-via-user-settings" targe= t=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Savsoft Quiz 5.0 Persiste=
nt Cross-Site Scripting via User Settings</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Timeclock--PHP Timeclock</td>
<td>PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabiliti=
es that allow unauthenticated attackers to inject arbitrary JavaScript by m= anipulating URL paths and POST parameters. Attackers can append malicious p= ayloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, =
or inject code through from_date and to_date parameters in report requests =
to execute scripts in user browsers.</td>
<td>2026-05-15</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47967" target=3D= "_blank" rel=3D"noopener">CVE-2021-47967</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49853" target=3D"_blank" rel= =3D"noopener">ExploitDB-49853</a><br><a href=3D"
http://timeclock.sourceforg= e.net" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br>=
<a href=3D"
https://sourceforge.net/projects/timeclock/files/PHP%20Timeclock= /PHP%20Timeclock%201.04/" target=3D"_blank" rel=3D"noopener">Product Refere= nce</a><br><a href=3D"
https://www.vulncheck.com/advisories/php-timeclock-mu= ltiple-cross-site-scripting-via-parameters" target=3D"_blank" rel=3D"noopen= er">VulnCheck Advisory: PHP Timeclock 1.04 Multiple Cross-Site Scripting vi=
a Parameters</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Podcastgenerator--Podcast Generator</td> <td>Podcast Generator 3.1 contains a persistent cross-site scripting vulner= ability that allows authenticated attackers to inject malicious scripts by = submitting unfiltered JavaScript code in the long_description parameter. At= tackers can inject script tags through episode creation or editing requests=
to execute arbitrary JavaScript when other users view the episode details.= </td>
<td>2026-05-15</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47968" target=3D= "_blank" rel=3D"noopener">CVE-2021-47968</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49866" target=3D"_blank" rel= =3D"noopener">ExploitDB-49866</a><br><a href=3D"
https://podcastgenerator.ne= t/demoV2/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"
https://podcastgenerator.net/download" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com= /advisories/podcast-generator-persistent-cross-site-scripting-via-long-desc= ription" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Podcast Gen= erator 3.1 Persistent Cross-Site Scripting via long_description</a><br>=C2= =A0</td>
</tr>
<td class=3D"vendor-product">Processmaker--ProcessMaker</td>
<td>ProcessMaker 3.5.4 contains a local file inclusion vulnerability that a= llows unauthenticated attackers to read arbitrary files by exploiting impro= per path traversal validation. Attackers can send requests with directory t= raversal sequences to access sensitive system files like /etc/passwd withou=
t authentication.</td>
<td>2026-05-16</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47978" target=3D= "_blank" rel=3D"noopener">CVE-2021-47978</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50229" target=3D"_blank" rel= =3D"noopener">ExploitDB-50229</a><br><a href=3D"
https://www.processmaker.co= m/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a = href=3D"
https://www.vulncheck.com/advisories/processmaker-local-file-inclus= ion-via-path-traversal" target=3D"_blank" rel=3D"noopener">VulnCheck Adviso= ry: ProcessMaker 3.5.4 Local File Inclusion via Path Traversal</a><br>=C2= =A0</td>
</tr>
<td class=3D"vendor-product">interactivegeomaps--MapGeo Interactive Geo Map= s</td>
<td>The MapGeo - Interactive Geo Maps plugin for WordPress is vulnerable to=
Reflected Cross-Site Scripting via the 'map' parameter in the display-map = shortcode in all versions up to, and including, 1.6.27 due to insufficient = input sanitization and output escaping. This makes it possible for unauthen= ticated attackers to inject arbitrary web scripts in pages that execute if = they can successfully trick a user into performing an action such as clicki=
ng on a link.</td>
<td>2026-05-14</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15345" target=3D= "_blank" rel=3D"noopener">CVE-2025-15345</a></td>
<a href=3D"
https://www.wordfence.com/threat-intel/vulnerabilities/id/bfccbf= 41-c861-4bf1-b400-7858cb255b9a?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">
https://www.wordfence.com/threat-intel/vulnerabilities/id/bfccbf41-c86= 1-4bf1-b400-7858cb255b9a?source=3Dcve</a><br><a href=3D"
https://research.cl= eantalk.org/cve-2025-15345" target=3D"_blank" rel=3D"noopener">
https://rese= arch.cleantalk.org/cve-2025-15345</a><br><a href=3D"
https://plugins.trac.wo= rdpress.org/changeset?old_path=3D/interactive-geo-maps/tags/1.6.27/src/Plug= in/Map.php&new_path=3D/interactive-geo-maps/tags/1.6.28/src/Plugin/Map.php"=
target=3D"_blank" rel=3D"noopener">
https://plugins.trac.wordpress.org/chan= geset?old_path=3D/interactive-geo-maps/tags/1.6.27/src/Plugin/Map.php&new_p= ath=3D/interactive-geo-maps/tags/1.6.28/src/Plugin/Map.php</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">hwk-fr--Advanced Custom Fields: Extended</td> <td>The The Advanced Custom Fields: Extended plugin for WordPress is vulner= able to arbitrary shortcode execution in all versions up to, and including,=
0.9.2.3. This is due to the software allowing users to execute an action t= hat does not properly validate a value before running do_shortcode. This ma= kes it possible for unauthenticated attackers to execute arbitrary shortcod= es.</td>
<td>2026-05-12</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15463" target=3D= "_blank" rel=3D"noopener">CVE-2025-15463</a></td>
<a href=3D"
https://www.wordfence.com/threat-intel/vulnerabilities/id/f85447= 84-1994-47e2-be39-568d0ab9ee00?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">
https://www.wordfence.com/threat-intel/vulnerabilities/id/f8544784-199= 4-47e2-be39-568d0ab9ee00?source=3Dcve</a><br><a href=3D"
https://plugins.tra= c.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/modules/form/mod= ule-form-action-email.php#L111" target=3D"_blank" rel=3D"noopener">
https://= plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/modul= es/form/module-form-action-email.php#L111</a><br><a href=3D"
https://plugins= .trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/modules/form= /module-form-front-render.php#L35" target=3D"_blank" rel=3D"noopener">https= ://plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/mo= dules/form/module-form-front-render.php#L35</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Joomsky--JS Jobs</td>
<td>Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery v= ulnerability that allows attackers to perform state-changing actions withou=
t token validation. Attackers can craft malicious HTML forms targeting admi= nistrative endpoints like job.jobenforcedelete to delete job entries or mod= ify component settings when administrators visit attacker-controlled pages.= </td>
<td>2026-05-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25327" target=3D= "_blank" rel=3D"noopener">CVE-2018-25327</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44492" target=3D"_blank" rel= =3D"noopener">ExploitDB-44492</a><br><a href=3D"
https://www.joomsky.com" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://extensions.joomla.org/extension/js-jobs/" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com= /advisories/joomla-component-js-jobs-cross-site-request-forgery" target=3D"= _blank" rel=3D"noopener">VulnCheck Advisory: Joomla! Component Js Jobs 1.2.=
0 Cross-Site Request Forgery</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Bylancer--Zechat</td>
<td>Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability t= hat allows an attacker to change a user's information by bypassing anti-CSR=
F protections. The application uses a CSRF token, but an attacker can use t=
he hashtag parameter to inject an encoded payload and bypass the CSRF prote= ction, allowing for unauthorized changes to user data. This can be exploite=
d by tricking a user into submitting a crafted form or by using a script to=
obtain and set the CSRF token.</td>
<td>2026-05-17</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25334" target=3D= "_blank" rel=3D"noopener">CVE-2018-25334</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44685" target=3D"_blank" rel= =3D"noopener">ExploitDB-44685</a><br><a href=3D"
https://bylancer.com" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/zechat-cross-site-request-forgery-csrf-= via-hashtag-parameter" target=3D"_blank" rel=3D"noopener">VulnCheck Advisor=
y: Zechat 1.5 Cross-Site Request Forgery (CSRF) via hashtag parameter</a><b= r>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Joomlaextensions--Joomla! extension jCart for = OpenCart</td>
<td>Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery=
vulnerability that allows attackers to modify user account information wit= hout authentication. Attackers can craft malicious HTML forms targeting end= points , and to change user credentials, passwords, and affiliate account d= etails when victims visit the attacker-controlled page.</td> <td>2026-05-17</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25336" target=3D= "_blank" rel=3D"noopener">CVE-2018-25336</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44788" target=3D"_blank" rel= =3D"noopener">ExploitDB-44788</a><br><a href=3D"
https://www.joomlaextension= s.co.in/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><= br><a href=3D"
https://extensions.joomla.org/extensions/extension/e-commerce= /e-commerce-integrations/jcart-for-opencart/" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"
https://www.vulncheck.com/advisor= ies/joomla-jcart-for-opencart-cross-site-request-forgery" target=3D"_blank"=
rel=3D"noopener">VulnCheck Advisory: Joomla jCart for OpenCart 2.3.0.2 Cro= ss-Site Request Forgery</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Ultimate Member--ultimate-member</td> <td>WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion = vulnerability that allows authenticated attackers to include arbitrary file=
s by manipulating the pack parameter in class-admin-upgrade.php. Attackers = can send POST requests with malicious pack values to include unintended PHP=
files from the packages directory and execute arbitrary code.</td> <td>2026-05-13</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37169" target=3D= "_blank" rel=3D"noopener">CVE-2020-37169</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48065" target=3D"_blank" rel= =3D"noopener">ExploitDB-48065</a><br><a href=3D"
https://www.vulncheck.com/a= dvisories/wordpress-plugin-ultimate-member-local-file-inclusion" target=3D"= _blank" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin ultimate-memb=
er 2.1.3 Local File Inclusion</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">HUSKY--Products Filter Professional for WooCom= merce</td>
<td>WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-= site scripting vulnerability that allows authenticated attackers to inject = malicious scripts by entering XSS payloads in design tab textfields. Attack= ers can inject JavaScript code through fields like 'Text for block toggle' = and 'Custom front css styles' that executes on frontend pages when saved, a= ffecting all site visitors.</td>
<td>2026-05-13</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37174" target=3D= "_blank" rel=3D"noopener">CVE-2020-37174</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48088" target=3D"_blank" rel= =3D"noopener">ExploitDB-48088</a><br><a href=3D"
https://products-filter.com=
/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a h= ref=3D"
https://wordpress.org/plugins/woocommerce-products-filter/" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://ww= w.vulncheck.com/advisories/woof-products-filter-for-woocommerce-persistent-= xss" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WOOF Products F= ilter for WooCommerce 1.2.3 Persistent XSS</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Bloofox--bloofoxCMS</td>
<td>bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability = that allows attackers to perform administrative actions by tricking logged-=
in users into visiting malicious pages. Attackers can craft hidden forms ta= rgeting the admin user creation endpoint to add new administrative accounts=
with arbitrary credentials without requiring explicit user consent.</td> <td>2026-05-16</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37241" target=3D= "_blank" rel=3D"noopener">CVE-2020-37241</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49507" target=3D"_blank" rel= =3D"noopener">ExploitDB-49507</a><br><a href=3D"
https://www.bloofox.com/" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://github.com/alexlang24/bloofoxCMS/releases/tag/0.5.2.1" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"
https://ww= w.vulncheck.com/advisories/bloofoxcms-cross-site-request-forgery-via-user-a= dd" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: bloofoxCMS 0.5.2=
.1 Cross-Site Request Forgery via user add</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">MyBB--MyBB Timeline Plugin</td>
<td>MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities = that allow attackers to inject malicious scripts through thread titles, pos=
t content, and user profile fields like Location and Bio. Attackers can als=
o exploit a cross-site request forgery vulnerability in the timeline.php pr= ofile action to change a user's cover picture by crafting malicious forms t= hat execute when victims visit affected profiles.</td>
<td>2026-05-16</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47934" target=3D= "_blank" rel=3D"noopener">CVE-2021-47934</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49467" target=3D"_blank" rel= =3D"noopener">ExploitDB-49467</a><br><a href=3D"
https://community.mybb.com/= mods.php?action=3Dview&pid=3D1428" target=3D"_blank" rel=3D"noopener">Produ=
ct Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories/mybb-ti= meline-plugin-cross-site-scripting-and-csrf" target=3D"_blank" rel=3D"noope= ner">VulnCheck Advisory: MyBB Timeline Plugin 1.0 Cross-Site Scripting and = CSRF</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">CouchCMS--CouchCMS</td>
<td>CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allow=
s authenticated attackers to execute arbitrary JavaScript by uploading mali= cious SVG files through the file upload functionality. Attackers can upload=
SVG files containing embedded script tags to the browse.php endpoint, whic=
h are then executed in users' browsers when the files are accessed or previ= ewed.</td>
<td>2026-05-16</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47955" target=3D= "_blank" rel=3D"noopener">CVE-2021-47955</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49636" target=3D"_blank" rel= =3D"noopener">ExploitDB-49636</a><br><a href=3D"
https://github.com/CouchCMS= /CouchCMS" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"
https://www.vulncheck.com/advisories/couchcms-cross-site-scr= ipting-via-svg-file-upload" target=3D"_blank" rel=3D"noopener">VulnCheck Ad= visory: CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload</a><br>=C2= =A0</td>
</tr>
<td class=3D"vendor-product">Opensolution--Quick.CMS</td>
<td>Quick.CMS 6.7 contains a cross-site scripting vulnerability in the slid= ers form that allows authenticated attackers to inject malicious scripts by=
submitting XSS payloads through the sDescription parameter. Attackers can = craft CSRF forms targeting the admin.php?p=3Dsliders-form endpoint to execu=
te arbitrary JavaScript in victim browsers when the form is submitted.</td> <td>2026-05-16</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47981" target=3D= "_blank" rel=3D"noopener">CVE-2021-47981</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/50530" target=3D"_blank" rel= =3D"noopener">ExploitDB-50530</a><br><a href=3D"
https://opensolution.org/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://opensolution.org/download/home.html?sFile=3DQuick.Cms_v6.7-en.z= ip" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"=
https://www.vulncheck.com/advisories/quick-cms-cross-site-scripting-via-csr= f-to-sliders-form" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Q= uick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
<td>The check user account lock states feature within the email OTP flow fa= ils to validate user input, allowing an attacker to infer the existence of = registered user accounts. The discovery of valid usernames can increase the=
risk of brute-force and social engineering attacks. Attackers can leverage=
this information to craft targeted phishing campaigns or other malicious a= ctivities aimed at tricking users into divulging sensitive data, potentiall=
y damaging the organization's reputation and leading to regulatory non-comp= liance and financial consequences.</td>
<td>2026-05-11</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-0391" target=3D"= _blank" rel=3D"noopener">CVE-2024-0391</a></td>
<a href=3D"
https://security.docs.wso2.com/en/latest/security-announcements/= security-advisories/2026/WSO2-2024-3115/" target=3D"_blank" rel=3D"noopener= ">
https://security.docs.wso2.com/en/latest/security-announcements/security-= advisories/2026/WSO2-2024-3115/</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Siemens--SIPROTEC 5 6MD84 (CP300)</td>
<td>A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All ve= rsions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD=
85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 6MD86 (CP200=
) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions >=3D V7.80 <=
V11.0), SIPROTEC 5 6MD89 (CP300) (All versions >=3D V7.80 < V11.0), = SIPROTEC 5 6MU85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC =
5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions >= =3D V7.80 < V11.0), SIPROTEC 5 7SA82 (CP100) (All versions >=3D V7.80=
), SIPROTEC 5 7SA82 (CP150) (All versions < V11.0), SIPROTEC 5 7SA84 (CP= 200) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7S= A86 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SA87 (CP20=
0) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions >=3D V7.80 <=
; V11.0), SIPROTEC 5 7SD82 (CP100) (All versions >=3D V7.80), SIPROTEC 5=
7SD82 (CP150) (All versions < V11.0), SIPROTEC 5 7SD84 (CP200) (All ver= sions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (= All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SD87 (CP200) (All versi= ons), SIPROTEC 5 7SD87 (CP300) (All versions >=3D V7.80 < V11.0), SIP= ROTEC 5 7SJ81 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SJ81 (CP150=
) (All versions < V11.0), SIPROTEC 5 7SJ82 (CP100) (All versions >=3D=
V7.80), SIPROTEC 5 7SJ82 (CP150) (All versions < V11.0), SIPROTEC 5 7SJ=
85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions >=3D V= 7.80 < V11.0), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86=
(CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SK82 (CP100) = (All versions >=3D V7.80), SIPROTEC 5 7SK82 (CP150) (All versions < V= 11.0), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (A=
ll versions >=3D V7.80 < V11.0), SIPROTEC 5 7SL82 (CP100) (All versio=
ns >=3D V7.80), SIPROTEC 5 7SL82 (CP150) (All versions < V11.0), SIPR= OTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions=
>=3D V7.80 < V11.0), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROT=
EC 5 7SL87 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SS8=
5 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions >=3D V7= .80 < V11.0), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 = (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7ST86 (CP300) (= All versions < V11.0), SIPROTEC 5 7SX82 (CP150) (All versions < V11.0=
), SIPROTEC 5 7SX85 (CP300) (All versions < V11.0), SIPROTEC 5 7SY82 (CP= 150) (All versions < V11.0), SIPROTEC 5 7UM85 (CP300) (All versions >= =3D V7.80 < V11.0), SIPROTEC 5 7UT82 (CP100) (All versions >=3D V7.80=
), SIPROTEC 5 7UT82 (CP150) (All versions < V11.0), SIPROTEC 5 7UT85 (CP= 200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions >=3D V7.80 &= lt; V11.0), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP30=
0) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT87 (CP200) (All v= ersions), SIPROTEC 5 7UT87 (CP300) (All versions >=3D V7.80 < V11.0),=
SIPROTEC 5 7VE85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC=
5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions >= ;=3D V7.80 < V11.0), SIPROTEC 5 7VU85 (CP300) (All versions < V11.0),=
SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V11.0). Affected devi= ces do not use sufficiently random values to create session identifiers. Th=
is could allow an unauthenticated remote attacker to brute force a session = identifier and gain read access to limited information from the web server = without authorization.</td>
<td>2026-05-12</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-54017" target=3D= "_blank" rel=3D"noopener">CVE-2024-54017</a></td>
<a href=3D"
https://cert-portal.siemens.com/productcert/html/ssa-786884.html=
" target=3D"_blank" rel=3D"noopener">
https://cert-portal.siemens.com/produc= tcert/html/ssa-786884.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 tha=
t could have allowed an authenticated user to inject HTML and JavaScript in=
to email notifications sent to other users due to improper input sanitizati= on.</td>
<td>2026-05-14</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12669" target=3D= "_blank" rel=3D"noopener">CVE-2025-12669</a></td>
<a href=3D"
https://hackerone.com/reports/3368096" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3368096</a><br><a href=3D"
https://gi= tlab.com/gitlab-org/gitlab/-/work_items/579385" target=3D"_blank" rel=3D"no= opener">
https://gitlab.com/gitlab-org/gitlab/-/work_items/579385</a><br><a = href=3D"
https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">
https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
</tr>
<td class=3D"vendor-product">ghera74--ilGhera Support System for WooCommerc= e</td>
<td>The ilGhera Support System for WooCommerce plugin for WordPress is vuln= erable to unauthorized access of data due to a missing capability check on = the 'get_ticket_content_callback' function in all versions up to, and inclu= ding, 1.3.0. This makes it possible for unauthenticated attackers to view a=
ny support ticket content, including sensitive customer information and pri= vate communications, by providing a ticket ID.</td>
<td>2026-05-13</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14033" target=3D= "_blank" rel=3D"noopener">CVE-2025-14033</a></td>
<a href=3D"
https://www.wordfence.com/threat-intel/vulnerabilities/id/40ceea= 17-ec60-4775-8495-e2f7643d1b7c?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">
https://www.wordfence.com/threat-intel/vulnerabilities/id/40ceea17-ec6= 0-4775-8495-e2f7643d1b7c?source=3Dcve</a><br><a href=3D"
https://plugins.tra= c.wordpress.org/browser/wc-support-system/trunk/includes/class-wc-support-s= ystem.php#L68" target=3D"_blank" rel=3D"noopener">
https://plugins.trac.word= press.org/browser/wc-support-system/trunk/includes/class-wc-support-system.= php#L68</a><br><a href=3D"
https://plugins.trac.wordpress.org/browser/wc-sup= port-system/tags/1.2.6/includes/class-wc-support-system.php#L68" target=3D"= _blank" rel=3D"noopener">
https://plugins.trac.wordpress.org/browser/wc-supp= ort-system/tags/1.2.6/includes/class-wc-support-system.php#L68</a><br><a hr= ef=3D"
https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/in= cludes/class-wc-support-system.php#L643" target=3D"_blank" rel=3D"noopener"= >
https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/include= s/class-wc-support-system.php#L643</a><br><a href=3D"
https://plugins.trac.w= ordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support= -system.php#L643" target=3D"_blank" rel=3D"noopener">
https://plugins.trac.w= ordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support= -system.php#L643</a><br><a href=3D"
https://plugins.trac.wordpress.org/brows= er/wc-support-system/tags/1.3.1/includes/class-wc-support-system.php#L780" = target=3D"_blank" rel=3D"noopener">
https://plugins.trac.wordpress.org/brows= er/wc-support-system/tags/1.3.1/includes/class-wc-support-system.php#L780</= a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">stylemix--Cost Calculator Builder</td>
<td>The Cost Calculator Builder plugin for WordPress is vulnerable to Unaut= henticated Price Manipulation and Insecure Direct Object Reference (IDOR) i=
n all versions up to, and including, 4.0.1 only when used in combination wi=
th Cost Calculator Builder PRO. This is due to the ccb_woocommerce_payment = AJAX action being registered via wp_ajax_nopriv, making it accessible to un= authenticated users, and the renderWooCommercePayment() function passing us= er-controlled data directly to CCBWooCheckout::init() without authorization=
checks. This makes it possible for unauthenticated attackers to add WooCom= merce products to their cart with attacker-controlled prices.</td> <td>2026-05-13</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14755" target=3D= "_blank" rel=3D"noopener">CVE-2025-14755</a></td>
<a href=3D"
https://www.wordfence.com/threat-intel/vulnerabilities/id/fe684f= 43-8442-4b29-84a8-da8c6863e62b?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">
https://www.wordfence.com/threat-intel/vulnerabilities/id/fe684f43-844= 2-4b29-84a8-da8c6863e62b?source=3Dcve</a><br><a href=3D"
https://plugins.tra= c.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes= /CCBOrderController.php#L484" target=3D"_blank" rel=3D"noopener">
https://pl= ugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/include= s/classes/CCBOrderController.php#L484</a><br><a href=3D"
https://plugins.tra= c.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes= /CCBAjaxAction.php#L99" target=3D"_blank" rel=3D"noopener">
https://plugins.= trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/clas= ses/CCBAjaxAction.php#L99</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">wpclever--WPC Badge Management for WooCommerce= </td>
<td>The WPC Badge Management for WooCommerce plugin for WordPress is vulner= able to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_= best_seller` shortcode in all versions up to, and including, 3.1.6 due to i= nsufficient input sanitization and output escaping. This makes it possible = for authenticated attackers, with Shop Manager-level access and above, to i= nject arbitrary web scripts in pages that will execute whenever a user acce= sses an injected page.</td>
<td>2026-05-13</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14767" target=3D= "_blank" rel=3D"noopener">CVE-2025-14767</a></td>
<a href=3D"
https://www.wordfence.com/threat-intel/vulnerabilities/id/bf02ed= c9-2bb6-4ceb-b2a1-63f95c8becb3?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">
https://www.wordfence.com/threat-intel/vulnerabilities/id/bf02edc9-2bb= 6-4ceb-b2a1-63f95c8becb3?source=3Dcve</a><br><a href=3D"
https://wordpress.o= rg/plugins/wpc-badge-management" target=3D"_blank" rel=3D"noopener">https:/= /wordpress.org/plugins/wpc-badge-management</a><br><a href=3D"
https://plugi= ns.trac.wordpress.org/browser/wpc-badge-management/trunk/includes/class-sho= rtcode.php#L98" target=3D"_blank" rel=3D"noopener">
https://plugins.trac.wor= dpress.org/browser/wpc-badge-management/trunk/includes/class-shortcode.php#= L98</a><br><a href=3D"
https://plugins.trac.wordpress.org/changeset/3519100/=
" target=3D"_blank" rel=3D"noopener">
https://plugins.trac.wordpress.org/cha= ngeset/3519100/</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Tp-link--TL-WR720NMbps Wireless N Router</td> <td>TP-Link TL-WR720N wireless router contains a cross-site request forgery=
vulnerability that allows attackers to perform unauthorized administrative=
actions by crafting malicious web requests. Attackers can modify port forw= arding rules via VirtualServerRpm.htm or change WiFi security settings via = WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-= controlled pages.</td>
<td>2026-05-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25321" target=3D= "_blank" rel=3D"noopener">CVE-2018-25321</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44335" target=3D"_blank" rel= =3D"noopener">ExploitDB-44335</a><br><a href=3D"
https://www.tp-link.com/" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://static.tp-link.com/resources/software/TL-WR720N_V1_130719.zip" = target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"http= s://www.vulncheck.com/advisories/tp-link-tl-wr720n-all-versions-csrf-via-ad= ministrative-interfaces" target=3D"_blank" rel=3D"noopener">VulnCheck Advis= ory: TP-Link TL-WR720N All Versions CSRF via Administrative Interfaces</a><= br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Joomlaextensions--Joomla! extension JoomOCShop= </td>
<td>Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerabili=
ty that allows attackers to perform unauthorized actions on behalf of authe= nticated users. Attackers can craft malicious HTML forms targeting account = endpoints like /joomoc2/?route=3Daccount/edit and to modify user informatio=
n or reset passwords without user consent.</td>
<td>2026-05-17</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2018-25337" target=3D= "_blank" rel=3D"noopener">CVE-2018-25337</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/44789" target=3D"_blank" rel= =3D"noopener">ExploitDB-44789</a><br><a href=3D"
https://www.joomlaextension= s.co.in/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><= br><a href=3D"
https://extensions.joomla.org/extensions/extension/e-commerce= /e-commerce-integrations/joomocshop/" target=3D"_blank" rel=3D"noopener">Pr= oduct Reference</a><br><a href=3D"
https://www.vulncheck.com/advisories/joom= la-joomocshop-cross-site-request-forgery" target=3D"_blank" rel=3D"noopener= ">VulnCheck Advisory: Joomla JoomOCShop 1.0 Cross-Site Request Forgery</a><= br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Easy2pilot-v7--Easy2Pilot</td>
<td>Easy2Pilot 7 contains a cross-site request forgery vulnerability that a= llows attackers to add unauthorized user accounts by tricking authenticated=
administrators into visiting malicious pages. Attackers can craft HTML for=
ms targeting the admin.php?action=3Dadd_user endpoint with POST requests co= ntaining username and password parameters to create new administrative acco= unts without explicit user consent.</td>
<td>2026-05-13</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37217" target=3D= "_blank" rel=3D"noopener">CVE-2020-37217</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/48099" target=3D"_blank" rel= =3D"noopener">ExploitDB-48099</a><br><a href=3D"
http://easy2pilot-v7.com/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"
https://www.vulncheck.com/advisories/easy2pilot-7-cross-site-request-fo= rgery-via-admin-php" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory:=
Easy2Pilot 7 Cross-Site Request Forgery via admin.php</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">CouchCMS--CouchCMS</td>
<td>CouchCMS 2.2.1 contains a server-side request forgery vulnerability tha=
t allows authenticated attackers to make arbitrary HTTP requests by uploadi=
ng malicious SVG files. Attackers can upload SVG files containing external = entity references through the browse.php endpoint to access internal servic=
es and resources.</td>
<td>2026-05-15</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-47958" target=3D= "_blank" rel=3D"noopener">CVE-2021-47958</a></td>
<a href=3D"
https://www.exploit-db.com/exploits/49675" target=3D"_blank" rel= =3D"noopener">ExploitDB-49675</a><br><a href=3D"
https://github.com/CouchCMS= /CouchCMS" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"
https://www.vulncheck.com/advisories/couchcms-server-side-re= quest-forgery-via-svg-upload" target=3D"_blank" rel=3D"noopener">VulnCheck = Advisory: CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload</a><br>= =C2=A0</td>
</tr>
<td class=3D"vendor-product">GitLab--GitLab</td>
<td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that=
could have allowed an authenticated user with Guest permissions to view is= sues in projects they were not authorized to access.</td>
<td>2026-05-14</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-13874" target=3D= "_blank" rel=3D"noopener">CVE-2025-13874</a></td>
<a href=3D"
https://hackerone.com/reports/3445398" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3445398</a><br><a href=3D"
https://gi= tlab.com/gitlab-org/gitlab/-/work_items/582634" target=3D"_blank" rel=3D"no= opener">
https://gitlab.com/gitlab-org/gitlab/-/work_items/582634</a><br><a = href=3D"
https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">
https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"low_v">
<h2 id=3D"low_v_title">Low Vulnerabilities</h2>
<table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Low Vulnerabilities">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
<th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
</tr>
</thead>
<tbody>
<td style=3D"text-align: center;" colspan=3D"5" align=3D"center">There were=
no low vulnerabilities recorded this week.</td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"snya_v">
<h2 id=3D"snya_v_title">Severity Not Yet Assigned</h2>
<table id=3D"table_severity_not_yet_assigned" class=3D"table no-tablesaw" s= tyle=3D"table-layout: fixed; width: 100%;" border=3D"1" summary=3D"Severity=
Not Yet Assigned">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
<th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">AMD--AMD Ryzen 5000 Series Desktop Processors = with Radeon Graphics</td>
<td>A compromised Trusted OS (TOS) driver could issue a malformed call that=
could potentially allow memory access outside the intended range resulting=
in loss of integrity.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-26380" target=3D= "_blank" rel=3D"noopener">CVE-2021-26380</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD--AMD Ryzen 3000 Series Mobile Processors w= ith Radeon Graphics</td>
<td>A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may a= llow an attacker to load registers repeatedly creating a race condition pot= entially leading to a loss of integrity.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-23826" target=3D= "_blank" rel=3D"noopener">CVE-2022-23826</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">KMX--Alien::FreeImage</td>
<td>Alien::FreeImage versions through 1.001 for Perl contains several vulne= rable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage = library from 2017, which has known vulnerabilities such as CVE-2015-0852 an=
d CVE-2025-65803. The library embeds other images libraries that also have = known vulnerabilities.</td>
<td>2026-05-11</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-4988" target=3D"= _blank" rel=3D"noopener">CVE-2022-4988</a></td>
<a href=3D"
https://freeimage.sourceforge.io/" target=3D"_blank" rel=3D"noop= ener">
https://freeimage.sourceforge.io/</a><br><a href=3D"
https://metacpan.= org/release/KMX/Alien-FreeImage-1.001/source/src/Source" target=3D"_blank" = rel=3D"noopener">
https://metacpan.org/release/KMX/Alien-FreeImage-1.001/sou= rce/src/Source</a><br><a href=3D"
https://nvd.nist.gov/vuln/detail/CVE-2015-= 0852" target=3D"_blank" rel=3D"noopener">
https://nvd.nist.gov/vuln/detail/C= VE-2015-0852</a><br><a href=3D"
https://nvd.nist.gov/vuln/detail/CVE-2025-65= 803" target=3D"_blank" rel=3D"noopener">
https://nvd.nist.gov/vuln/detail/CV= E-2025-65803</a><br><a href=3D"
https://github.com/kmx/alien-freeimage/issue= s/4" target=3D"_blank" rel=3D"noopener">
https://github.com/kmx/alien-freeim= age/issues/4</a><br><a href=3D"
https://github.com/kmx/alien-freeimage/issue= s/5" target=3D"_blank" rel=3D"noopener">
https://github.com/kmx/alien-freeim= age/issues/5</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">n/a--MK-Auth 23.01K4.9</td>
<td>An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows atta= ckers to execute arbitrary code via uploading a crafted PHP file.</td> <td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-27753" target=3D= "_blank" rel=3D"noopener">CVE-2023-27753</a></td>
<a href=3D"
https://github.com/yueslly/MKAUTH-RCE/blob/main/README.md" targe= t=3D"_blank" rel=3D"noopener">
https://github.com/yueslly/MKAUTH-RCE/blob/ma= in/README.md</a><br><a href=3D"
https://github.com/yueslly/MKAUTH-RCE" targe= t=3D"_blank" rel=3D"noopener">
https://github.com/yueslly/MKAUTH-RCE</a><br>= =C2=A0</td>
</tr>
<td class=3D"vendor-product">n/a--MK-Auth 23.01K4.9</td>
<td>An insecure direct object reference in MK-Auth 23.01K4.9 allows attacke=
rs to access and send support calls for other users via manipulation of the=
chamado parameter through a crafted GET request.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-30059" target=3D= "_blank" rel=3D"noopener">CVE-2023-30059</a></td>
<a href=3D"
https://github.com/yueslly/MKAUTH-IDOR" target=3D"_blank" rel=3D= "noopener">
https://github.com/yueslly/MKAUTH-IDOR</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 6000 Series Graphics = Products</td>
<td>Improper validation in Power Management Firmware (PMFW) may allow an at= tacker with privileges to pass malformed workload arguments when exporting = table data from SMU to DRAM potentially resulting in a loss of confidential= ity and/or availability.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-31309" target=3D= "_blank" rel=3D"noopener">CVE-2023-31309</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 5000 Series Mobile Proces= sors with Radeon Graphics</td>
<td>Improperly preserved integrity of hardware configuration state during a=
power save/restore operation in the AMD Secure Processor (ASP) could allow=
an attacker with the ability to write outside the trusted memory range (TM=
R) to change the execution flow of the Video Core Next (VCN) firmware poten= tially impacting confidentiality, integrity, or availability.</td> <td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-31316" target=3D= "_blank" rel=3D"noopener">CVE-2023-31316</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 6000 Series Graphics = Products</td>
<td>Improper restriction of operations within the bounds of a memory buffer=
in the AMD secure processer (ASP) could allow an attacker to read or write=
to protected memory potentially resulting in arbitrary code execution.</td=
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-31317" target=3D= "_blank" rel=3D"noopener">CVE-2023-31317</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Instinct MI300X</td>
<td>An out of bounds read in the remote management firmware could allow a p= rivileged attacker read a limited section of memory outside of established = bounds potentially resulting in loss of confidentiality or availability.</t=
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-21950" target=3D= "_blank" rel=3D"noopener">CVE-2024-21950</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD EPYC 4005 Series Processors</td=
<td>Improper Input Validation in the AMD RAID driver could allow an attacke=
r to point to an arbitrary memory location potentially resulting in privile=
ge escalation and arbitrary code execution.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-21962" target=3D= "_blank" rel=3D"noopener">CVE-2024-21962</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4016.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4016.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD EPYC Series 9004 Processors</td=
<td>Improper enforcement of the LFENCE serialization property may allow an = attacker to bypass speculation barriers and potentially disclose sensitive = information, potentially resulting in loss of confidentiality.</td> <td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-36315" target=3D= "_blank" rel=3D"noopener">CVE-2024-36315</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-3030.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-3030.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-4017.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 7000 Series Graphics = Products</td>
<td>Improper isolation of VCN-JPEG HW register space could allow a maliciou=
s Guest Virtual Machine (VM) or a process to perform unauthorized access to=
the register space of the JPEG cores assigned a victim VM/process, potenti= ally gaining arbitrary read/write access to the victim VM/process data.</td=
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-36323" target=3D= "_blank" rel=3D"noopener">CVE-2024-36323</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Radeon PRO V710</td>
<td>Improper isolation of GPU HW register space could allow a privileged at= tacker in malicious Guest Virtual Machine (VM) to perform unauthorized acce=
ss to specific victim range of GPU MMIO register space, potentially causing=
the host OS to reboot and creating a Denial of Service (DOS) condition.</t=
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-36332" target=3D= "_blank" rel=3D"noopener">CVE-2024-36332</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 5000 Series Graphics = Products</td>
<td>A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an=
attacker to achieve privilege escalation potentially resulting in arbitrar=
y code execution.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-36333" target=3D= "_blank" rel=3D"noopener">CVE-2024-36333</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 7000 Series Graphics = Products</td>
<td>Improper verification of cryptographic signature in the Radeon RGB tool=
could allow a malicious file placed in the installation directory to be ru=
n with elevated privileges potentially leading to arbitrary code execution.= </td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-36334" target=3D= "_blank" rel=3D"noopener">CVE-2024-36334</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD EPYC 4004</td>
<td>Improper input validation in the AMD OverDrive (AOD) System Management = Mode (SMM) module could allow a privileged attacker to perform an out-of-bo= unds read, potentially resulting in loss of confidentiality.</td> <td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-36345" target=3D= "_blank" rel=3D"noopener">CVE-2024-36345</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-3030.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-3030.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-4017.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Checkmk GmbH--Checkmk</td>
<td>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk=
<2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged us=
er able to create a Windows service whose name matches 'MySQL' or 'MariaDB'=
(or with write access to a binary referenced by such a service) to execute=
arbitrary code in the context of the Checkmk agent service, which typicall=
y runs as SYSTEM.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-47091" target=3D= "_blank" rel=3D"noopener">CVE-2024-47091</a></td>
<a href=3D"
https://checkmk.com/werk/19198" target=3D"_blank" rel=3D"noopene= r">
https://checkmk.com/werk/19198</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">n/a--Ardupilot</td>
<td>Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162= 058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of se= rvice via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor = component.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-48519" target=3D= "_blank" rel=3D"noopener">CVE-2024-48519</a></td>
<a href=3D"
https://github.com/ArduPilot/ardupilot/issues/27937" target=3D"_= blank" rel=3D"noopener">
https://github.com/ArduPilot/ardupilot/issues/27937= </a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">n/a--Ardupilot</td>
<td>Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e02= 3793133e49a035daf37c14433e484778 allows a local attacker to cause a denial =
of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp components.</td> <td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-51394" target=3D= "_blank" rel=3D"noopener">CVE-2024-51394</a></td>
<a href=3D"
https://github.com/ArduPilot/ardupilot/issues/28458" target=3D"_= blank" rel=3D"noopener">
https://github.com/ArduPilot/ardupilot/issues/28458= </a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">n/a--Ardupilot</td>
<td>Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e02= 3793133e49a035daf37c14433e484778 allows a local attacker to cause a denial =
of service via the AP_SmartAudio::loop, AP_SmartAudio, AP_SmartAudio.cpp co= mponents.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-51395" target=3D= "_blank" rel=3D"noopener">CVE-2024-51395</a></td>
<a href=3D"
https://github.com/ArduPilot/ardupilot/issues/28374" target=3D"_= blank" rel=3D"noopener">
https://github.com/ArduPilot/ardupilot/issues/28374= </a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">n/a--FMT-Firmware</td>
<td>Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contai=
n a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c= .</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-55045" target=3D= "_blank" rel=3D"noopener">CVE-2024-55045</a></td>
<a href=3D"
https://github.com/Firmament-Autopilot/FMT-Firmware/issues/133" = target=3D"_blank" rel=3D"noopener">
https://github.com/Firmament-Autopilot/F= MT-Firmware/issues/133</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
<td>An unchecked return value within the AMD Platform Management Framework = (PMF) could allow an attacker to read or modify an arbitrary address potent= ially resulting in loss of confidentiality, integrity, or availability.</td=
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-0028" target=3D"= _blank" rel=3D"noopener">CVE-2025-0028</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7040 Series Mobile Proces= sors with Radeon Graphics</td>
<td>Improper access control between the Joint Test Action Group (JTAG) and = Advanced Extensible Interface (AXI) could allow an attacker with physical a= ccess to read or overwrite the contents of cross-chip debug (XCD) registers=
potentially resulting in loss of data integrity or confidentiality.</td> <td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-0040" target=3D"= _blank" rel=3D"noopener">CVE-2025-0040</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen Al Max+</td>
<td>An out-of-bounds read in power management firmware by a malicious local=
attacker with low privileges could potentially lead to a partial loss of c= onfidentiality and availability.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-0044" target=3D"= _blank" rel=3D"noopener">CVE-2025-0044</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--Athlon 3000 Series Mobile Processor=
s with Radeon Graphics</td>
<td>Improper Input validation in the AMD Secure Processor (ASP) PCI driver = may allow a local attacker to create a buffer overflow condition, potential=
ly resulting in a crash or denial of service</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-0045" target=3D"= _blank" rel=3D"noopener">CVE-2025-0045</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br><a href=3D"
https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-3047.html" target= =3D"_blank" rel=3D"noopener">
https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-3047.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
<td>Due to a lack of user account state validation during authentication, l= ocked user accounts can be successfully authenticated using Magic Link or P= ass Key methods. This bypasses the intended security control that should pr= event access to accounts that have been locked. This vulnerability may allo=
w unauthorized access to applications and sensitive data associated with ac= counts that should have been restricted via the account lock mechanism. It = also undermines the effectiveness of the account lock mechanism intended to=
prevent further login attempts.</td>
<td>2026-05-11</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-10908" target=3D= "_blank" rel=3D"noopener">CVE-2025-10908</a></td>
<a href=3D"
https://security.docs.wso2.com/en/latest/security-announcements/= security-advisories/2026/WSO2-2025-4388/" target=3D"_blank" rel=3D"noopener= ">
https://security.docs.wso2.com/en/latest/security-announcements/security-= advisories/2026/WSO2-2025-4388/</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Siemens--Simcenter Femap</td>
<td>The affected applications contains a memory corruption vulnerability wh= ile parsing specially crafted IPT files. This could allow an attacker to ex= ecute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-2= 7389)</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12659" target=3D= "_blank" rel=3D"noopener">CVE-2025-12659</a></td>
<a href=3D"
https://cert-portal.siemens.com/productcert/html/ssa-870926.html=
" target=3D"_blank" rel=3D"noopener">
https://cert-portal.siemens.com/produc= tcert/html/ssa-870926.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">silabs.com--Simplicity SDK</td>
<td>* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices=
are not sufficiently random and will eventually repeat. * KSU keys using S= YMCRYPTO will be impacted by this vulnerability.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14972" target=3D= "_blank" rel=3D"noopener">CVE-2025-14972</a></td>
<a href=3D"
https://community.silabs.com/068Vm00000M3cAX" target=3D"_blank" = rel=3D"noopener">
https://community.silabs.com/068Vm00000M3cAX</a><br>=C2=A0= </td>
</tr>
<td class=3D"vendor-product">n/a--Intel(R) Ethernet 800 series</td>
<td>Use after free for some Linux kernel driver for the Intel(R) Ethernet 8=
00 series before version 2.3.14 within Ring 0: Kernel may allow a denial of=
service. Unprivileged software adversary with an authenticated user combin=
ed with a low complexity attack may enable denial of service. This result m=
ay potentially occur via local access when attack requirements are present = without special internal knowledge and requires no user interaction. The po= tential vulnerability may impact the confidentiality (none), integrity (non=
e) and availability (high) of the vulnerable system, resulting in subsequen=
t system confidentiality (none), integrity (none) and availability (high) i= mpacts.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27723" target=3D= "_blank" rel=3D"noopener">CVE-2025-27723</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01426.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01426.html</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
<td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows a symlink attack. If a malicious graphics package containing symlinks i=
s uploaded, the web server follows the supplied links when serving content.=
No mechanisms to restrict those link targets to a specific area of the fil= esystem is enabled. This allows an attacker to retrieve arbitrary files fro=
m the device.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27850" target=3D= "_blank" rel=3D"noopener">CVE-2025-27850</a></td>
<a href=3D"
https://garmin.com" target=3D"_blank" rel=3D"noopener">
https://g= armin.com</a><br><a href=3D"
https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">
https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
<td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows a cross-site origin WebSocket hijacking attack. Among other uses, the W=
DU utilizes WebSockets to control settings, including administrative settin= gs. This allows a network attacker to take full control of a WDU. To initia=
te an exploit of this vulnerability, the victim must (1) be utilizing a web=
browser on a multihomed host that has local interfaces on the Garmin Marin=
e Network as well as another network, and (2) access a malicious third part=
y website created by the attacker.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27851" target=3D= "_blank" rel=3D"noopener">CVE-2025-27851</a></td>
<a href=3D"
https://garmin.com" target=3D"_blank" rel=3D"noopener">
https://g= armin.com</a><br><a href=3D"
https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">
https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
<td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows a reflected cross site scripting (XSS) attack. This allows an attacker =
on the local network segment to execute arbitrary JavaScript code within th=
e context of the WDU webpage. Full administrator level access to the device=
is possible. To initiate an exploit of this vulnerability, the victim must=
execute two actions: (1) view a specific URL served by the WDU, and (2) cl= ick an element on the rendered page.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27852" target=3D= "_blank" rel=3D"noopener">CVE-2025-27852</a></td>
<a href=3D"
https://garmin.com" target=3D"_blank" rel=3D"noopener">
https://g= armin.com</a><br><a href=3D"
https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">
https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
<td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows its authentication to be bypassed. The WDU web site only performs authe= ntication with the client within the client's browser. The WebSockets used =
to communicate with the WDU server do not enforce any authentication. An at= tacker may bypass all authentication mechanisms by directly utilizing the r= emote APIs available on the websocket.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-27853" target=3D= "_blank" rel=3D"noopener">CVE-2025-27853</a></td>
<a href=3D"
https://garmin.com" target=3D"_blank" rel=3D"noopener">
https://g= armin.com</a><br><a href=3D"
https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">
https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">ThreadReadButtons--ThreadReadButtons</td> <td>striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in fun= ction ThreadReadButtons.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-28343" target=3D= "_blank" rel=3D"noopener">CVE-2025-28343</a></td>
<a href=3D"
https://github.com/striso/striso-control-firmware/issues/5" targ= et=3D"_blank" rel=3D"noopener">
https://github.com/striso/striso-control-fir= mware/issues/5</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AuxJack--AuxJack</td>
<td>striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in fun= ction AuxJack.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-28344" target=3D= "_blank" rel=3D"noopener">CVE-2025-28344</a></td>
<a href=3D"
https://github.com/striso/striso-control-firmware/issues/6" targ= et=3D"_blank" rel=3D"noopener">
https://github.com/striso/striso-control-fir= mware/issues/6</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">NXP[.]com--NXP</td>
<td>NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v= 17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_pa=
ra parameter in the woal_init_module_param function.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-29338" target=3D= "_blank" rel=3D"noopener">CVE-2025-29338</a></td>
<a href=3D"
https://www.nxp.com/docs/en/release-note/RN00104.pdf" target=3D"= _blank" rel=3D"noopener">
https://www.nxp.com/docs/en/release-note/RN00104.p= df</a><br><a href=3D"
https://github.com/masjadaan/CVE-2025-29338" target=3D= "_blank" rel=3D"noopener">
https://github.com/masjadaan/CVE-2025-29338</a><b= r>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
<td>An out of bounds write within the AMD Platform Management Framework (PM=
F) could allow an attacker to execute arbitrary code at an elevated privile=
ge level potentially leading to loss of confidentiality integrity, or avail= ability.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-29935" target=3D= "_blank" rel=3D"noopener">CVE-2025-29935</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
<td>Improper input validation within the AMD Platform Management Framework = (PMF) could allow an attacker to unmap arbitrary memory pages potentially i= mpacting integrity and availability, or allowing privilege escalation resul= ting in loss of confidentiality.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-29936" target=3D= "_blank" rel=3D"noopener">CVE-2025-29936</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
<td>An out of bounds read within the AMD Platform Management Framework (PMF=
) could allow an attacker to trigger a read of an arbitrary memory location=
potentially resulting in loss of availability or confidentiality.</td> <td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-29937" target=3D= "_blank" rel=3D"noopener">CVE-2025-29937</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
<td>An unchecked return value within the AMD Platform Management Framework = (PMF) could allow an attacker to write to an arbitrary memory address resul= ting in denial of service or arbitrary code execution.</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-29938" target=3D= "_blank" rel=3D"noopener">CVE-2025-29938</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">AMD[.]com--AMD Ryzen 4000 Series Mobile Proces= sors with Radeon Graphics (formerly codenamed "Renoir")</td>
<td>A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can=
allow a local attacker to write out of bounds, potentially resulting in de= nial of service or crash</td>
<td>2026-05-15</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-29944" target=3D= "_blank" rel=3D"noopener">CVE-2025-29944</a></td>
<a href=3D"
https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">
https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
<td>AutoGPT is a platform that allows users to create, deploy, and manage c= ontinuous artificial intelligence agents that automate complex workflows. I=
n AutoGPT, the execution process is recorded to the console (stdout/stderr)=
, and deployed in container mode, which is automatically captured by Docker=
and stored as "container logs". However, prior to 0.6.32, there is no limi=
t on the log size when the container is deployed. When the number of user a= ccesses is too large, the log on the server disk will be too large, causing=
disk resource exhaustion and eventually causing DoS. autogpt-platform-beta= -v0.6.32 fixes the issue.</td>
<td>2026-05-13</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-32425" target=3D= "_blank" rel=3D"noopener">CVE-2025-32425</a></td>
<a href=3D"
https://github.com/Significant-Gravitas/AutoGPT/security/advisor= ies/GHSA-vw3v-whvp-33v5" target=3D"_blank" rel=3D"noopener">
https://github.= com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-vw3v-whvp-33v5</a= ><br><a href=3D"
https://github.com/Significant-Gravitas/AutoGPT/commit/57a0= 6f70883ce6be18738c6ae8bb41085c71e266" target=3D"_blank" rel=3D"noopener">ht= tps://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be18738c= 6ae8bb41085c71e266</a><br><a href=3D"
https://github.com/Significant-Gravita= s/AutoGPT/blob/62361ccc48327b3124549543b45d933d16f622d2/autogpt_platform/au= togpt_libs/autogpt_libs/logging/config.py#L83-L102" target=3D"_blank" rel= =3D"noopener">
https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc= 48327b3124549543b45d933d16f622d2/autogpt_platform/autogpt_libs/autogpt_libs= /logging/config.py#L83-L102</a><br><a href=3D"
https://github.com/Significan= t-Gravitas/AutoGPT/blob/62361ccc48327b3124549543b45d933d16f622d2/autogpt_pl= atform/docker-compose.platform.yml#L102-L142" target=3D"_blank" rel=3D"noop= ener">
https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b31= 24549543b45d933d16f622d2/autogpt_platform/docker-compose.platform.yml#L102-= L142</a><br>=C2=A0</td>
</tr>
<td class=3D"vendor-product">Intel[.]com--Intel(R) Server Firmware Update U= tility Software</td>
<td>Uncontrolled search path for some Intel(R) Server Firmware Update Utili=
ty Software before version 16.0.12. within Ring 3: User Applications may al= low an escalation of privilege. System software adversary with an authentic= ated user combined with a high complexity attack may enable escalation of p= rivilege. This result may potentially occur via local access when attack re= quirements are present without special internal knowledge and requires acti=
ve user interaction. The potential vulnerability may impact the confidentia= lity (high), integrity (high) and availability (high) of the vulnerable sys= tem, resulting in subsequent system confidentiality (none), integrity (none=
) and availability (none) impacts.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-35969" target=3D= "_blank" rel=3D"noopener">CVE-2025-35969</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01410.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01410.html</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Intel[.]com--Intel(R) Processors</td>
<td>Exposure of sensitive information caused by shared microarchitectural p= redictor state that influences transient execution for some Intel(R) Proces= sors within VMX non-root (guest) operation may allow an information disclos= ure. Unprivileged software adversary with an authenticated user combined wi=
th a high complexity attack may enable data exposure. This result may poten= tially occur via local access when attack requirements are present without = special internal knowledge and requires no user interaction. The potential = vulnerability may impact the confidentiality (high), integrity (none) and a= vailability (none) of the vulnerable system, resulting in subsequent system=
confidentiality (high), integrity (none) and availability (none) impacts.<=
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-35979" target=3D= "_blank" rel=3D"noopener">CVE-2025-35979</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01420.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01420.html</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Intel[.]com--Intel Endpoint Management Assista=
nt (EMA) software</td>
<td>Improper input validation for some Intel Endpoint Management Assistant = (EMA) software before version 1.14.5 within Ring 3: User Applications may a= llow an escalation of privilege. Unprivileged software adversary with an un= authenticated user combined with a low complexity attack may enable escalat= ion of privilege. This result may potentially occur via adjacent access whe=
n attack requirements are not present without special internal knowledge an=
d requires no user interaction. The potential vulnerability may impact the = confidentiality (high), integrity (high) and availability (high) of the vul= nerable system, resulting in subsequent system confidentiality (none), inte= grity (none) and availability (none) impacts.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-35990" target=3D= "_blank" rel=3D"noopener">CVE-2025-35990</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01434.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01434.html</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Intel[.]com--Intel platforms</td>
<td>Improper initialization in the UEFI firmware for some Intel platforms w= ithin Ring 0: Bare Metal OS may allow an information disclosure. System sof= tware adversary with a privileged user combined with a high complexity atta=
ck may enable data exposure. This result may potentially occur via local ac= cess when attack requirements are present without special internal knowledg=
e and requires no user interaction. The potential vulnerability may impact = the confidentiality (high), integrity (none) and availability (none) of the=
vulnerable system, resulting in subsequent system confidentiality (none), = integrity (none) and availability (none) impacts.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-35991" target=3D= "_blank" rel=3D"noopener">CVE-2025-35991</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01413.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01413.html</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Intel[.]com--Display Virtualization for Window=
s OS driver software</td>
<td>Improper buffer restrictions for some Display Virtualization for Window=
s OS driver software within Ring 2: Device Drivers may allow a denial of se= rvice. Unprivileged software adversary with an authenticated user combined = with a low complexity attack may enable denial of service. This result may = potentially occur via local access when attack requirements are not present=
without special internal knowledge and requires no user interaction. The p= otential vulnerability may impact the confidentiality (none), integrity (no= ne) and availability (high) of the vulnerable system, resulting in subseque=
nt system confidentiality (none), integrity (none) and availability (none) = impacts.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-36510" target=3D= "_blank" rel=3D"noopener">CVE-2025-36510</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01430.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01430.html</a><br>=C2=A0</t=
</tr>
<td class=3D"vendor-product">Intel[.]com--AI Playground software</td> <td>Uncontrolled search path for some AI Playground software before version=
3.0.0 alpha within Ring 3: User Applications may allow an escalation of pr= ivilege. Unprivileged software adversary with an authenticated user combine=
d with a high complexity attack may enable escalation of privilege. This re= sult may potentially occur via local access when attack requirements are pr= esent without special internal knowledge and requires active user interacti= on. The potential vulnerability may impact the confidentiality (high), inte= grity (high) and availability (high) of the vulnerable system, resulting in=
subsequent system confidentiality (none), integrity (none) and availabilit=
y (none) impacts.</td>
<td>2026-05-12</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-36515" target=3D= "_blank" rel=3D"noopener">CVE-2025-36515</a></td>
<a href=3D"
https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01438.html" target=3D"_blank" rel=3D"noopener">
https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01438.html</a><br>=C2=A0</t=
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/417e991" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using GovDelivery Com= munications Cloud, on behalf of: Cybersecurity and Infrastructure Security = Agency =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://subscriberhelp.granicu= s.com/" target=3D"_blank" rel=3D"noopener"><img src=3D"
https://content.govd= elivery.com/images/govd-logo-dark.png" border=3D"0" alt=3D"GovDelivery logo=
" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/0101019e3ce7a975-0= 4279e1d-c4a4-4390-ae74-eaa897475d71-000000/tlm_SNsaQSB3na98HZNrFGM9LSmUCmnc= knzIX0Njzlg=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============7146585765089518506==--
--===============8728627738968554007==--