• Vulnerability Summary for the Week of May 11, 2026

    From CISA@cisa@messages.cisa.gov to cisa@toolazy.synchro.net on Mon May 18 21:04:35 2026
    --===============8728627738968554007==
    Content-Type: multipart/alternative; boundary="===============7146585765089518506=="
    MIME-Version: 1.0

    --===============7146585765089518506==
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    Cybersecurity and Infrastructure Security Agency (CISA)

    You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrast= ructure Security Agency. This information has recently been updated and is = now available.

    The CISA Vulnerability Bulletin provides a summary of new vulnerabilities t= hat have been recorded in the past week. In some cases, the vulnerabilities=
    in the bulletin may not yet have assigned CVSS scores.

    Vulnerabilities are based on the=C2=A0Common Vulnerabilities and Exposures =
    [ https://www.cve.org/ ]=C2=A0(CVE) vulnerability naming standard and are o= rganized according to severity, determined by the=C2=A0Common Vulnerability=
    Scoring System [ https://www.cve.org/about/relatedefforts ]=C2=A0(CVSS) st= andard. The division of high, medium, and low severities correspond to the = following scores:


    * *High*: vulnerabilities with a CVSS base score of 7.0=E2=80=9310.0=20
    * *Medium*: vulnerabilities with a CVSS base score of 4.0=E2=80=936.9=20
    * *Low*: vulnerabilities with a CVSS base score of 0.0=E2=80=933.9=20

    Entries may include additional information provided by organizations and ef= forts sponsored by CISA. This information may include identifying informati= on, values, definitions, and related links. Patch information is provided w= hen available. Please note that some of the information in the bulletin is = compiled from external, open-source reports and is not a direct result of C= ISA analysis.

    =C2=A0

    Vulnerability Summary for the Week of May 11, 2026 [ https://www.cisa.gov/n= ews-events/bulletins/sb26-138 ] 05/18/2026 05:00 PM EDT=20

    High Vulnerabilities

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info a= cl--ACL Analytics ACL Analytics versions 11.x through 13.0.0.579 contain an=
    arbitrary code execution vulnerability that allows attackers to execute ar= bitrary commands by leveraging the EXECUTE function. Attackers can use bits= admin to download malicious PowerShell scripts and execute them with system=
    privileges to establish reverse shells and gain complete system control. 2= 026-05-17 9.8 CVE-2018-25320 [ https://www.cve.org/CVERecord?id=3DCVE-2018-= 25320 ] ExploitDB-44281 [ https://www.exploit-db.com/exploits/44281 ]
    Official Product Homepage [ https://www.acl.com ]
    Product Reference [ https://www.acl.com/products/acl-analytics/ ]
    VulnCheck Advisory: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Executio=
    n [ https://www.vulncheck.com/advisories/acl-analytics-11-x-arbitrary-code-= execution ]
    =C2=A0 gitbucket--GitBucket GitBucket 4.23.1 contains an unauthenticated re= mote code execution vulnerability that allows attackers to execute arbitrar=
    y commands by exploiting weak secret token generation and insecure file upl= oad functionality. Attackers can brute-force the Blowfish encryption key, u= pload a malicious JAR plugin via the git-lfs endpoint, and execute system c= ommands through an exposed exploit endpoint. 2026-05-17 9.8 CVE-2018-25332 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2018-25332 ] ExploitDB-44668 [ htt= ps://www.exploit-db.com/exploits/44668 ]
    Official Product Homepage [ https://security.szurek.pl/ ]
    Product Reference [ https://github.com/gitbucket/gitbucket ]
    VulnCheck Advisory: GitBucket 4.23.1 Unauthenticated Remote Code Execution =
    [ https://www.vulncheck.com/advisories/gitbucket-unauthenticated-remote-cod= e-execution ]
    =C2=A0 peugeot-music-plugin--Peugeot Music WordPress Plugin Peugeot Music 1=
    .0 contains an arbitrary file upload vulnerability that allows unauthentica= ted attackers to upload malicious files by sending POST requests to the upl= oad.php endpoint. Attackers can upload files with arbitrary extensions by m= anipulating the 'name' parameter to execute code from the uploads directory=
    . 2026-05-17 9.8 CVE-2018-25335 [ https://www.cve.org/CVERecord?id=3DCVE-20= 18-25335 ] ExploitDB-44737 [ https://www.exploit-db.com/exploits/44737 ] VulnCheck Advisory: WordPress Plugin Peugeot Music 1.0 Arbitrary File Uploa=
    d [ https://www.vulncheck.com/advisories/wordpress-plugin-peugeot-music-arb= itrary-file-upload ]
    =C2=A0 Paiement--Ecommerce Systempay Ecommerce Systempay 1.0 contains a wea=
    k cryptographic implementation vulnerability that allows attackers to brute=
    force the 16-character production secret key used for payment signature ge= neration. Attackers can extract payment form data and signatures from POST = requests to the payment endpoint, then use SHA1 hash comparison to iterativ= ely test key candidates until discovering the correct production key, enabl= ing them to forge valid payment signatures and manipulate transaction amoun= ts. 2026-05-13 9.8 CVE-2020-37168 [ https://www.cve.org/CVERecord?id=3DCVE-= 2020-37168 ] ExploitDB-48017 [ https://www.exploit-db.com/exploits/48017 ] Official Product Homepage [ https://paiement.systempay.fr/doc/fr-FR/ ]
    Product Reference [ https://paiement.systempay.fr/doc/fr-FR/module-de-paiem= ent-gratuit/ ]
    VulnCheck Advisory: Ecommerce Systempay 1.0 Production Key Brute Force [ ht= tps://www.vulncheck.com/advisories/ecommerce-systempay-production-key-brute= -force ]
    =C2=A0 Yerootech--iDS6 DSSPro Digital Signage System iDS6 DSSPro Digital Si= gnage System 6.2 contains a CAPTCHA security bypass vulnerability that allo=
    ws attackers to bypass authentication by requesting the autoLoginVerifyCode=
    object. Attackers can retrieve valid CAPTCHA codes via the login endpoint = and use them to perform brute-force attacks against user accounts. 2026-05-=
    16 9.8 CVE-2020-37228 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37228 ]=
    ExploitDB-48991 [ https://www.exploit-db.com/exploits/48991 ]
    Vulnerability Advisory [ https://www.zeroscience.mk/en/vulnerabilities/ZSL-= 2020-5607.php ]
    Official Product Homepage [ http://www.yerootech.com ]
    VulnCheck Advisory: iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security=
    Bypass [ https://www.vulncheck.com/advisories/ids6-dsspro-digital-signage-= system-captcha-security-bypass ]
    =C2=A0 Gegl--libbabl libbabl 0.1.62 contains a broken double free detection=
    vulnerability that allows attackers to bypass memory safety checks by expl= oiting signature overwriting in freed chunks. Attackers can call babl_free(=
    ) twice on the same pointer without triggering detection, as libc's malloc = metadata overwrites babl's signature field upon freeing, enabling potential=
    memory corruption and code execution. 2026-05-16 9.8 CVE-2020-37239 [ http= s://www.cve.org/CVERecord?id=3DCVE-2020-37239 ] ExploitDB-49259 [ https://w= ww.exploit-db.com/exploits/49259 ]
    Official Product Homepage [ https://www.gegl.org ]
    Product Reference [ https://www.gegl.org/babl/ ]
    VulnCheck Advisory: libbabl 0.1.62 Broken Double Free Detection Memory Safe=
    ty [ https://www.vulncheck.com/advisories/libbabl-broken-double-free-detect= ion-memory-safety ]
    =C2=A0 Jsonpickle--python jsonpickle python jsonpickle 2.0.0 contains a rem= ote code execution vulnerability that allows attackers to execute arbitrary=
    Python commands by deserializing malicious JSON payloads containing py/rep=
    r objects. Attackers can craft JSON strings with py/repr directives that in= voke the eval function during deserialization to execute system commands an=
    d arbitrary code. 2026-05-16 9.8 CVE-2021-47952 [ https://www.cve.org/CVERe= cord?id=3DCVE-2021-47952 ] ExploitDB-49585 [ https://www.exploit-db.com/exp= loits/49585 ]
    Official Product Homepage [ https://jsonpickle.github.io ]
    Product Reference [ https://github.com/jsonpickle/jsonpickle ]
    VulnCheck Advisory: python jsonpickle 2.0.0 Remote Code Execution via py/re=
    pr [ https://www.vulncheck.com/advisories/python-jsonpickle-remote-code-exe= cution-via-py-repr ]
    =C2=A0 wp-super-edit--WP Super Edit WordPress Plugin WP Super Edit 2.5.4 an=
    d earlier contains an unrestricted file upload vulnerability in the FCKedit=
    or component that allows attackers to upload dangerous file types without v= alidation. Attackers can upload arbitrary files through the filemanager upl= oad endpoint to achieve remote code execution and complete system compromis=
    e. 2026-05-15 9.8 CVE-2021-47965 [ https://www.cve.org/CVERecord?id=3DCVE-2= 021-47965 ] ExploitDB-49839 [ https://www.exploit-db.com/exploits/49839 ] Official Product Homepage [ https://wordpress.org ]
    Product Reference [ https://wordpress.org/plugins/wp-super-edit/ ]
    VulnCheck Advisory: WordPress Plugin WP Super Edit 2.5.4 Unrestricted File = Upload [ https://www.vulncheck.com/advisories/wordpress-plugin-wp-super-edi= t-unrestricted-file-upload ]
    =C2=A0 Akilli Commerce Software Technologies Ltd. Co.--E-Commerce Website I= mproper neutralization of special elements used in an SQL command ('SQL inj= ection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-= Commerce Website allows Blind SQL Injection. This issue affects E-Commerce = Website: before 4.5.001. 2026-05-14 9.8 CVE-2025-11024 [ https://www.cve.or= g/CVERecord?id=3DCVE-2025-11024 ] https://siberguvenlik.gov.tr/guvenlik-bil= dirimleri/detay/tr-26-0222
    =C2=A0 Hitachi Vantara--Pentaho Data Integration and Analytics Hitachi Vant= ara Pentaho Data Integration & Analytics of all versions contain a JDBC dri= ver for H2 databases which is vulnerable to external script execution when =
    a new connection is created by a=C2=A0data source administrator. 2026-05-13=
    9.1 CVE-2025-11159 [ https://www.cve.org/CVERecord?id=3DCVE-2025-11159 ] h= ttps://support.pentaho.com/hc/en-us/articles/39954640408077--Resolved-Hitac= hi-Vantara-Pentaho-Data-Integration-Analytics-Dependency-on-Vulnerable-Thir= d-Party-Component-Versions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2025-1= 1159
    =C2=A0 alloksoft--Fast AVI MPEG Splitter Allok Fast AVI MPEG Splitter 1.2 c= ontains a stack based buffer overflow vulnerability that allows local attac= kers to execute arbitrary code by supplying a malicious license name string=
    . Attackers can craft a payload with 780 bytes of junk data followed by str= uctured shellcode and place it in the License Name field to trigger the ove= rflow and execute code with application privileges. 2026-05-17 8.4 CVE-2018= -25322 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25322 ] ExploitDB-4434=
    1 [ https://www.exploit-db.com/exploits/44341 ]
    Official Product Homepage [ http://www.alloksoft.com ]
    Product Reference [ http://www.alloksoft.com/allok_vconverter.exe ]
    VulnCheck Advisory: Allok Fast AVI MPEG Splitter 1.2 Stack Based Buffer Ove= rflow [ https://www.vulncheck.com/advisories/allok-fast-avi-mpeg-splitter-s= tack-based-buffer-overflow ]
    =C2=A0 Alloksoft--Allok AVI DivX MPEG to DVD Converter Allok AVI DivX MPEG =
    to DVD Converter 2.6.1217 contains a structured exception handler buffer ov= erflow vulnerability that allows local attackers to execute arbitrary code =
    by supplying a malicious payload. Attackers can craft a text file with a sp= ecially crafted buffer containing shellcode and SEH chain overwrite values,=
    then paste the contents into the License Name field to trigger code execut= ion. 2026-05-17 8.4 CVE-2018-25323 [ https://www.cve.org/CVERecord?id=3DCVE= -2018-25323 ] ExploitDB-44363 [ https://www.exploit-db.com/exploits/44363 ] VulnCheck Advisory: Allok AVI DivX MPEG to DVD Converter 2.6.1217 Buffer Ov= erflow SEH [ https://www.vulncheck.com/advisories/allok-avi-divx-mpeg-to-dv= d-converter-buffer-overflow-seh ]
    =C2=A0 vxsearch--VX Search VX Search 10.6.18 contains a local buffer overfl=
    ow vulnerability that allows attackers to overwrite the instruction pointer=
    by supplying an oversized string in the directory field. Attackers can cra=
    ft a malicious input file containing 271 bytes of junk data followed by a r= eturn address to execute arbitrary code with application privileges. 2026-0= 5-17 8.4 CVE-2018-25328 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25328=
    ] ExploitDB-44494 [ https://www.exploit-db.com/exploits/44494 ]
    Official Product Homepage [ https://www.7elements.co.uk ]
    Official Product Homepage [ http://www.vxsearch.com ]
    VulnCheck Advisory: VX Search 10.6.18 Local Buffer Overflow via Directory F= ield [ https://www.vulncheck.com/advisories/vx-search-local-buffer-overflow= -via-directory-field ]
    =C2=A0 Joomlaextensions--Joomla! extension EkRishta Joomla! extension EkRis= hta 2.10 contains persistent cross-site scripting and SQL injection vulnera= bilities that allow attackers to inject malicious code through profile fiel=
    ds and POST parameters. Attackers can inject script payloads in profile inf= ormation fields like Address that execute when users visit the profile, or = submit SQL injection payloads via the phone_no parameter to the user_settin=
    g endpoint to manipulate database queries. 2026-05-17 8.2 CVE-2018-25330 [ = https://www.cve.org/CVERecord?id=3DCVE-2018-25330 ] ExploitDB-44660 [ https= ://www.exploit-db.com/exploits/44660 ]
    Official Product Homepage [ https://www.joomlaextensions.co.in/ ]
    Product Reference [ https://extensions.joomla.org/extensions/extension/livi= ng/dating-a-relationships/ek-rishta/ ]
    VulnCheck Advisory: Joomla! EkRishta 2.10 Persistent XSS and SQL Injection =
    [ https://www.vulncheck.com/advisories/joomla-ekrishta-persistent-xss-and-s= ql-injection ]
    =C2=A0 nordex-online--N149 Wind Turbine Web Server Nordex N149/4.0-4.5 Wind=
    Turbine Web Server 4.0 contains an SQL injection vulnerability that allows=
    unauthenticated attackers to execute arbitrary SQL queries by injecting ma= licious code through the login parameter in login.php. Attackers can submit=
    crafted POST requests with SQL injection payloads in the login field to ex= tract sensitive database information and bypass authentication mechanisms. = 2026-05-17 8.2 CVE-2018-25333 [ https://www.cve.org/CVERecord?id=3DCVE-2018= -25333 ] ExploitDB-44684 [ https://www.exploit-db.com/exploits/44684 ]
    Official Product Homepage [ http://www.nordex-online.com ]
    VulnCheck Advisory: Nordex N149/4.0-4.5 Wind Turbine Web Server SQL Injecti=
    on [ https://www.vulncheck.com/advisories/nordex-n149-wind-turbine-web-serv= er-sql-injection ]
    =C2=A0 Bylancer--Zechat Zechat 1.5 contains a SQL injection vulnerability i=
    n the hashtag parameter that allows unauthenticated attackers to extract da= tabase information using union-based techniques. Attackers can exploit the = hashtag parameter with union-based payloads to retrieve table and column na= mes. 2026-05-17 8.2 CVE-2018-25338 [ https://www.cve.org/CVERecord?id=3DCVE= -2018-25338 ] ExploitDB-44685 [ https://www.exploit-db.com/exploits/44685 ] Official Product Homepage [ https://bylancer.com ]
    VulnCheck Advisory: Zechat 1.5 SQL Injection via hashtag parameter [ https:= //www.vulncheck.com/advisories/zechat-sql-injection-via-hashtag-parameter ] =C2=A0 Bylancer--Zechat Zechat 1.5 contains a SQL injection vulnerability i=
    n the v parameter that allows unauthenticated attackers to extract database=
    information using time-based blind techniques. Attackers can exploit the v=
    parameter with sleep-based blind injection to confirm vulnerability and ex= tract data. 2026-05-17 8.2 CVE-2018-25339 [ https://www.cve.org/CVERecord?i= d=3DCVE-2018-25339 ] ExploitDB-44685 [ https://www.exploit-db.com/exploits/= 44685 ]
    Official Product Homepage [ https://bylancer.com ]
    VulnCheck Advisory: Zechat 1.5 SQL Injection via v parameter (time-based bl= ind) [ https://www.vulncheck.com/advisories/zechat-sql-injection-via-v-para= meter-time-based-blind ]
    =C2=A0 Hdwplayer--com_hdwplayer Joomla com_hdwplayer 4.2 contains an SQL in= jection vulnerability in the search.php file that allows unauthenticated at= tackers to execute arbitrary SQL queries by injecting malicious code throug=
    h the hdwplayersearch parameter. Attackers can submit POST requests with cr= afted SQL payloads in the hdwplayersearch parameter to extract sensitive da= tabase information from the hdwplayer_videos table. 2026-05-13 8.2 CVE-2020= -37218 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37218 ] ExploitDB-4824=
    2 [ https://www.exploit-db.com/exploits/48242 ]
    Official Product Homepage [ https://www.hdwplayer.com/ ]
    Product Reference [ https://www.hdwplayer.com/download/ ]
    VulnCheck Advisory: Joomla com_hdwplayer 4.2 SQL Injection via search.php [=
    https://www.vulncheck.com/advisories/joomla-com-hdwplayer-sql-injection-vi= a-search-php ]
    =C2=A0 Drive-software--Atomic Alarm Clock Atomic Alarm Clock 6.3 contains a=
    stack overflow vulnerability that allows local attackers to execute arbitr= ary code by supplying a malicious string to the display name textbox in the=
    Time Zones Clock configuration. Attackers can craft a buffer with structur=
    ed exception handling overwrite and encoded shellcode to bypass SafeSEH pro= tections and execute arbitrary commands with application privileges. 2026-0= 5-13 8.4 CVE-2020-37221 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37221=
    ] ExploitDB-48346 [ https://www.exploit-db.com/exploits/48346 ]
    VulnCheck Advisory: Atomic Alarm Clock 6.3 Stack Overflow via SEH Unicode [=
    https://www.vulncheck.com/advisories/atomic-alarm-clock-stack-overflow-via= -seh-unicode ]
    =C2=A0 Heliossolutions--HS Brand Logo Slider HS Brand Logo Slider 2.1 conta= ins an unrestricted file upload vulnerability that allows authenticated use=
    rs to bypass client-side file extension validation by uploading arbitrary f= iles. Attackers can intercept upload requests to the logoupload parameter i=
    n the admin interface and rename files to executable extensions .php to ach= ieve remote code execution. 2026-05-16 8.8 CVE-2020-37227 [ https://www.cve= .org/CVERecord?id=3DCVE-2020-37227 ] ExploitDB-48913 [ https://www.exploit-= db.com/exploits/48913 ]
    Official Product Homepage [ https://www.heliossolutions.co/ ]
    Product Reference [ https://ms.wordpress.org/plugins/hs-brand-logo-slider/ ] VulnCheck Advisory: WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted = File Upload [ https://www.vulncheck.com/advisories/wordpress-plugin-hs-bran= d-logo-slider-unrestricted-file-upload ]
    =C2=A0 Supsystic--Ultimate Maps Supsystic Ultimate Maps 1.1.12 contains an = SQL injection vulnerability that allows unauthenticated attackers to execut=
    e arbitrary SQL queries by injecting malicious code through the 'sidx' GET = parameter. Attackers can send crafted requests to the getListForTbl action = with boolean-based blind or time-based blind SQL injection payloads to extr= act sensitive database information. 2026-05-16 8.2 CVE-2020-37242 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2020-37242 ] ExploitDB-49532 [ https://www.= exploit-db.com/exploits/49532 ]
    Official Product Homepage [ https://supsystic.com/ ]
    Product Reference [ https://downloads.wordpress.org/plugin/ultimate-maps-by= -supsystic.1.1.12.zip ]
    VulnCheck Advisory: WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Inj= ection via sidx [ https://www.vulncheck.com/advisories/wordpress-plugin-sup= systic-ultimate-maps-sql-injection-via-sidx ]
    =C2=A0 Supsystic--Pricing Table Supsystic Pricing Table 1.8.7 contains an S=
    QL injection vulnerability in the 'sidx' GET parameter that allows unauthen= ticated attackers to execute arbitrary SQL queries through the getListForTb=
    l action. The plugin also contains stored cross-site scripting vulnerabilit= ies in the 'Edit name' and 'Edit HTML' fields that execute malicious script=
    s when viewing pricing tables. 2026-05-16 8.2 CVE-2020-37243 [ https://www.= cve.org/CVERecord?id=3DCVE-2020-37243 ] ExploitDB-49533 [ https://www.explo= it-db.com/exploits/49533 ]
    Official Product Homepage [ https://supsystic.com/ ]
    Product Reference [ https://downloads.wordpress.org/plugin/pricing-table-by= -supsystic.1.8.7.zip ]
    VulnCheck Advisory: WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Inje= ction XSS [ https://www.vulncheck.com/advisories/wordpress-plugin-supsystic= -pricing-table-sql-injection-xss ]
    =C2=A0 Supsystic--Membership Supsystic Membership 1.4.7 contains an SQL inj= ection vulnerability that allows unauthenticated attackers to execute arbit= rary SQL queries by injecting malicious code through the 'search' and 'sidx=
    ' parameters. Attackers can send GET requests to the badges module with cra= fted payloads to extract sensitive database information using time-based bl= ind or UNION-based SQL injection techniques. 2026-05-16 8.2 CVE-2020-37244 =
    [ https://www.cve.org/CVERecord?id=3DCVE-2020-37244 ] ExploitDB-49540 [ htt= ps://www.exploit-db.com/exploits/49540 ]
    Official Product Homepage [ https://supsystic.com/ ]
    Product Reference [ https://downloads.wordpress.org/plugin/membership-by-su= psystic.1.4.7.zip ]
    VulnCheck Advisory: WordPress Plugin Supsystic Membership 1.4.7 SQL Injecti=
    on via sidx [ https://www.vulncheck.com/advisories/wordpress-plugin-supsyst= ic-membership-sql-injection-via-sidx ]
    =C2=A0 LayerBB--LayerBB LayerBB 1.1.4 contains an SQL injection vulnerabili=
    ty that allows unauthenticated attackers to manipulate database queries by = injecting SQL code through the search_query parameter. Attackers can send P= OST requests to /search.php with malicious search_query values using CASE W= HEN statements to extract sensitive database information. 2026-05-16 8.2 CV= E-2021-47954 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47954 ] ExploitD= B-49593 [ https://www.exploit-db.com/exploits/49593 ]
    VulnCheck Advisory: LayerBB 1.1.4 SQL Injection via search_query Parameter =
    [ https://www.vulncheck.com/advisories/layerbb-sql-injection-via-search-que= ry-parameter ]
    =C2=A0 Egavilanmedia--EgavilanMedia PHPCRUD EgavilanMedia PHPCRUD 1.0 conta= ins an SQL injection vulnerability that allows unauthenticated attackers to=
    manipulate database queries by injecting SQL code through the firstname pa= rameter. Attackers can send POST requests to insert.php with malicious firs= tname values to extract sensitive database information. 2026-05-16 8.2 CVE-= 2021-47956 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47956 ] ExploitDB-= 49878 [ https://www.exploit-db.com/exploits/49878 ]
    Official Product Homepage [ https://egavilanmedia.com ]
    Product Reference [ https://egavilanmedia.com/crud-operation-with-php-mysql= -bootstrap-and-dompdf/ ]
    VulnCheck Advisory: EgavilanMedia PHPCRUD 1.0 SQL Injection via firstname [=
    https://www.vulncheck.com/advisories/egavilanmedia-phpcrud-sql-injection-v= ia-firstname ]
    =C2=A0 Schlix--Schlix CMS Schlix CMS 2.2.6-6 contains a remote code executi=
    on vulnerability that allows authenticated attackers to execute arbitrary P=
    HP code by uploading malicious extension packages through the block manager=
    . Attackers can upload a crafted ZIP file containing PHP code in the packag= einfo.inc file and trigger execution by accessing the About tab of the inst= alled extension. 2026-05-15 8.8 CVE-2021-47964 [ https://www.cve.org/CVERec= ord?id=3DCVE-2021-47964 ] ExploitDB-49838 [ https://www.exploit-db.com/expl= oits/49838 ]
    Official Product Homepage [ https://www.schlix.com/ ]
    Product Reference [ https://www.schlix.com/downloads/schlix-cms/schlix-cms-= v2.2.6-6.zip ]
    VulnCheck Advisory: Schlix CMS 2.2.6-6 Remote Code Execution via core.block= manager [ https://www.vulncheck.com/advisories/schlix-cms-6-remote-code-exe= cution-via-core-blockmanager ]
    =C2=A0 Timeclock--PHP Timeclock PHP Timeclock 1.04 contains time-based and = boolean-based blind SQL injection vulnerabilities in the login_userid param= eter of login.php that allows unauthenticated attackers to extract database=
    contents. Attackers can submit crafted POST requests with SQL payloads usi=
    ng SLEEP functions or RLIKE conditional statements to dump sensitive databa=
    se information including employee names and credentials. 2026-05-15 8.2 CVE= -2021-47966 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47966 ] ExploitDB= -49849 [ https://www.exploit-db.com/exploits/49849 ]
    Official Product Homepage [ http://timeclock.sourceforge.net ]
    Product Reference [ https://sourceforge.net/projects/timeclock/files/PHP%20= Timeclock/PHP%20Timeclock%201.04/ ]
    VulnCheck Advisory: PHP Timeclock 1.04 SQL Injection via login.php [ https:= //www.vulncheck.com/advisories/php-timeclock-sql-injection-via-login-php ] =C2=A0 Textpattern--TextPattern CMS TextPattern CMS 4.9.0-dev contains a re= mote code execution vulnerability that allows authenticated attackers to up= load arbitrary PHP files by exploiting the plugin upload functionality. Att= ackers can authenticate, retrieve a CSRF token from the plugin event page, = and upload malicious PHP files to the textpattern/tmp/ directory for code e= xecution. 2026-05-16 8.8 CVE-2021-47976 [ https://www.cve.org/CVERecord?id= =3DCVE-2021-47976 ] ExploitDB-50095 [ https://www.exploit-db.com/exploits/5= 0095 ]
    Official Product Homepage [ https://textpattern.com/ ]
    Product Reference [ https://github.com/textpattern/textpattern ]
    VulnCheck Advisory: TextPattern CMS 4.9.0-dev Authenticated Remote Code Exe= cution via Plugin Upload [ https://www.vulncheck.com/advisories/textpattern= -cms-dev-authenticated-remote-code-execution-via-plugin-upload ]
    =C2=A0 Miniorange--Backup and Restore WordPress Plugin Backup and Restore 1= .0.3 contains an arbitrary file deletion vulnerability that allows authenti= cated attackers to delete files by manipulating parameters in AJAX requests=
    . Attackers can send POST requests to admin-ajax.php with crafted file_name=
    and folder_name parameters to delete arbitrary files from the WordPress in= stallation directory. 2026-05-16 8.8 CVE-2021-47979 [ https://www.cve.org/C= VERecord?id=3DCVE-2021-47979 ] ExploitDB-50503 [ https://www.exploit-db.com= /exploits/50503 ]
    Official Product Homepage [ https://www.miniorange.com/ ]
    Product Reference [ https://wordpress.org/plugins/backup-and-restore-for-wp=
    / ]
    VulnCheck Advisory: WordPress Plugin Backup and Restore 1.0.3 Arbitrary Fil=
    e Deletion [ https://www.vulncheck.com/advisories/wordpress-plugin-backup-a= nd-restore-arbitrary-file-deletion ]
    =C2=A0 WSO2--WSO2 Identity Server The Magic Link authentication flow accept=
    s multiple invalid authentication requests without adequate rate limiting o=
    r resource control, leading to uncontrolled memory usage growth. This vulne= rability can result in a denial-of-service condition, causing service unava= ilability for deployments that utilize the Magic Link authenticator. The im= pact is limited to these specific deployments and requires repeated invalid=
    authentication attempts to trigger. 2026-05-11 8.6 CVE-2025-10470 [ https:= //www.cve.org/CVERecord?id=3DCVE-2025-10470 ] https://security.docs.wso2.co= m/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4469/ =C2=A0 APPYAP Technology and Information Inc.--Yaay Social Media App Author= ization bypass through User-Controlled key vulnerability in APPYAP Technolo=
    gy and Information Inc. Yaay Social Media App allows Accessing Functionalit=
    y Not Properly Constrained by ACLs. This issue affects Yaay Social Media Ap=
    p: from 3.8.0 through 24102025. 2026-05-14 8.8 CVE-2025-12008 [ https://www= .cve.org/CVERecord?id=3DCVE-2025-12008 ] https://siberguvenlik.gov.tr/guven= lik-bildirimleri/detay/tr-26-0238
    =C2=A0 Yordam Information Technology Consulting, Training and Electronic Sy= stems Industry and Trade Inc.--Library Automation System Incorrect Authoriz= ation vulnerability in Yordam Information Technology Consulting, Training a=
    nd Electronic Systems Industry and Trade Inc. Library Automation System all= ows Exploiting Incorrectly Configured Access Control Security Levels. This = issue affects Library Automation System: from v.19.5 before v.22.1. 2026-05= -14 8.8 CVE-2025-15023 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15023 =
    ] https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240
    =C2=A0 Yordam Information Technology Consulting, Training and Electronic Sy= stems Industry and Trade Inc.--Library Automation System Improper Control o=
    f Generation of Code ('Code Injection') vulnerability in Yordam Information=
    Technology Consulting, Training and Electronic Systems Industry and Trade = Inc. Library Automation System allows Remote Code Inclusion. This issue aff= ects Library Automation System: from v.19.5 before v.22.1. 2026-05-14 8.8 C= VE-2025-15024 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15024 ] https:/= /siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240
    =C2=A0 Yordam Information Technology Consulting, Training and Electronic Sy= stems Industry and Trade Inc.--Library Automation System Authorization bypa=
    ss through User-Controlled key vulnerability in Yordam Information Technolo=
    gy Consulting, Training and Electronic Systems Industry and Trade Inc. Libr= ary Automation System allows Exploitation of Trusted Identifiers. This issu=
    e affects Library Automation System: from v.21.6 before v.22.1. 2026-05-14 = 8.8 CVE-2025-15025 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15025 ] ht= tps://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240
    =C2=A0 wende60--Redaxo CMS Addon MyEvents Redaxo CMS Addon MyEvents 2.2.1 c= ontains an SQL injection vulnerability that allows authenticated attackers =
    to manipulate database queries by injecting SQL code through the myevents_i=
    d parameter. Attackers can send GET requests to the event_add.php page with=
    malicious myevents_id values to extract or modify sensitive database infor= mation. 2026-05-17 7.1 CVE-2018-25319 [ https://www.cve.org/CVERecord?id=3D= CVE-2018-25319 ] ExploitDB-44261 [ https://www.exploit-db.com/exploits/4426=
    1 ]
    Official Product Homepage [ http://www.github.com/wende60/myevents ]
    VulnCheck Advisory: Redaxo CMS Addon MyEvents 2.2.1 SQL Injection via event= _add.php [ https://www.vulncheck.com/advisories/redaxo-cms-addon-myevents-s= ql-injection-via-event-add-php ]
    =C2=A0 woocommerce-csvimport--WooCommerce CSV-Importer Woocommerce CSV Impo= rter 3.3.6 contains a path traversal vulnerability that allows any register=
    ed user to delete arbitrary files by submitting unescaped filenames through=
    the delete_export_file AJAX action. Attackers can craft POST requests with=
    directory traversal sequences in the filename parameter to delete sensitiv=
    e files like wp-config.php outside the intended export directory. 2026-05-1=
    7 7.5 CVE-2018-25325 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25325 ] = ExploitDB-44433 [ https://www.exploit-db.com/exploits/44433 ]
    Official Product Homepage [ http://lenonleite.com.br/ ]
    VulnCheck Advisory: Woocommerce CSV Importer 3.3.6 Path Traversal File Dele= tion [ https://www.vulncheck.com/advisories/woocommerce-csv-importer-path-t= raversal-file-deletion ]
    =C2=A0 wp-google-drive--Google Drive Google Drive for WordPress 2.2 contain=
    s a path traversal vulnerability that allows unauthenticated attackers to r= ead arbitrary files by injecting directory traversal sequences in the file_= name parameter. Attackers can send POST requests to gdrive-ajaxs.php with t=
    he ajaxstype parameter set to del_fl_bkp and file_name containing traversal=
    sequences ../../wp-config.php to access sensitive configuration files. 202= 6-05-17 7.5 CVE-2018-25326 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25= 326 ] ExploitDB-44435 [ https://www.exploit-db.com/exploits/44435 ]
    Official Product Homepage [ http://lenonleite.com.br/ ]
    VulnCheck Advisory: Google Drive for WordPress 2.2 Path Traversal RCE via g= drive-ajaxs.php [ https://www.vulncheck.com/advisories/google-drive-for-wor= dpress-path-traversal-rce-via-gdrive-ajaxs-php ]
    =C2=A0 wp-with-spritz--WP with Spritz WordPress Plugin WP with Spritz 1.0 c= ontains a remote file inclusion vulnerability that allows unauthenticated a= ttackers to read arbitrary files by injecting file paths into the url param= eter. Attackers can send GET requests to wp.spritz.content.filter.php with = malicious url values to access sensitive files like system configuration an=
    d credentials. 2026-05-17 7.5 CVE-2018-25329 [ https://www.cve.org/CVERecor= d?id=3DCVE-2018-25329 ] ExploitDB-44544 [ https://www.exploit-db.com/exploi= ts/44544 ]
    Product Reference [ https://downloads.wordpress.org/plugin/wp-with-spritz.z=
    ip ]
    VulnCheck Advisory: WordPress Plugin WP with Spritz 1.0 Remote File Inclusi=
    on [ https://www.vulncheck.com/advisories/wordpress-plugin-wp-with-spritz-r= emote-file-inclusion ]
    =C2=A0 Fabrikar--com_fabrik Joomla com_fabrik 3.9.11 contains a directory t= raversal vulnerability that allows unauthenticated attackers to list arbitr= ary files by manipulating the folder parameter. Attackers can send GET requ= ests to the onAjax_files method with path traversal sequences to enumerate = files in system directories outside the intended web root. 2026-05-13 7.5 C= VE-2020-37219 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37219 ] Exploit= DB-48263 [ https://www.exploit-db.com/exploits/48263 ]
    Official Product Homepage [ https://fabrikar.com/ ]
    Product Reference [ https://fabrikar.com/downloads ]
    VulnCheck Advisory: Joomla com_fabrik 3.9.11 Directory Traversal via image.= php [ https://www.vulncheck.com/advisories/joomla-com-fabrik-directory-trav= ersal-via-image-php ]
    =C2=A0 www.huawei.com--Huawei HG630 Router Huawei HG630 V2 router contains =
    an authentication bypass vulnerability that allows unauthenticated attacker=
    s to obtain administrative access by retrieving the device serial number. A= ttackers can query the /api/system/deviceinfo endpoint without authenticati=
    on to extract the SerialNumber field, then use the last 8 characters as the=
    default password to login to the router. 2026-05-13 7.5 CVE-2020-37220 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2020-37220 ] ExploitDB-48310 [ https:= //www.exploit-db.com/exploits/48310 ]
    Reference [ https://www.youtube.com/watch?v=3DvOrIL7L_cVc ]
    VulnCheck Advisory: Huawei HG630 V2 Router Authentication Bypass via Serial=
    Number [ https://www.vulncheck.com/advisories/huawei-hg630-v2-router-authe= ntication-bypass-via-serial-number ]
    =C2=A0 Kuicms--Kuicms Php EE Kuicms Php EE 2.0 contains a persistent cross-= site scripting vulnerability that allows unauthenticated attackers to injec=
    t malicious scripts by submitting crafted content through the bbs reply end= point. Attackers can send POST requests to /web/?c=3Dbbs&a=3Dreply with HTM=
    L and JavaScript payloads in the content parameter to execute arbitrary scr= ipts in users' browsers. 2026-05-13 7.2 CVE-2020-37222 [ https://www.cve.or= g/CVERecord?id=3DCVE-2020-37222 ] ExploitDB-48526 [ https://www.exploit-db.= com/exploits/48526 ]
    Official Product Homepage [ https://kuicms.com ]
    Product Reference [ https://kuicms.com/kuicms.zip ]
    VulnCheck Advisory: Kuicms Php EE 2.0 Persistent Cross-Site Scripting via b=
    bs reply [ https://www.vulncheck.com/advisories/kuicms-php-ee-persistent-cr= oss-site-scripting-via-bbs-reply ]
    =C2=A0 Iobit--IObit Uninstaller IObit Uninstaller 9.5.0.15 contains an unqu= oted service path vulnerability in the IObitUnSvr service that allows local=
    attackers to escalate privileges to SYSTEM level. Attackers can place a ma= licious executable named IObit.exe in the C:\Program Files (x86)\IObit dire= ctory and restart the service to execute code with SYSTEM privileges. 2026-= 05-13 7.8 CVE-2020-37223 [ https://www.cve.org/CVERecord?id=3DCVE-2020-3722=
    3 ] ExploitDB-48543 [ https://www.exploit-db.com/exploits/48543 ]
    Official Product Homepage [ https://www.iobit.com ]
    Product Reference [ https://www.iobit.com/en/advanceduninstaller.php ] VulnCheck Advisory: IObit Uninstaller 9.5.0.15 Unquoted Service Path Privil= ege Escalation [ https://www.vulncheck.com/advisories/iobit-uninstaller-unq= uoted-service-path-privilege-escalation ]
    =C2=A0 Joomsky--J2 JOBS Joomla J2 JOBS 1.3.0 contains an authenticated SQL = injection vulnerability that allows authenticated attackers to manipulate d= atabase queries by injecting SQL code through the 'sortby' parameter. Attac= kers can send POST requests to the administrator index with malicious 'sort= by' values to extract sensitive database information. 2026-05-13 7.1 CVE-20= 20-37224 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37224 ] ExploitDB-48= 648 [ https://www.exploit-db.com/exploits/48648 ]
    Official Product Homepage [ https://joomsky.com/ ]
    Product Reference [ https://joomsky.com/products/js-jobs-pro.html ]
    VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via so= rtby [ https://www.vulncheck.com/advisories/joomla-j2-jobs-authenticated-sq= l-injection-via-sortby ]
    =C2=A0 Joomsky--J2 JOBS Joomla J2 JOBS 1.3.0 contains an authenticated SQL = injection vulnerability that allows authenticated attackers to manipulate d= atabase queries by injecting SQL code through the 'sortby' parameter. Attac= kers can send POST requests to the administrator index with malicious 'sort= by' values to extract sensitive database information using automated tools.=
    2026-05-13 7.1 CVE-2020-37226 [ https://www.cve.org/CVERecord?id=3DCVE-202= 0-37226 ] ExploitDB-48670 [ https://www.exploit-db.com/exploits/48670 ] Official Product Homepage [ https://joomsky.com/ ]
    Product Reference [ https://joomsky.com/products/js-jobs-pro.html ]
    VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via so= rtby [ https://www.vulncheck.com/advisories/joomla-j2-jobs-authenticated-sq= l-injection-via-sortby-2 ]
    =C2=A0 Oki--OKI sPSV Port Manager OKI sPSV Port Manager 1.0.41 contains an = unquoted service path vulnerability in the sPSVOpLclSrv service that allows=
    local attackers to escalate privileges by inserting executable files into = the unquoted path. Attackers can place a malicious executable in a director=
    y within the service path that will execute with LocalSystem privileges whe=
    n the service restarts or the system reboots. 2026-05-16 7.8 CVE-2020-37229=
    [ https://www.cve.org/CVERecord?id=3DCVE-2020-37229 ] ExploitDB-49005 [ ht= tps://www.exploit-db.com/exploits/49005 ]
    Official Product Homepage [ https://www.oki.com/ ]
    Product Reference [ https://www.oki.com/mx/printing/download/sPSV_010041_2_= 270910.exe ]
    VulnCheck Advisory: OKI sPSV Port Manager 1.0.41 Unquoted Service Path Priv= ilege Escalation [ https://www.vulncheck.com/advisories/oki-spsv-port-manag= er-unquoted-service-path-privilege-escalation ]
    =C2=A0 Syncplify--Syncplify.me Server! Syncplify.me Server! 5.0.37 contains=
    an unquoted service path vulnerability in the SMWebRestServicev5 service t= hat allows local attackers to escalate privileges by exploiting the unquote=
    d binary path. Attackers can insert a malicious executable into the service=
    path and execute it with LocalSystem privileges when the service restarts =
    or the system reboots. 2026-05-16 7.8 CVE-2020-37230 [ https://www.cve.org/= CVERecord?id=3DCVE-2020-37230 ] ExploitDB-49009 [ https://www.exploit-db.co= m/exploits/49009 ]
    Official Product Homepage [ https://www.syncplify.me/ ]
    Product Reference [ https://download.syncplify.me/SMServer_Setup.exe ] VulnCheck Advisory: Syncplify.me Server! 5.0.37 Unquoted Service Path Privi= lege Escalation [ https://www.vulncheck.com/advisories/syncplify-me-server-= unquoted-service-path-privilege-escalation ]
    =C2=A0 Cybertronsoft--Privacy Drive Privacy Drive 3.17.0 contains an unquot=
    ed service path vulnerability in the pdsvc.exe service binary that allows l= ocal attackers to escalate privileges by exploiting the service startup pro= cess. Attackers can place malicious executables in the unquoted path direct= ories to execute arbitrary code with LocalSystem privileges during service = startup or system reboot. 2026-05-16 7.8 CVE-2020-37231 [ https://www.cve.o= rg/CVERecord?id=3DCVE-2020-37231 ] ExploitDB-49023 [ https://www.exploit-db= .com/exploits/49023 ]
    Official Product Homepage [ https://www.cybertronsoft.com/ ]
    Product Reference [ https://www.cybertronsoft.com/download/privacy-drive-se= tup.exe ]
    VulnCheck Advisory: Privacy Drive 3.17.0 Unquoted Service Path Privilege Es= calation [ https://www.vulncheck.com/advisories/privacy-drive-unquoted-serv= ice-path-privilege-escalation ]
    =C2=A0 Iobit--Advanced System Care Service Advanced System Care Service 13.= 0.0.157 contains an unquoted service path vulnerability in the AdvancedSyst= emCareService13 service binary path that allows local attackers to escalate=
    privileges. Attackers can place malicious executables in the system root p= ath that will be executed with LocalSystem privileges during service startu=
    p or system reboot. 2026-05-16 7.8 CVE-2020-37232 [ https://www.cve.org/CVE= Record?id=3DCVE-2020-37232 ] ExploitDB-49049 [ https://www.exploit-db.com/e= xploits/49049 ]
    Official Product Homepage [ https://www.iobit.com ]
    Product Reference [ https://www.iobit.com/es/advancedsystemcarepro.php ] VulnCheck Advisory: Advanced System Care Service 13.0.0.157 Unquoted Servic=
    e Path Privilege Escalation [ https://www.vulncheck.com/advisories/advanced= -system-care-service-unquoted-service-path-privilege-escalation ]
    =C2=A0 Supsystic--Digital Publications Supsystic Digital Publications 1.6.9=
    contains a path traversal vulnerability in the Folder input field that all= ows attackers to access files outside the web root by injecting directory t= raversal sequences. Additionally, the plugin fails to sanitize input fields=
    in publication settings, allowing stored cross-site scripting attacks thro= ugh script injection in parameters like Area Width and Publication Width th=
    at execute when publications are viewed or edited. 2026-05-16 7.5 CVE-2020-= 37245 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37245 ] ExploitDB-49542=
    [ https://www.exploit-db.com/exploits/49542 ]
    Official Product Homepage [ https://supsystic.com/ ]
    Product Reference [ https://downloads.wordpress.org/plugin/digital-publicat= ions-by-supsystic.1.6.9.zip ]
    VulnCheck Advisory: WordPress Plugin Supsystic Digital Publications 1.6.9 P= ath Traversal XSS [ https://www.vulncheck.com/advisories/wordpress-plugin-s= upsystic-digital-publications-path-traversal-xss ]
    =C2=A0 Kite--Kite Kite 4.2.0.1 U1 contains an unquoted service path vulnera= bility in the KiteService Windows service that allows local attackers to es= calate privileges by exploiting the service binary path. Attackers can plac=
    e a malicious executable in the Program Files directory to be executed with=
    LocalSystem privileges when the service starts. 2026-05-16 7.8 CVE-2020-37= 247 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37247 ] ExploitDB-50975 [=
    https://www.exploit-db.com/exploits/50975 ]
    Official Product Homepage [ https://www.kite.com/ ]
    VulnCheck Advisory: Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalat= ion [ https://www.vulncheck.com/advisories/kite-u1-unquoted-service-path-pr= ivilege-escalation ]
    =C2=A0 Home-Assistant--Home Assistant Community Store (HACS) Home Assistant=
    Community Store (HACS) 1.10.0 contains a path traversal vulnerability that=
    allows unauthenticated attackers to read sensitive files by traversing dir= ectories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/= auth file containing user credentials and refresh tokens, then craft valid = JWT tokens to gain administrative access to Home Assistant instances. 2026-= 05-16 7.5 CVE-2021-47942 [ https://www.cve.org/CVERecord?id=3DCVE-2021-4794=
    2 ] ExploitDB-49495 [ https://www.exploit-db.com/exploits/49495 ]
    Official Product Homepage [ https://www.home-assistant.io/ ]
    Product Reference [ https://github.com/hacs/integration ]
    VulnCheck Advisory: Home Assistant Community Store 1.10.0 Path Traversal Ac= count Takeover [ https://www.vulncheck.com/advisories/home-assistant-commun= ity-store-path-traversal-account-takeover ]
    =C2=A0 Wpgraphql--WPGraphQL WordPress Plugin WPGraphQL 1.3.5 contains a den= ial of service vulnerability that allows unauthenticated attackers to exhau=
    st server resources by sending batched GraphQL queries with duplicated fiel= ds. Attackers can send POST requests to the GraphQL endpoint with amplified=
    field duplication payloads to trigger server out-of-memory conditions and = MySQL connection errors. 2026-05-15 7.5 CVE-2021-47959 [ https://www.cve.or= g/CVERecord?id=3DCVE-2021-47959 ] ExploitDB-49807 [ https://www.exploit-db.= com/exploits/49807 ]
    Official Product Homepage [ https://www.wpgraphql.com/ ]
    VulnCheck Advisory: WordPress Plugin WPGraphQL 1.3.5 Denial of Service [ ht= tps://www.vulncheck.com/advisories/wordpress-plugin-wpgraphql-denial-of-ser= vice ]
    =C2=A0 AnotherNote--Anote Anote 1.0 contains a persistent cross-site script= ing vulnerability that allows attackers to execute arbitrary code by inject= ing malicious payloads into markdown files stored within the application. A= ttackers can craft malicious markdown files with embedded JavaScript that e= xecutes system commands when opened, enabling remote code execution on the = victim's computer. 2026-05-15 7.2 CVE-2021-47963 [ https://www.cve.org/CVER= ecord?id=3DCVE-2021-47963 ] ExploitDB-49836 [ https://www.exploit-db.com/ex= ploits/49836 ]
    Official Product Homepage [ https://github.com/AnotherNote/anote ]
    VulnCheck Advisory: Anote 1.0 Persistent Cross-Site Scripting Remote Code E= xecution [ https://www.vulncheck.com/advisories/anote-persistent-cross-site= -scripting-remote-code-execution ]
    =C2=A0 color-notes--Color Notes Color Notes 1.4 contains a denial of servic=
    e vulnerability that allows attackers to crash the application by pasting e= xcessively long character strings into note fields. Attackers can generate =
    a payload containing 350,000 repeated characters and paste it twice into a = new note to cause the application to stop responding. 2026-05-16 7.5 CVE-20= 21-47969 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47969 ] ExploitDB-49= 952 [ https://www.exploit-db.com/exploits/49952 ]
    VulnCheck Advisory: Color Notes 1.4 Denial of Service via Long Character St= ring [ https://www.vulncheck.com/advisories/color-notes-denial-of-service-v= ia-long-character-string ]
    =C2=A0 macaron-notes-great-notebook--Macaron Notes Gear Notebook Macaron No= tes 5.5 contains a denial of service vulnerability that allows attackers to=
    crash the application by creating notes with excessively long character st= rings. Attackers can generate a payload containing 350000 repeated characte=
    rs and paste it into a note field to trigger application crash and stop fun= ctionality. 2026-05-16 7.5 CVE-2021-47970 [ https://www.cve.org/CVERecord?i= d=3DCVE-2021-47970 ] ExploitDB-49953 [ https://www.exploit-db.com/exploits/= 49953 ]
    VulnCheck Advisory: Macaron Notes 5.5 Denial of Service via Buffer Overflow=
    [ https://www.vulncheck.com/advisories/macaron-notes-denial-of-service-via= -buffer-overflow ]
    =C2=A0 my-notes-safe--My Notes Safe My Notes Safe 5.3 contains a denial of = service vulnerability that allows attackers to crash the application by pas= ting excessively long character strings into note fields. Attackers can gen= erate a payload containing 350000 repeated characters and paste it twice in=
    to a new note to trigger an application crash. 2026-05-16 7.5 CVE-2021-4797=
    1 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47971 ] ExploitDB-49954 [ h= ttps://www.exploit-db.com/exploits/49954 ]
    VulnCheck Advisory: My Notes Safe 5.3 Denial of Service via Buffer Overflow=
    [ https://www.vulncheck.com/advisories/my-notes-safe-denial-of-service-via= -buffer-overflow ]
    =C2=A0 sticky-notes-color-widgets--Sticky Notes Color Widgets Sticky Notes =
    & Color Widgets 1.4.2 contains a denial of service vulnerability that allow=
    s attackers to crash the application by creating notes with excessively lon=
    g character strings. Attackers can paste large payloads of repeated charact= ers into note fields to trigger application crashes and make the applicatio=
    n stop responding. 2026-05-16 7.5 CVE-2021-47972 [ https://www.cve.org/CVER= ecord?id=3DCVE-2021-47972 ] ExploitDB-49957 [ https://www.exploit-db.com/ex= ploits/49957 ]
    VulnCheck Advisory: Sticky Notes & Color Widgets 1.4.2 Denial of Service [ = https://www.vulncheck.com/advisories/sticky-notes-color-widgets-denial-of-s= ervice ]
    =C2=A0 sticky-notes--Sticky Notes Widget Sticky Notes Widget 3.0.6 contains=
    a denial of service vulnerability that allows attackers to crash the appli= cation by pasting excessively long character strings into note fields. Atta= ckers can generate a payload containing 350000 repeated characters and past=
    e it twice into a new note to trigger an application crash on iOS devices. = 2026-05-16 7.5 CVE-2021-47973 [ https://www.cve.org/CVERecord?id=3DCVE-2021= -47973 ] ExploitDB-49978 [ https://www.exploit-db.com/exploits/49978 ] VulnCheck Advisory: Sticky Notes Widget 3.0.6 Denial of Service via Buffer = Overflow [ https://www.vulncheck.com/advisories/sticky-notes-widget-denial-= of-service-via-buffer-overflow ]
    =C2=A0 Vxsearch--VX Search VX Search 13.5.28 contains an unquoted service p= ath vulnerability in both VX Search Server and VX Search Enterprise service=
    s that allows local attackers to escalate privileges. Attackers can place m= alicious executables in unquoted path directories like C:\Program Files\VX = Search to execute arbitrary code with LocalSystem privileges when services = restart. 2026-05-16 7.8 CVE-2021-47974 [ https://www.cve.org/CVERecord?id= =3DCVE-2021-47974 ] ExploitDB-50026 [ https://www.exploit-db.com/exploits/5= 0026 ]
    Official Product Homepage [ https://www.vxsearch.com ]
    VulnCheck Advisory: VX Search 13.5.28 Unquoted Service Path Privilege Escal= ation [ https://www.vulncheck.com/advisories/vx-search-unquoted-service-pat= h-privilege-escalation ]
    =C2=A0 Wplearnmanager--WP Learn Manager WP Learn Manager 1.1.2 contains a s= tored cross-site scripting vulnerability that allows unauthenticated attack= ers to inject malicious scripts through the fieldtitle parameter. Attackers=
    can submit POST requests to the jslm_fieldordering page with XSS payloads =
    in the fieldtitle field to execute arbitrary JavaScript when administrators=
    view the field ordering interface. 2026-05-16 7.2 CVE-2021-47975 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2021-47975 ] ExploitDB-50086 [ https://www.= exploit-db.com/exploits/50086 ]
    Official Product Homepage [ https://wplearnmanager.com/ ]
    Product Reference [ https://wordpress.org/plugins/learn-manager/ ]
    VulnCheck Advisory: WordPress Plugin WP Learn Manager 1.1.2 Stored XSS [ ht= tps://www.vulncheck.com/advisories/wordpress-plugin-wp-learn-manager-stored= -xss ]
    =C2=A0 Gotmls--Malware Security and Bruteforce Firewall WordPress Plugin An= ti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory tr= aversal vulnerability that allows unauthenticated attackers to read arbitra=
    ry files by manipulating the file parameter. Attackers can send requests to=
    the duplicator_download action via admin-ajax.php with path traversal sequ= ences to access sensitive system files outside the intended directory. 2026= -05-16 7.5 CVE-2021-47977 [ https://www.cve.org/CVERecord?id=3DCVE-2021-479=
    77 ] ExploitDB-50107 [ https://www.exploit-db.com/exploits/50107 ]
    Official Product Homepage [ https://gotmls.net/ ]
    Product Reference [ https://gotmls.net/downloads/ ]
    VulnCheck Advisory: WordPress Anti-Malware Security Bruteforce Firewall 4.2= 0.59 Directory Traversal [ https://www.vulncheck.com/advisories/wordpress-a= nti-malware-security-bruteforce-firewall-directory-traversal ]
    =C2=A0 Getfuelcms--Fuel CMS Fuel CMS 1.4.13 contains a blind SQL injection = vulnerability that allows authenticated attackers to manipulate database qu= eries by injecting SQL code through the 'col' parameter in the Activity Log=
    interface. Attackers can send requests to the logs endpoint with malicious=
    SQL payloads in the 'col' parameter to extract database information based =
    on response time delays. 2026-05-16 7.1 CVE-2021-47980 [ https://www.cve.or= g/CVERecord?id=3DCVE-2021-47980 ] ExploitDB-50523 [ https://www.exploit-db.= com/exploits/50523 ]
    Official Product Homepage [ https://www.getfuelcms.com/ ]
    Product Reference [ https://github.com/daylightstudio/FUEL-CMS/archive/1.4.= 13.zip ]
    VulnCheck Advisory: Fuel CMS 1.4.13 Blind SQL Injection via col Parameter [=
    https://www.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-= parameter ]
    =C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 b= efore 18.11.3 that could have allowed an unauthenticated user to cause deni=
    al of service by sending specially crafted payloads on certain API endpoint=
    s. 2026-05-14 7.5 CVE-2025-14869 [ https://www.cve.org/CVERecord?id=3DCVE-2= 025-14869 ] HackerOne Bug Bounty Report #3447146 [ https://hackerone.com/re= ports/3447146 ]
    https://gitlab.com/gitlab-org/gitlab/-/work_items/584489 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
    =C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 b= efore 18.11.3 that could have allowed an unauthenticated user to cause deni=
    al of service by sending specially crafted JSON payloads due to insufficien=
    t input validation. 2026-05-14 7.5 CVE-2025-14870 [ https://www.cve.org/CVE= Record?id=3DCVE-2025-14870 ] HackerOne Bug Bounty Report #3446641 [ https:/= /hackerone.com/reports/3446641 ] https://gitlab.com/gitlab-org/gitlab/-/work_items/584490 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
    =C2=A0=20

    Back to top [ #top ]

    Medium Vulnerabilities

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info S= imple-Fields--Simple Fields Simple Fields 0.2 through 0.3.5 WordPress Plugi=
    n contains a local file inclusion vulnerability that allows unauthenticated=
    attackers to read arbitrary files by injecting null bytes into the wp_absp= ath parameter on PHP versions before 5.3.4. Attackers can supply malicious = wp_abspath values to simple_fields.php to include files like /etc/passwd or=
    inject PHP code into Apache logs for remote code execution when allow_url_= include is enabled. 2026-05-17 6.2 CVE-2018-25324 [ https://www.cve.org/CVE= Record?id=3DCVE-2018-25324 ] ExploitDB-44425 [ https://www.exploit-db.com/e= xploits/44425 ]
    Official Product Homepage [ http://simple-fields.com ]
    Product Reference [ https://downloads.wordpress.org/plugin/simple-fields.0.= 3.5.zip ]
    VulnCheck Advisory: Simple Fields 0.2-0.3.5 Local File Inclusion via wp_abs= path [ https://www.vulncheck.com/advisories/simple-fields-local-file-inclus= ion-via-wp-abspath ]
    =C2=A0 zenar--Zenar Content Management System Zenar Content Management Syst=
    em contains a cross-site scripting vulnerability that allows unauthenticate=
    d attackers to inject malicious scripts by manipulating form parameters in = POST requests. Attackers can inject script tags through the current_page pa= rameter sent to the ajax.php endpoint, which reflects unsanitized user inpu=
    t in the response HTML to execute arbitrary JavaScript in victim browsers. = 2026-05-17 6.1 CVE-2018-25331 [ https://www.cve.org/CVERecord?id=3DCVE-2018= -25331 ] ExploitDB-44664 [ https://www.exploit-db.com/exploits/44664 ]
    Official Product Homepage [ http://demo.zenar.io ]
    Product Reference [ https://zenar.io/ ]
    VulnCheck Advisory: Zenar Content Management System Cross-Site Scripting vi=
    a ajax.php [ https://www.vulncheck.com/advisories/zenar-content-management-= system-cross-site-scripting-via-ajax-php ]
    =C2=A0 Powie--WHOIS Domain Check Powie's WHOIS Domain Check 0.9.31 contains=
    a persistent cross-site scripting vulnerability that allows authenticated = attackers to inject arbitrary JavaScript by exploiting unsanitized input fi= elds in plugin settings. Attackers can submit malicious payloads through te= xtarea and input elements in the pwhois_settings.php configuration page to = execute JavaScript in the admin context and escalate privileges. 2026-05-13=
    6.4 CVE-2020-37225 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37225 ] E= xploitDB-48656 [ https://www.exploit-db.com/exploits/48656 ]
    Official Product Homepage [ https://powie.de ]
    Official Product Homepage [ https://blog.haao.sh ]
    Product Reference [ https://wordpress.org/plugins/powies-whois/ ]
    VulnCheck Advisory: Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site=
    Scripting [ https://www.vulncheck.com/advisories/powie-s-whois-domain-chec= k-persistent-cross-site-scripting ]
    =C2=A0 Wordpress--Buddypress WordPress Plugin Buddypress 6.2.0 contains a p= ersistent cross-site scripting vulnerability that allows authenticated atta= ckers with moderator privileges to inject malicious script code through the=
    figure parameter in wp:html blocks. Attackers can inject iframe elements w= ith event handlers like onload that execute when administrators or privileg=
    ed users preview or view the affected page content, enabling session hijack= ing and persistent phishing attacks. 2026-05-16 6.4 CVE-2020-37233 [ https:= //www.cve.org/CVERecord?id=3DCVE-2020-37233 ] ExploitDB-49061 [ https://www= .exploit-db.com/exploits/49061 ]
    Official Product Homepage [ https://wordpress.org/plugins/buddypress/ ] VulnCheck Advisory: WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site=
    Scripting [ https://www.vulncheck.com/advisories/wordpress-plugin-buddypre= ss-persistent-cross-site-scripting ]
    =C2=A0 Internetdownloadmanager--Internet Download Manager Internet Download=
    Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler = component that allows local attackers to crash the application by supplying=
    oversized input. Attackers can paste malicious data exceeding 5000 bytes i= nto the 'Open the following file when done' field to trigger a denial of se= rvice condition. 2026-05-16 6.2 CVE-2020-37234 [ https://www.cve.org/CVERec= ord?id=3DCVE-2020-37234 ] ExploitDB-49083 [ https://www.exploit-db.com/expl= oits/49083 ]
    Official Product Homepage [ http://www.internetdownloadmanager.com/ ]
    Product Reference [ http://www.internetdownloadmanager.com/download.html ] VulnCheck Advisory: Internet Download Manager 6.38.12 Scheduler Buffer Over= flow [ https://www.vulncheck.com/advisories/internet-download-manager-sched= uler-buffer-overflow ]
    =C2=A0 themeftc--Theme Wibar WordPress Theme Wibar 1.1.8 contains a stored = cross-site scripting vulnerability in the Brand component that allows authe= nticated users to inject malicious scripts by manipulating the Logo URL par= ameter. Attackers with editor, administrator, contributor, or author privil= eges can inject base64-encoded script payloads through the ftc_brand_url in= put field to execute arbitrary JavaScript when users visit the brand page. = 2026-05-16 6.4 CVE-2020-37235 [ https://www.cve.org/CVERecord?id=3DCVE-2020= -37235 ] ExploitDB-49107 [ https://www.exploit-db.com/exploits/49107 ]
    Official Product Homepage [ http://demo.themeftc.com/wibar ]
    Product Reference [ https://themeforest.net/item/wibar-responsive-woocommer= ce-wordpress-theme/20994798 ]
    VulnCheck Advisory: WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting=
    via Brand Component [ https://www.vulncheck.com/advisories/wordpress-theme= -wibar-stored-cross-site-scripting-via-brand-component ]
    =C2=A0 Netartmedia--NewsLister NewsLister contains an authenticated persist= ent cross-site scripting vulnerability that allows authenticated administra= tors to inject malicious scripts through the title parameter in the news ad= dition interface. Attackers can inject JavaScript payloads via the title fi= eld in the admin panel that execute when news items are viewed by other use= rs. 2026-05-16 6.4 CVE-2020-37236 [ https://www.cve.org/CVERecord?id=3DCVE-= 2020-37236 ] ExploitDB-49160 [ https://www.exploit-db.com/exploits/49160 ] Official Product Homepage [ https://www.netartmedia.net/newslister.html ] VulnCheck Advisory: NewsLister Authenticated Persistent Cross-Site Scriptin=
    g via Admin Panel [ https://www.vulncheck.com/advisories/newslister-authent= icated-persistent-cross-site-scripting-via-admin-panel ]
    =C2=A0 Compo--Composr CMS Composr CMS 10.0.34 contains a persistent cross-s= ite scripting vulnerability that allows authenticated administrators to inj= ect malicious scripts through the banner management interface. Attackers wi=
    th admin credentials can inject XSS payloads in the Description field of th=
    e Add banner functionality, which execute for all website visitors when the=
    y access the home page. 2026-05-16 6.4 CVE-2020-37237 [ https://www.cve.org= /CVERecord?id=3DCVE-2020-37237 ] ExploitDB-49190 [ https://www.exploit-db.c= om/exploits/49190 ]
    Official Product Homepage [ https://compo.sr/ ]
    Product Reference [ https://compo.sr/download.htm ]
    VulnCheck Advisory: Composr CMS 10.0.34 Persistent Cross-Site Scripting via=
    banners [ https://www.vulncheck.com/advisories/composr-cms-persistent-cros= s-site-scripting-via-banners ]
    =C2=A0 Cmsmadesimple--CMS Made Simple CMS Made Simple 2.2.15 contains a sto= red cross-site scripting vulnerability that allows authenticated users with=
    Content Manager access to inject malicious scripts through SVG file upload=
    s. Attackers can upload SVG files containing embedded JavaScript to the fil=
    e manager, which executes when other authenticated users access the uploade=
    d file, enabling cookie theft and session hijacking. 2026-05-16 6.4 CVE-202= 0-37238 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37238 ] ExploitDB-491=
    99 [ https://www.exploit-db.com/exploits/49199 ]
    Official Product Homepage [ https://www.cmsmadesimple.org/ ]
    Product Reference [ https://www.cmsmadesimple.org/downloads ]
    VulnCheck Advisory: CMS Made Simple 2.2.15 Stored XSS via SVG File Upload [=
    https://www.vulncheck.com/advisories/cms-made-simple-stored-xss-via-svg-fi= le-upload ]
    =C2=A0 Codekernel--Queue Management System Queue Management System 4.0.0 co= ntains a stored cross-site scripting vulnerability that allows authenticate=
    d administrators to inject malicious scripts through user creation fields. = Attackers can insert JavaScript payloads in the First Name, Last Name, and = Email fields during user creation, which execute when viewing the User List=
    page. 2026-05-16 6.4 CVE-2020-37240 [ https://www.cve.org/CVERecord?id=3DC= VE-2020-37240 ] ExploitDB-49296 [ https://www.exploit-db.com/exploits/49296=
    ]
    Official Product Homepage [ http://codekernel.net/ ]
    Product Reference [ https://codecanyon.net/item/queue-management-system/220= 29961 ]
    VulnCheck Advisory: Queue Management System 4.0.0 Stored XSS via Add User [=
    https://www.vulncheck.com/advisories/queue-management-system-stored-xss-vi= a-add-user ]
    =C2=A0 Supsystic--Backup Supsystic Backup 2.3.9 contains a local file inclu= sion vulnerability that allows unauthenticated attackers to read and delete=
    arbitrary files by manipulating the download path parameter. Attackers can=
    modify the download parameter in admin.php requests with directory travers=
    al sequences to access sensitive files like /etc/passwd or delete files via=
    the removeAction parameter. 2026-05-16 6.2 CVE-2020-37246 [ https://www.cv= e.org/CVERecord?id=3DCVE-2020-37246 ] ExploitDB-49545 [ https://www.exploit= -db.com/exploits/49545 ]
    Official Product Homepage [ https://supsystic.com/ ]
    Product Reference [ https://downloads.wordpress.org/plugin/backup-by-supsys= tic.zip ]
    VulnCheck Advisory: WordPress Plugin Supsystic Backup 2.3.9 Local File Incl= usion [ https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-bac= kup-local-file-inclusion ]
    =C2=A0 Cookielawinfo--Cookie Law Bar Cookie Law Bar 1.2.1 contains a stored=
    cross-site scripting vulnerability that allows authenticated attackers to = inject malicious scripts by submitting unsanitized input to the Bar Message=
    field. Attackers can inject script payloads through the plugin settings pa=
    ge that execute in the browsers of all WordPress users viewing the site, en= abling cookie theft and sensitive data exfiltration. 2026-05-16 6.4 CVE-202= 1-47957 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47957 ] ExploitDB-499=
    05 [ https://www.exploit-db.com/exploits/49905 ]
    Official Product Homepage [ https://www.cookielawinfo.com/wordpress-plugin/=
    ]
    Product Reference [ https://wordpress.org/plugins/cookie-law-bar/ ]
    VulnCheck Advisory: WordPress Plugin Cookie Law Bar 1.2.1 Stored XSS via cl= b_bar_msg [ https://www.vulncheck.com/advisories/wordpress-plugin-cookie-la= w-bar-stored-xss-via-clb-bar-msg ]
    =C2=A0 savsofts--Savsoft Quiz Savsoft Quiz 5.0 contains a persistent cross-= site scripting vulnerability in the user account settings page that allows = authenticated attackers to inject malicious HTML and JavaScript code. Attac= kers can inject script payloads into user profile fields at the edit_user e= ndpoint, which execute in the browsers of users viewing the affected profil=
    e after submission. 2026-05-15 6.4 CVE-2021-47962 [ https://www.cve.org/CVE= Record?id=3DCVE-2021-47962 ] ExploitDB-49825 [ https://www.exploit-db.com/e= xploits/49825 ]
    Official Product Homepage [ https://savsoftquiz.com ]
    Product Reference [ https://github.com/savsofts/savsoftquiz_v5 ]
    VulnCheck Advisory: Savsoft Quiz 5.0 Persistent Cross-Site Scripting via Us=
    er Settings [ https://www.vulncheck.com/advisories/savsoft-quiz-persistent-= cross-site-scripting-via-user-settings ]
    =C2=A0 Timeclock--PHP Timeclock PHP Timeclock 1.04 contains multiple cross-= site scripting vulnerabilities that allow unauthenticated attackers to inje=
    ct arbitrary JavaScript by manipulating URL paths and POST parameters. Atta= ckers can append malicious payloads to login.php, timeclock.php, audit.php,=
    and timerpt.php endpoints, or inject code through from_date and to_date pa= rameters in report requests to execute scripts in user browsers. 2026-05-15=
    6.1 CVE-2021-47967 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47967 ] E= xploitDB-49853 [ https://www.exploit-db.com/exploits/49853 ]
    Official Product Homepage [ http://timeclock.sourceforge.net ]
    Product Reference [ https://sourceforge.net/projects/timeclock/files/PHP%20= Timeclock/PHP%20Timeclock%201.04/ ]
    VulnCheck Advisory: PHP Timeclock 1.04 Multiple Cross-Site Scripting via Pa= rameters [ https://www.vulncheck.com/advisories/php-timeclock-multiple-cros= s-site-scripting-via-parameters ]
    =C2=A0 Podcastgenerator--Podcast Generator Podcast Generator 3.1 contains a=
    persistent cross-site scripting vulnerability that allows authenticated at= tackers to inject malicious scripts by submitting unfiltered JavaScript cod=
    e in the long_description parameter. Attackers can inject script tags throu=
    gh episode creation or editing requests to execute arbitrary JavaScript whe=
    n other users view the episode details. 2026-05-15 6.4 CVE-2021-47968 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2021-47968 ] ExploitDB-49866 [ https://= www.exploit-db.com/exploits/49866 ]
    Official Product Homepage [ https://podcastgenerator.net/demoV2/ ]
    Product Reference [ https://podcastgenerator.net/download ]
    VulnCheck Advisory: Podcast Generator 3.1 Persistent Cross-Site Scripting v=
    ia long_description [ https://www.vulncheck.com/advisories/podcast-generato= r-persistent-cross-site-scripting-via-long-description ]
    =C2=A0 Processmaker--ProcessMaker ProcessMaker 3.5.4 contains a local file = inclusion vulnerability that allows unauthenticated attackers to read arbit= rary files by exploiting improper path traversal validation. Attackers can = send requests with directory traversal sequences to access sensitive system=
    files like /etc/passwd without authentication. 2026-05-16 6.2 CVE-2021-479=
    78 [ https://www.cve.org/CVERecord?id=3DCVE-2021-47978 ] ExploitDB-50229 [ = https://www.exploit-db.com/exploits/50229 ]
    Official Product Homepage [ https://www.processmaker.com/ ]
    VulnCheck Advisory: ProcessMaker 3.5.4 Local File Inclusion via Path Traver= sal [ https://www.vulncheck.com/advisories/processmaker-local-file-inclusio= n-via-path-traversal ]
    =C2=A0 interactivegeomaps--MapGeo Interactive Geo Maps The MapGeo - Interac= tive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Sc= ripting via the 'map' parameter in the display-map shortcode in all version=
    s up to, and including, 1.6.27 due to insufficient input sanitization and o= utput escaping. This makes it possible for unauthenticated attackers to inj= ect arbitrary web scripts in pages that execute if they can successfully tr= ick a user into performing an action such as clicking on a link. 2026-05-14=
    6.1 CVE-2025-15345 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15345 ] h= ttps://www.wordfence.com/threat-intel/vulnerabilities/id/bfccbf41-c861-4bf1= -b400-7858cb255b9a?source=3Dcve
    https://research.cleantalk.org/cve-2025-15345 https://plugins.trac.wordpress.org/changeset?old_path=3D/interactive-geo-ma= ps/tags/1.6.27/src/Plugin/Map.php&new_path=3D/interactive-geo-maps/tags/1.6= .28/src/Plugin/Map.php
    =C2=A0 hwk-fr--Advanced Custom Fields: Extended The The Advanced Custom Fie= lds: Extended plugin for WordPress is vulnerable to arbitrary shortcode exe= cution in all versions up to, and including, 0.9.2.3. This is due to the so= ftware allowing users to execute an action that does not properly validate =
    a value before running do_shortcode. This makes it possible for unauthentic= ated attackers to execute arbitrary shortcodes. 2026-05-12 6.5 CVE-2025-154=
    63 [ https://www.cve.org/CVERecord?id=3DCVE-2025-15463 ] https://www.wordfe= nce.com/threat-intel/vulnerabilities/id/f8544784-1994-47e2-be39-568d0ab9ee0= 0?source=3Dcve https://plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includ= es/modules/form/module-form-action-email.php#L111 https://plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includ= es/modules/form/module-form-front-render.php#L35
    =C2=A0 Joomsky--JS Jobs Joomla! Component Js Jobs 1.2.0 contains a cross-si=
    te request forgery vulnerability that allows attackers to perform state-cha= nging actions without token validation. Attackers can craft malicious HTML = forms targeting administrative endpoints like job.jobenforcedelete to delet=
    e job entries or modify component settings when administrators visit attack= er-controlled pages. 2026-05-17 5.3 CVE-2018-25327 [ https://www.cve.org/CV= ERecord?id=3DCVE-2018-25327 ] ExploitDB-44492 [ https://www.exploit-db.com/= exploits/44492 ]
    Official Product Homepage [ https://www.joomsky.com ]
    Product Reference [ https://extensions.joomla.org/extension/js-jobs/ ] VulnCheck Advisory: Joomla! Component Js Jobs 1.2.0 Cross-Site Request Forg= ery [ https://www.vulncheck.com/advisories/joomla-component-js-jobs-cross-s= ite-request-forgery ]
    =C2=A0 Bylancer--Zechat Zechat 1.5 contains a Cross-Site Request Forgery (C= SRF) vulnerability that allows an attacker to change a user's information b=
    y bypassing anti-CSRF protections. The application uses a CSRF token, but a=
    n attacker can use the hashtag parameter to inject an encoded payload and b= ypass the CSRF protection, allowing for unauthorized changes to user data. = This can be exploited by tricking a user into submitting a crafted form or =
    by using a script to obtain and set the CSRF token. 2026-05-17 5.4 CVE-2018= -25334 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25334 ] ExploitDB-4468=
    5 [ https://www.exploit-db.com/exploits/44685 ]
    Official Product Homepage [ https://bylancer.com ]
    VulnCheck Advisory: Zechat 1.5 Cross-Site Request Forgery (CSRF) via hashta=
    g parameter [ https://www.vulncheck.com/advisories/zechat-cross-site-reques= t-forgery-csrf-via-hashtag-parameter ]
    =C2=A0 Joomlaextensions--Joomla! extension jCart for OpenCart Joomla jCart = for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability th=
    at allows attackers to modify user account information without authenticati= on. Attackers can craft malicious HTML forms targeting endpoints , and to c= hange user credentials, passwords, and affiliate account details when victi=
    ms visit the attacker-controlled page. 2026-05-17 5.3 CVE-2018-25336 [ http= s://www.cve.org/CVERecord?id=3DCVE-2018-25336 ] ExploitDB-44788 [ https://w= ww.exploit-db.com/exploits/44788 ]
    Official Product Homepage [ https://www.joomlaextensions.co.in/ ]
    Product Reference [ https://extensions.joomla.org/extensions/extension/e-co= mmerce/e-commerce-integrations/jcart-for-opencart/ ]
    VulnCheck Advisory: Joomla jCart for OpenCart 2.3.0.2 Cross-Site Request Fo= rgery [ https://www.vulncheck.com/advisories/joomla-jcart-for-opencart-cros= s-site-request-forgery ]
    =C2=A0 Ultimate Member--ultimate-member WordPress Plugin ultimate-member 2.= 1.3 contains a local file inclusion vulnerability that allows authenticated=
    attackers to include arbitrary files by manipulating the pack parameter in=
    class-admin-upgrade.php. Attackers can send POST requests with malicious p= ack values to include unintended PHP files from the packages directory and = execute arbitrary code. 2026-05-13 5.5 CVE-2020-37169 [ https://www.cve.org= /CVERecord?id=3DCVE-2020-37169 ] ExploitDB-48065 [ https://www.exploit-db.c= om/exploits/48065 ]
    VulnCheck Advisory: WordPress Plugin ultimate-member 2.1.3 Local File Inclu= sion [ https://www.vulncheck.com/advisories/wordpress-plugin-ultimate-membe= r-local-file-inclusion ]
    =C2=A0 HUSKY--Products Filter Professional for WooCommerce WOOF Products Fi= lter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulne= rability that allows authenticated attackers to inject malicious scripts by=
    entering XSS payloads in design tab textfields. Attackers can inject JavaS= cript code through fields like 'Text for block toggle' and 'Custom front cs=
    s styles' that executes on frontend pages when saved, affecting all site vi= sitors. 2026-05-13 5.5 CVE-2020-37174 [ https://www.cve.org/CVERecord?id=3D= CVE-2020-37174 ] ExploitDB-48088 [ https://www.exploit-db.com/exploits/4808=
    8 ]
    Official Product Homepage [ https://products-filter.com/ ]
    Product Reference [ https://wordpress.org/plugins/woocommerce-products-filt= er/ ]
    VulnCheck Advisory: WOOF Products Filter for WooCommerce 1.2.3 Persistent X=
    SS [ https://www.vulncheck.com/advisories/woof-products-filter-for-woocomme= rce-persistent-xss ]
    =C2=A0 Bloofox--bloofoxCMS bloofoxCMS 0.5.2.1 contains a cross-site request=
    forgery vulnerability that allows attackers to perform administrative acti= ons by tricking logged-in users into visiting malicious pages. Attackers ca=
    n craft hidden forms targeting the admin user creation endpoint to add new = administrative accounts with arbitrary credentials without requiring explic=
    it user consent. 2026-05-16 5.3 CVE-2020-37241 [ https://www.cve.org/CVERec= ord?id=3DCVE-2020-37241 ] ExploitDB-49507 [ https://www.exploit-db.com/expl= oits/49507 ]
    Official Product Homepage [ https://www.bloofox.com/ ]
    Product Reference [ https://github.com/alexlang24/bloofoxCMS/releases/tag/0= .5.2.1 ]
    VulnCheck Advisory: bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user = add [ https://www.vulncheck.com/advisories/bloofoxcms-cross-site-request-fo= rgery-via-user-add ]
    =C2=A0 MyBB--MyBB Timeline Plugin MyBB Timeline Plugin 1.0 contains cross-s= ite scripting vulnerabilities that allow attackers to inject malicious scri= pts through thread titles, post content, and user profile fields like Locat= ion and Bio. Attackers can also exploit a cross-site request forgery vulner= ability in the timeline.php profile action to change a user's cover picture=
    by crafting malicious forms that execute when victims visit affected profi= les. 2026-05-16 5.3 CVE-2021-47934 [ https://www.cve.org/CVERecord?id=3DCVE= -2021-47934 ] ExploitDB-49467 [ https://www.exploit-db.com/exploits/49467 ] Product Reference [ https://community.mybb.com/mods.php?action=3Dview&pid= =3D1428 ]
    VulnCheck Advisory: MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF =
    [ https://www.vulncheck.com/advisories/mybb-timeline-plugin-cross-site-scri= pting-and-csrf ]
    =C2=A0 CouchCMS--CouchCMS CouchCMS 2.2.1 contains a cross-site scripting vu= lnerability that allows authenticated attackers to execute arbitrary JavaSc= ript by uploading malicious SVG files through the file upload functionality=
    . Attackers can upload SVG files containing embedded script tags to the bro= wse.php endpoint, which are then executed in users' browsers when the files=
    are accessed or previewed. 2026-05-16 5.4 CVE-2021-47955 [ https://www.cve= .org/CVERecord?id=3DCVE-2021-47955 ] ExploitDB-49636 [ https://www.exploit-= db.com/exploits/49636 ]
    Official Product Homepage [ https://github.com/CouchCMS/CouchCMS ]
    VulnCheck Advisory: CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload=
    [ https://www.vulncheck.com/advisories/couchcms-cross-site-scripting-via-s= vg-file-upload ]
    =C2=A0 Opensolution--Quick.CMS Quick.CMS 6.7 contains a cross-site scriptin=
    g vulnerability in the sliders form that allows authenticated attackers to = inject malicious scripts by submitting XSS payloads through the sDescriptio=
    n parameter. Attackers can craft CSRF forms targeting the admin.php?p=3Dsli= ders-form endpoint to execute arbitrary JavaScript in victim browsers when = the form is submitted. 2026-05-16 5.4 CVE-2021-47981 [ https://www.cve.org/= CVERecord?id=3DCVE-2021-47981 ] ExploitDB-50530 [ https://www.exploit-db.co= m/exploits/50530 ]
    Official Product Homepage [ https://opensolution.org/ ]
    Product Reference [ https://opensolution.org/download/home.html?sFile=3DQui= ck.Cms_v6.7-en.zip ]
    VulnCheck Advisory: Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders = Form [ https://www.vulncheck.com/advisories/quick-cms-cross-site-scripting-= via-csrf-to-sliders-form ]
    =C2=A0 WSO2--WSO2 Identity Server The check user account lock states featur=
    e within the email OTP flow fails to validate user input, allowing an attac= ker to infer the existence of registered user accounts. The discovery of va= lid usernames can increase the risk of brute-force and social engineering a= ttacks. Attackers can leverage this information to craft targeted phishing = campaigns or other malicious activities aimed at tricking users into divulg= ing sensitive data, potentially damaging the organization's reputation and = leading to regulatory non-compliance and financial consequences. 2026-05-11=
    5.3 CVE-2024-0391 [ https://www.cve.org/CVERecord?id=3DCVE-2024-0391 ] htt= ps://security.docs.wso2.com/en/latest/security-announcements/security-advis= ories/2026/WSO2-2024-3115/
    =C2=A0 Siemens--SIPROTEC 5 6MD84 (CP300) A vulnerability has been identifie=
    d in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP2= 00) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >=3D V7.80 < V11= .0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All=
    versions >=3D V7.80 < V11.0), SIPROTEC 5 6MD89 (CP300) (All versions >=3D = V7.80 < V11.0), SIPROTEC 5 6MU85 (CP300) (All versions >=3D V7.80 < V11.0),=
    SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All ver= sions >=3D V7.80 < V11.0), SIPROTEC 5 7SA82 (CP100) (All versions >=3D V7.8= 0), SIPROTEC 5 7SA82 (CP150) (All versions < V11.0), SIPROTEC 5 7SA84 (CP20=
    0) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA8=
    6 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SA87 (CP200) (All = versions), SIPROTEC 5 7SA87 (CP300) (All versions >=3D V7.80 < V11.0), SIPR= OTEC 5 7SD82 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SD82 (CP150) (A=
    ll versions < V11.0), SIPROTEC 5 7SD84 (CP200) (All versions), SIPROTEC 5 7= SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions >=3D V7= .80 < V11.0), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP= 300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SJ81 (CP100) (All versi= ons >=3D V7.80), SIPROTEC 5 7SJ81 (CP150) (All versions < V11.0), SIPROTEC =
    5 7SJ82 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SJ82 (CP150) (All ve= rsions < V11.0), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 = (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SJ86 (CP200) (All ve= rsions), SIPROTEC 5 7SJ86 (CP300) (All versions >=3D V7.80 < V11.0), SIPROT=
    EC 5 7SK82 (CP100) (All versions >=3D V7.80), SIPROTEC 5 7SK82 (CP150) (All=
    versions < V11.0), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK=
    85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SL82 (CP100) (All=
    versions >=3D V7.80), SIPROTEC 5 7SL82 (CP150) (All versions < V11.0), SIP= ROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All version=
    s >=3D V7.80 < V11.0), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 = 7SL87 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7SS85 (CP200) (= All versions), SIPROTEC 5 7SS85 (CP300) (All versions >=3D V7.80 < V11.0), = SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All vers= ions >=3D V7.80 < V11.0), SIPROTEC 5 7ST86 (CP300) (All versions < V11.0), = SIPROTEC 5 7SX82 (CP150) (All versions < V11.0), SIPROTEC 5 7SX85 (CP300) (= All versions < V11.0), SIPROTEC 5 7SY82 (CP150) (All versions < V11.0), SIP= ROTEC 5 7UM85 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT82 (= CP100) (All versions >=3D V7.80), SIPROTEC 5 7UT82 (CP150) (All versions < = V11.0), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (= All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT86 (CP200) (All versions), = SIPROTEC 5 7UT86 (CP300) (All versions >=3D V7.80 < V11.0), SIPROTEC 5 7UT8=
    7 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions >=3D V7.80=
    < V11.0), SIPROTEC 5 7VE85 (CP300) (All versions >=3D V7.80 < V11.0), SIPR= OTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions=
    =3D V7.80 < V11.0), SIPROTEC 5 7VU85 (CP300) (All versions < V11.0), SIPR= OTEC 5 Compact 7SX800 (CP050) (All versions < V11.0). Affected devices do n=
    ot use sufficiently random values to create session identifiers. This could=
    allow an unauthenticated remote attacker to brute force a session identifi=
    er and gain read access to limited information from the web server without = authorization. 2026-05-12 5.3 CVE-2024-54017 [ https://www.cve.org/CVERecor= d?id=3DCVE-2024-54017 ] https://cert-portal.siemens.com/productcert/html/ss= a-786884.html
    =C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 = before 18.11.3 that could have allowed an authenticated user to inject HTML=
    and JavaScript into email notifications sent to other users due to imprope=
    r input sanitization. 2026-05-14 5.4 CVE-2025-12669 [ https://www.cve.org/C= VERecord?id=3DCVE-2025-12669 ] HackerOne Bug Bounty Report #3368096 [ https= ://hackerone.com/reports/3368096 ] https://gitlab.com/gitlab-org/gitlab/-/work_items/579385 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
    =C2=A0 ghera74--ilGhera Support System for WooCommerce The ilGhera Support = System for WooCommerce plugin for WordPress is vulnerable to unauthorized a= ccess of data due to a missing capability check on the 'get_ticket_content_= callback' function in all versions up to, and including, 1.3.0. This makes =
    it possible for unauthenticated attackers to view any support ticket conten=
    t, including sensitive customer information and private communications, by = providing a ticket ID. 2026-05-13 5.3 CVE-2025-14033 [ https://www.cve.org/= CVERecord?id=3DCVE-2025-14033 ] https://www.wordfence.com/threat-intel/vuln= erabilities/id/40ceea17-ec60-4775-8495-e2f7643d1b7c?source=3Dcve https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes= /class-wc-support-system.php#L68 https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/inc= ludes/class-wc-support-system.php#L68 https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes= /class-wc-support-system.php#L643 https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/inc= ludes/class-wc-support-system.php#L643 https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.3.1/inc= ludes/class-wc-support-system.php#L780
    =C2=A0 stylemix--Cost Calculator Builder The Cost Calculator Builder plugin=
    for WordPress is vulnerable to Unauthenticated Price Manipulation and Inse= cure Direct Object Reference (IDOR) in all versions up to, and including, 4= .0.1 only when used in combination with Cost Calculator Builder PRO. This i=
    s due to the ccb_woocommerce_payment AJAX action being registered via wp_aj= ax_nopriv, making it accessible to unauthenticated users, and the renderWoo= CommercePayment() function passing user-controlled data directly to CCBWooC= heckout::init() without authorization checks. This makes it possible for un= authenticated attackers to add WooCommerce products to their cart with atta= cker-controlled prices. 2026-05-13 5.3 CVE-2025-14755 [ https://www.cve.org= /CVERecord?id=3DCVE-2025-14755 ] https://www.wordfence.com/threat-intel/vul= nerabilities/id/fe684f43-8442-4b29-84a8-da8c6863e62b?source=3Dcve https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6= .7/includes/classes/CCBOrderController.php#L484 https://plugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6= .7/includes/classes/CCBAjaxAction.php#L99
    =C2=A0 wpclever--WPC Badge Management for WooCommerce The WPC Badge Managem= ent for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site=
    Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in=
    all versions up to, and including, 3.1.6 due to insufficient input sanitiz= ation and output escaping. This makes it possible for authenticated attacke= rs, with Shop Manager-level access and above, to inject arbitrary web scrip=
    ts in pages that will execute whenever a user accesses an injected page. 20= 26-05-13 5.5 CVE-2025-14767 [ https://www.cve.org/CVERecord?id=3DCVE-2025-1= 4767 ] https://www.wordfence.com/threat-intel/vulnerabilities/id/bf02edc9-2= bb6-4ceb-b2a1-63f95c8becb3?source=3Dcve https://wordpress.org/plugins/wpc-badge-management https://plugins.trac.wordpress.org/browser/wpc-badge-management/trunk/inclu= des/class-shortcode.php#L98 https://plugins.trac.wordpress.org/changeset/3519100/
    =C2=A0 Tp-link--TL-WR720NMbps Wireless N Router TP-Link TL-WR720N wireless = router contains a cross-site request forgery vulnerability that allows atta= ckers to perform unauthorized administrative actions by crafting malicious = web requests. Attackers can modify port forwarding rules via VirtualServerR= pm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking=
    authenticated users into visiting attacker-controlled pages. 2026-05-17 4.=
    3 CVE-2018-25321 [ https://www.cve.org/CVERecord?id=3DCVE-2018-25321 ] Expl= oitDB-44335 [ https://www.exploit-db.com/exploits/44335 ]
    Official Product Homepage [ https://www.tp-link.com/ ]
    Product Reference [ https://static.tp-link.com/resources/software/TL-WR720N= _V1_130719.zip ]
    VulnCheck Advisory: TP-Link TL-WR720N All Versions CSRF via Administrative = Interfaces [ https://www.vulncheck.com/advisories/tp-link-tl-wr720n-all-ver= sions-csrf-via-administrative-interfaces ]
    =C2=A0 Joomlaextensions--Joomla! extension JoomOCShop Joomla JoomOCShop 1.0=
    contains a cross-site request forgery vulnerability that allows attackers =
    to perform unauthorized actions on behalf of authenticated users. Attackers=
    can craft malicious HTML forms targeting account endpoints like /joomoc2/?= route=3Daccount/edit and to modify user information or reset passwords with= out user consent. 2026-05-17 4.3 CVE-2018-25337 [ https://www.cve.org/CVERe= cord?id=3DCVE-2018-25337 ] ExploitDB-44789 [ https://www.exploit-db.com/exp= loits/44789 ]
    Official Product Homepage [ https://www.joomlaextensions.co.in/ ]
    Product Reference [ https://extensions.joomla.org/extensions/extension/e-co= mmerce/e-commerce-integrations/joomocshop/ ]
    VulnCheck Advisory: Joomla JoomOCShop 1.0 Cross-Site Request Forgery [ http= s://www.vulncheck.com/advisories/joomla-joomocshop-cross-site-request-forge=
    ry ]
    =C2=A0 Easy2pilot-v7--Easy2Pilot Easy2Pilot 7 contains a cross-site request=
    forgery vulnerability that allows attackers to add unauthorized user accou= nts by tricking authenticated administrators into visiting malicious pages.=
    Attackers can craft HTML forms targeting the admin.php?action=3Dadd_user e= ndpoint with POST requests containing username and password parameters to c= reate new administrative accounts without explicit user consent. 2026-05-13=
    4.3 CVE-2020-37217 [ https://www.cve.org/CVERecord?id=3DCVE-2020-37217 ] E= xploitDB-48099 [ https://www.exploit-db.com/exploits/48099 ]
    Official Product Homepage [ http://easy2pilot-v7.com/ ]
    VulnCheck Advisory: Easy2Pilot 7 Cross-Site Request Forgery via admin.php [=
    https://www.vulncheck.com/advisories/easy2pilot-7-cross-site-request-forge= ry-via-admin-php ]
    =C2=A0 CouchCMS--CouchCMS CouchCMS 2.2.1 contains a server-side request for= gery vulnerability that allows authenticated attackers to make arbitrary HT=
    TP requests by uploading malicious SVG files. Attackers can upload SVG file=
    s containing external entity references through the browse.php endpoint to = access internal services and resources. 2026-05-15 4.3 CVE-2021-47958 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2021-47958 ] ExploitDB-49675 [ https://= www.exploit-db.com/exploits/49675 ]
    Official Product Homepage [ https://github.com/CouchCMS/CouchCMS ]
    VulnCheck Advisory: CouchCMS 2.2.1 Server-Side Request Forgery via SVG uplo=
    ad [ https://www.vulncheck.com/advisories/couchcms-server-side-request-forg= ery-via-svg-upload ]
    =C2=A0 GitLab--GitLab GitLab has remediated an issue in GitLab CE/EE affect= ing all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 b= efore 18.11.3 that could have allowed an authenticated user with Guest perm= issions to view issues in projects they were not authorized to access. 2026= -05-14 4.3 CVE-2025-13874 [ https://www.cve.org/CVERecord?id=3DCVE-2025-138=
    74 ] HackerOne Bug Bounty Report #3445398 [ https://hackerone.com/reports/3= 445398 ]
    https://gitlab.com/gitlab-org/gitlab/-/work_items/582634 https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-r= eleased/
    =C2=A0=20

    Back to top [ #top ]

    Low Vulnerabilities

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info T= here were no low vulnerabilities recorded this week.=20

    Back to top [ #top ]

    Severity Not Yet Assigned

    Primary
    Vendor -- Product Description Published CVSS Score Source Info Patch Info A= MD--AMD Ryzen 5000 Series Desktop Processors with Radeon Graphics A comprom= ised Trusted OS (TOS) driver could issue a malformed call that could potent= ially allow memory access outside the intended range resulting in loss of i= ntegrity. 2026-05-15 not yet calculated CVE-2021-26380 [ https://www.cve.or= g/CVERecord?id=3DCVE-2021-26380 ] https://www.amd.com/en/resources/product-= security/bulletin/AMD-SB-4017.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 AMD--AMD Ryzen 3000 Series Mobile Processors with Radeon Graphics A = TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow a=
    n attacker to load registers repeatedly creating a race condition potential=
    ly leading to a loss of integrity. 2026-05-15 not yet calculated CVE-2022-2= 3826 [ https://www.cve.org/CVERecord?id=3DCVE-2022-23826 ] https://www.amd.= com/en/resources/product-security/bulletin/AMD-SB-4017.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 KMX--Alien::FreeImage Alien::FreeImage versions through 1.001 for Pe=
    rl contains several vulnerable libraries. Alien::FreeImage contains version=
    3.17.0 of the FreeImage library from 2017, which has known vulnerabilities=
    such as CVE-2015-0852 and CVE-2025-65803. The library embeds other images = libraries that also have known vulnerabilities. 2026-05-11 not yet calculat=
    ed CVE-2022-4988 [ https://www.cve.org/CVERecord?id=3DCVE-2022-4988 ] https= ://freeimage.sourceforge.io/ https://metacpan.org/release/KMX/Alien-FreeImage-1.001/source/src/Source https://nvd.nist.gov/vuln/detail/CVE-2015-0852 https://nvd.nist.gov/vuln/detail/CVE-2025-65803 https://github.com/kmx/alien-freeimage/issues/4 https://github.com/kmx/alien-freeimage/issues/5
    =C2=A0 n/a--MK-Auth 23.01K4.9 An arbitrary file upload vulnerability in MK-= Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c= rafted PHP file. 2026-05-12 not yet calculated CVE-2023-27753 [ https://www= .cve.org/CVERecord?id=3DCVE-2023-27753 ] https://github.com/yueslly/MKAUTH-= RCE/blob/main/README.md
    https://github.com/yueslly/MKAUTH-RCE
    =C2=A0 n/a--MK-Auth 23.01K4.9 An insecure direct object reference in MK-Aut=
    h 23.01K4.9 allows attackers to access and send support calls for other use=
    rs via manipulation of the chamado parameter through a crafted GET request.=
    2026-05-12 not yet calculated CVE-2023-30059 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2023-30059 ] https://github.com/yueslly/MKAUTH-IDOR
    =C2=A0 AMD[.]com--AMD Radeon RX 6000 Series Graphics Products Improper vali= dation in Power Management Firmware (PMFW) may allow an attacker with privi= leges to pass malformed workload arguments when exporting table data from S=
    MU to DRAM potentially resulting in a loss of confidentiality and/or availa= bility. 2026-05-15 not yet calculated CVE-2023-31309 [ https://www.cve.org/= CVERecord?id=3DCVE-2023-31309 ] https://www.amd.com/en/resources/product-se= curity/bulletin/AMD-SB-6027.html
    =C2=A0 AMD[.]com--AMD Ryzen 5000 Series Mobile Processors with Radeon Graph= ics Improperly preserved integrity of hardware configuration state during a=
    power save/restore operation in the AMD Secure Processor (ASP) could allow=
    an attacker with the ability to write outside the trusted memory range (TM=
    R) to change the execution flow of the Video Core Next (VCN) firmware poten= tially impacting confidentiality, integrity, or availability. 2026-05-15 no=
    t yet calculated CVE-2023-31316 [ https://www.cve.org/CVERecord?id=3DCVE-20= 23-31316 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 AMD[.]com--AMD Radeon RX 6000 Series Graphics Products Improper rest= riction of operations within the bounds of a memory buffer in the AMD secur=
    e processer (ASP) could allow an attacker to read or write to protected mem= ory potentially resulting in arbitrary code execution. 2026-05-15 not yet c= alculated CVE-2023-31317 [ https://www.cve.org/CVERecord?id=3DCVE-2023-3131=
    7 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.= html
    =C2=A0 AMD[.]com--AMD Instinct MI300X An out of bounds read in the remote m= anagement firmware could allow a privileged attacker read a limited section=
    of memory outside of established bounds potentially resulting in loss of c= onfidentiality or availability. 2026-05-15 not yet calculated CVE-2024-2195=
    0 [ https://www.cve.org/CVERecord?id=3DCVE-2024-21950 ] https://www.amd.com= /en/resources/product-security/bulletin/AMD-SB-6027.html
    =C2=A0 AMD[.]com--AMD EPYC 4005 Series Processors Improper Input Validation=
    in the AMD RAID driver could allow an attacker to point to an arbitrary me= mory location potentially resulting in privilege escalation and arbitrary c= ode execution. 2026-05-15 not yet calculated CVE-2024-21962 [ https://www.c= ve.org/CVERecord?id=3DCVE-2024-21962 ] https://www.amd.com/en/resources/pro= duct-security/bulletin/AMD-SB-4016.html
    =C2=A0 AMD[.]com--AMD EPYC Series 9004 Processors Improper enforcement of t=
    he LFENCE serialization property may allow an attacker to bypass speculatio=
    n barriers and potentially disclose sensitive information, potentially resu= lting in loss of confidentiality. 2026-05-13 not yet calculated CVE-2024-36= 315 [ https://www.cve.org/CVERecord?id=3DCVE-2024-36315 ] https://www.amd.c= om/en/resources/product-security/bulletin/AMD-SB-3030.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html =C2=A0 AMD[.]com--AMD Radeon RX 7000 Series Graphics Products Improper isol= ation of VCN-JPEG HW register space could allow a malicious Guest Virtual M= achine (VM) or a process to perform unauthorized access to the register spa=
    ce of the JPEG cores assigned a victim VM/process, potentially gaining arbi= trary read/write access to the victim VM/process data. 2026-05-15 not yet c= alculated CVE-2024-36323 [ https://www.cve.org/CVERecord?id=3DCVE-2024-3632=
    3 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.= html
    =C2=A0 AMD[.]com--AMD Radeon PRO V710 Improper isolation of GPU HW register=
    space could allow a privileged attacker in malicious Guest Virtual Machine=
    (VM) to perform unauthorized access to specific victim range of GPU MMIO r= egister space, potentially causing the host OS to reboot and creating a Den= ial of Service (DOS) condition. 2026-05-15 not yet calculated CVE-2024-3633=
    2 [ https://www.cve.org/CVERecord?id=3DCVE-2024-36332 ] https://www.amd.com= /en/resources/product-security/bulletin/AMD-SB-6027.html
    =C2=A0 AMD[.]com--AMD Radeon RX 5000 Series Graphics Products A DLL hijacki=
    ng vulnerability in the AMD Cleanup Utility could allow an attacker to achi= eve privilege escalation potentially resulting in arbitrary code execution.=
    2026-05-15 not yet calculated CVE-2024-36333 [ https://www.cve.org/CVEReco= rd?id=3DCVE-2024-36333 ] https://www.amd.com/en/resources/product-security/= bulletin/AMD-SB-6027.html
    =C2=A0 AMD[.]com--AMD Radeon RX 7000 Series Graphics Products Improper veri= fication of cryptographic signature in the Radeon RGB tool could allow a ma= licious file placed in the installation directory to be run with elevated p= rivileges potentially leading to arbitrary code execution. 2026-05-15 not y=
    et calculated CVE-2024-36334 [ https://www.cve.org/CVERecord?id=3DCVE-2024-= 36334 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6= 027.html
    =C2=A0 AMD[.]com--AMD EPYC 4004 Improper input validation in the AMD OverDr= ive (AOD) System Management Mode (SMM) module could allow a privileged atta= cker to perform an out-of-bounds read, potentially resulting in loss of con= fidentiality. 2026-05-15 not yet calculated CVE-2024-36345 [ https://www.cv= e.org/CVERecord?id=3DCVE-2024-36345 ] https://www.amd.com/en/resources/prod= uct-security/bulletin/AMD-SB-3030.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html =C2=A0 Checkmk GmbH--Checkmk Privilege escalation in the mk_mysql agent plu= gin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a lo= cal unprivileged user able to create a Windows service whose name matches '= MySQL' or 'MariaDB' (or with write access to a binary referenced by such a = service) to execute arbitrary code in the context of the Checkmk agent serv= ice, which typically runs as SYSTEM. 2026-05-13 not yet calculated CVE-2024= -47091 [ https://www.cve.org/CVERecord?id=3DCVE-2024-47091 ] https://checkm= k.com/werk/19198
    =C2=A0 n/a--Ardupilot Buffer Overflow vulnerability in Ardupilot rover comm=
    it v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to ca= use a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover,=
    ADIS1647x Sensor component. 2026-05-13 not yet calculated CVE-2024-48519 [=
    https://www.cve.org/CVERecord?id=3DCVE-2024-48519 ] https://github.com/Ard= uPilot/ardupilot/issues/27937
    =C2=A0 n/a--Ardupilot Buffer Overflow vulnerability in Ardupiot Copter Late=
    st commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker =
    to cause a denial of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp compo= nents. 2026-05-13 not yet calculated CVE-2024-51394 [ https://www.cve.org/C= VERecord?id=3DCVE-2024-51394 ] https://github.com/ArduPilot/ardupilot/issue= s/28458
    =C2=A0 n/a--Ardupilot Buffer Overflow vulnerability in Ardupiot Copter Late=
    st commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker =
    to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio, AP= _SmartAudio.cpp components. 2026-05-13 not yet calculated CVE-2024-51395 [ = https://www.cve.org/CVERecord?id=3DCVE-2024-51395 ] https://github.com/Ardu= Pilot/ardupilot/issues/28374
    =C2=A0 n/a--FMT-Firmware Firmament-Autopilot FMT-Firmware commit de5aec was=
    discovered to contain a buffer overflow via the task_mavobc_entry function=
    at /comm/task_comm.c. 2026-05-13 not yet calculated CVE-2024-55045 [ https= ://www.cve.org/CVERecord?id=3DCVE-2024-55045 ] https://github.com/Firmament= -Autopilot/FMT-Firmware/issues/133
    =C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An unchecked return value within the AMD Pl= atform Management Framework (PMF) could allow an attacker to read or modify=
    an arbitrary address potentially resulting in loss of confidentiality, int= egrity, or availability. 2026-05-15 not yet calculated CVE-2025-0028 [ http= s://www.cve.org/CVERecord?id=3DCVE-2025-0028 ] https://www.amd.com/en/resou= rces/product-security/bulletin/AMD-SB-4015.html
    =C2=A0 AMD[.]com--AMD Ryzen 7040 Series Mobile Processors with Radeon Graph= ics Improper access control between the Joint Test Action Group (JTAG) and = Advanced Extensible Interface (AXI) could allow an attacker with physical a= ccess to read or overwrite the contents of cross-chip debug (XCD) registers=
    potentially resulting in loss of data integrity or confidentiality. 2026-0= 5-15 not yet calculated CVE-2025-0040 [ https://www.cve.org/CVERecord?id=3D= CVE-2025-0040 ] https://www.amd.com/en/resources/product-security/bulletin/= AMD-SB-4017.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html =C2=A0 AMD[.]com--AMD Ryzen Al Max+ An out-of-bounds read in power manageme=
    nt firmware by a malicious local attacker with low privileges could potenti= ally lead to a partial loss of confidentiality and availability. 2026-05-15=
    not yet calculated CVE-2025-0044 [ https://www.cve.org/CVERecord?id=3DCVE-= 2025-0044 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-= SB-6027.html
    =C2=A0 AMD[.]com--Athlon 3000 Series Mobile Processors with Radeon Graphics=
    Improper Input validation in the AMD Secure Processor (ASP) PCI driver may=
    allow a local attacker to create a buffer overflow condition, potentially = resulting in a crash or denial of service 2026-05-15 not yet calculated CVE= -2025-0045 [ https://www.cve.org/CVERecord?id=3DCVE-2025-0045 ] https://www= .amd.com/en/resources/product-security/bulletin/AMD-SB-4015.html https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3047.html =C2=A0 WSO2--WSO2 Identity Server Due to a lack of user account state valid= ation during authentication, locked user accounts can be successfully authe= nticated using Magic Link or Pass Key methods. This bypasses the intended s= ecurity control that should prevent access to accounts that have been locke=
    d. This vulnerability may allow unauthorized access to applications and sen= sitive data associated with accounts that should have been restricted via t=
    he account lock mechanism. It also undermines the effectiveness of the acco= unt lock mechanism intended to prevent further login attempts. 2026-05-11 n=
    ot yet calculated CVE-2025-10908 [ https://www.cve.org/CVERecord?id=3DCVE-2= 025-10908 ] https://security.docs.wso2.com/en/latest/security-announcements= /security-advisories/2026/WSO2-2025-4388/
    =C2=A0 Siemens--Simcenter Femap The affected applications contains a memory=
    corruption vulnerability while parsing specially crafted IPT files. This c= ould allow an attacker to execute code in the context of the current proces=
    s. (ZDI-CAN-27349, ZDI-CAN-27389) 2026-05-12 not yet calculated CVE-2025-12= 659 [ https://www.cve.org/CVERecord?id=3DCVE-2025-12659 ] https://cert-port= al.siemens.com/productcert/html/ssa-870926.html
    =C2=A0 silabs.com--Simplicity SDK * Countermeasures for DPA within SYMCRYPT=
    O engine on SixG301xxx devices are not sufficiently random and will eventua= lly repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerabili= ty. 2026-05-15 not yet calculated CVE-2025-14972 [ https://www.cve.org/CVER= ecord?id=3DCVE-2025-14972 ] https://community.silabs.com/068Vm00000M3cAX
    =C2=A0 n/a--Intel(R) Ethernet 800 series Use after free for some Linux kern=
    el driver for the Intel(R) Ethernet 800 series before version 2.3.14 within=
    Ring 0: Kernel may allow a denial of service. Unprivileged software advers= ary with an authenticated user combined with a low complexity attack may en= able denial of service. This result may potentially occur via local access = when attack requirements are present without special internal knowledge and=
    requires no user interaction. The potential vulnerability may impact the c= onfidentiality (none), integrity (none) and availability (high) of the vuln= erable system, resulting in subsequent system confidentiality (none), integ= rity (none) and availability (high) impacts. 2026-05-12 not yet calculated = CVE-2025-27723 [ https://www.cve.org/CVERecord?id=3DCVE-2025-27723 ] https:= //intel.com/content/www/us/en/security-center/advisory/intel-sa-01426.html =C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
    DU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics p= ackage containing symlinks is uploaded, the web server follows the supplied=
    links when serving content. No mechanisms to restrict those link targets t=
    o a specific area of the filesystem is enabled. This allows an attacker to = retrieve arbitrary files from the device. 2026-05-13 not yet calculated CVE= -2025-27850 [ https://www.cve.org/CVERecord?id=3DCVE-2025-27850 ] https://g= armin.com
    https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
    =C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
    DU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking att= ack. Among other uses, the WDU utilizes WebSockets to control settings, inc= luding administrative settings. This allows a network attacker to take full=
    control of a WDU. To initiate an exploit of this vulnerability, the victim=
    must (1) be utilizing a web browser on a multihomed host that has local in= terfaces on the Garmin Marine Network as well as another network, and (2) a= ccess a malicious third party website created by the attacker. 2026-05-13 n=
    ot yet calculated CVE-2025-27851 [ https://www.cve.org/CVERecord?id=3DCVE-2= 025-27851 ] https://garmin.com https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
    =C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
    DU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) atta= ck. This allows an attacker on the local network segment to execute arbitra=
    ry JavaScript code within the context of the WDU webpage. Full administrato=
    r level access to the device is possible. To initiate an exploit of this vu= lnerability, the victim must execute two actions: (1) view a specific URL s= erved by the WDU, and (2) click an element on the rendered page. 2026-05-13=
    not yet calculated CVE-2025-27852 [ https://www.cve.org/CVERecord?id=3DCVE= -2025-27852 ] https://garmin.com https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
    =C2=A0 Garmin[.]com--Garmin WDU The locally served web site on the Garmin W=
    DU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU = web site only performs authentication with the client within the client's b= rowser. The WebSockets used to communicate with the WDU server do not enfor=
    ce any authentication. An attacker may bypass all authentication mechanisms=
    by directly utilizing the remote APIs available on the websocket. 2026-05-=
    13 not yet calculated CVE-2025-27853 [ https://www.cve.org/CVERecord?id=3DC= VE-2025-27853 ] https://garmin.com https://www8.garmin.com/support/ch.jsp?product=3D010-02642-00
    =C2=A0 ThreadReadButtons--ThreadReadButtons striso-control-firmware 54c9722=
    is vulnerable to Buffer Overflow in function ThreadReadButtons. 2026-05-13=
    not yet calculated CVE-2025-28343 [ https://www.cve.org/CVERecord?id=3DCVE= -2025-28343 ] https://github.com/striso/striso-control-firmware/issues/5
    =C2=A0 AuxJack--AuxJack striso-control-firmware 54c9722 is vulnerable to Bu= ffer Overflow in function AuxJack. 2026-05-13 not yet calculated CVE-2025-2= 8344 [ https://www.cve.org/CVERecord?id=3DCVE-2025-28344 ] https://github.c= om/striso/striso-control-firmware/issues/6
    =C2=A0 NXP[.]com--NXP NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17= .92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overf= low via the mod_para parameter in the woal_init_module_param function. 2026= -05-13 not yet calculated CVE-2025-29338 [ https://www.cve.org/CVERecord?id= =3DCVE-2025-29338 ] https://www.nxp.com/docs/en/release-note/RN00104.pdf https://github.com/masjadaan/CVE-2025-29338
    =C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An out of bounds write within the AMD Platf= orm Management Framework (PMF) could allow an attacker to execute arbitrary=
    code at an elevated privilege level potentially leading to loss of confide= ntiality integrity, or availability. 2026-05-15 not yet calculated CVE-2025= -29935 [ https://www.cve.org/CVERecord?id=3DCVE-2025-29935 ] https://www.am= d.com/en/resources/product-security/bulletin/AMD-SB-4015.html
    =C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") Improper input validation within the AMD Pl= atform Management Framework (PMF) could allow an attacker to unmap arbitrar=
    y memory pages potentially impacting integrity and availability, or allowin=
    g privilege escalation resulting in loss of confidentiality. 2026-05-15 not=
    yet calculated CVE-2025-29936 [ https://www.cve.org/CVERecord?id=3DCVE-202= 5-29936 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB= -4015.html
    =C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An out of bounds read within the AMD Platfo=
    rm Management Framework (PMF) could allow an attacker to trigger a read of =
    an arbitrary memory location potentially resulting in loss of availability =
    or confidentiality. 2026-05-15 not yet calculated CVE-2025-29937 [ https://= www.cve.org/CVERecord?id=3DCVE-2025-29937 ] https://www.amd.com/en/resource= s/product-security/bulletin/AMD-SB-4015.html
    =C2=A0 AMD[.]com--AMD Ryzen 7035 Series Processors with Radeon Graphics (fo= rmerly codenamed "Rembrandt R") An unchecked return value within the AMD Pl= atform Management Framework (PMF) could allow an attacker to write to an ar= bitrary memory address resulting in denial of service or arbitrary code exe= cution. 2026-05-15 not yet calculated CVE-2025-29938 [ https://www.cve.org/= CVERecord?id=3DCVE-2025-29938 ] https://www.amd.com/en/resources/product-se= curity/bulletin/AMD-SB-4015.html
    =C2=A0 AMD[.]com--AMD Ryzen 4000 Series Mobile Processors with Radeon Graph= ics (formerly codenamed "Renoir") A buffer overflow vulnerability within AM=
    D Sensor Fusion Hub Driver can allow a local attacker to write out of bound=
    s, potentially resulting in denial of service or crash 2026-05-15 not yet c= alculated CVE-2025-29944 [ https://www.cve.org/CVERecord?id=3DCVE-2025-2994=
    4 ] https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4015.= html
    =C2=A0 Significant-Gravitas--AutoGPT AutoGPT is a platform that allows user=
    s to create, deploy, and manage continuous artificial intelligence agents t= hat automate complex workflows. In AutoGPT, the execution process is record=
    ed to the console (stdout/stderr), and deployed in container mode, which is=
    automatically captured by Docker and stored as "container logs". However, = prior to 0.6.32, there is no limit on the log size when the container is de= ployed. When the number of user accesses is too large, the log on the serve=
    r disk will be too large, causing disk resource exhaustion and eventually c= ausing DoS. autogpt-platform-beta-v0.6.32 fixes the issue. 2026-05-13 not y=
    et calculated CVE-2025-32425 [ https://www.cve.org/CVERecord?id=3DCVE-2025-= 32425 ] https://github.com/Significant-Gravitas/AutoGPT/security/advisories= /GHSA-vw3v-whvp-33v5 https://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be1873= 8c6ae8bb41085c71e266 https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b31245495= 43b45d933d16f622d2/autogpt_platform/autogpt_libs/autogpt_libs/logging/confi= g.py#L83-L102 https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b31245495= 43b45d933d16f622d2/autogpt_platform/docker-compose.platform.yml#L102-L142 =C2=A0 Intel[.]com--Intel(R) Server Firmware Update Utility Software Uncont= rolled search path for some Intel(R) Server Firmware Update Utility Softwar=
    e before version 16.0.12. within Ring 3: User Applications may allow an esc= alation of privilege. System software adversary with an authenticated user = combined with a high complexity attack may enable escalation of privilege. = This result may potentially occur via local access when attack requirements=
    are present without special internal knowledge and requires active user in= teraction. The potential vulnerability may impact the confidentiality (high=
    ), integrity (high) and availability (high) of the vulnerable system, resul= ting in subsequent system confidentiality (none), integrity (none) and avai= lability (none) impacts. 2026-05-12 not yet calculated CVE-2025-35969 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2025-35969 ] https://intel.com/content/= www/us/en/security-center/advisory/intel-sa-01410.html
    =C2=A0 Intel[.]com--Intel(R) Processors Exposure of sensitive information c= aused by shared microarchitectural predictor state that influences transien=
    t execution for some Intel(R) Processors within VMX non-root (guest) operat= ion may allow an information disclosure. Unprivileged software adversary wi=
    th an authenticated user combined with a high complexity attack may enable = data exposure. This result may potentially occur via local access when atta=
    ck requirements are present without special internal knowledge and requires=
    no user interaction. The potential vulnerability may impact the confidenti= ality (high), integrity (none) and availability (none) of the vulnerable sy= stem, resulting in subsequent system confidentiality (high), integrity (non=
    e) and availability (none) impacts. 2026-05-12 not yet calculated CVE-2025-= 35979 [ https://www.cve.org/CVERecord?id=3DCVE-2025-35979 ] https://intel.c= om/content/www/us/en/security-center/advisory/intel-sa-01420.html
    =C2=A0 Intel[.]com--Intel Endpoint Management Assistant (EMA) software Impr= oper input validation for some Intel Endpoint Management Assistant (EMA) so= ftware before version 1.14.5 within Ring 3: User Applications may allow an = escalation of privilege. Unprivileged software adversary with an unauthenti= cated user combined with a low complexity attack may enable escalation of p= rivilege. This result may potentially occur via adjacent access when attack=
    requirements are not present without special internal knowledge and requir=
    es no user interaction. The potential vulnerability may impact the confiden= tiality (high), integrity (high) and availability (high) of the vulnerable = system, resulting in subsequent system confidentiality (none), integrity (n= one) and availability (none) impacts. 2026-05-12 not yet calculated CVE-202= 5-35990 [ https://www.cve.org/CVERecord?id=3DCVE-2025-35990 ] https://intel= .com/content/www/us/en/security-center/advisory/intel-sa-01434.html
    =C2=A0 Intel[.]com--Intel platforms Improper initialization in the UEFI fir= mware for some Intel platforms within Ring 0: Bare Metal OS may allow an in= formation disclosure. System software adversary with a privileged user comb= ined with a high complexity attack may enable data exposure. This result ma=
    y potentially occur via local access when attack requirements are present w= ithout special internal knowledge and requires no user interaction. The pot= ential vulnerability may impact the confidentiality (high), integrity (none=
    ) and availability (none) of the vulnerable system, resulting in subsequent=
    system confidentiality (none), integrity (none) and availability (none) im= pacts. 2026-05-12 not yet calculated CVE-2025-35991 [ https://www.cve.org/C= VERecord?id=3DCVE-2025-35991 ] https://intel.com/content/www/us/en/security= -center/advisory/intel-sa-01413.html
    =C2=A0 Intel[.]com--Display Virtualization for Windows OS driver software I= mproper buffer restrictions for some Display Virtualization for Windows OS = driver software within Ring 2: Device Drivers may allow a denial of service=
    . Unprivileged software adversary with an authenticated user combined with =
    a low complexity attack may enable denial of service. This result may poten= tially occur via local access when attack requirements are not present with= out special internal knowledge and requires no user interaction. The potent= ial vulnerability may impact the confidentiality (none), integrity (none) a=
    nd availability (high) of the vulnerable system, resulting in subsequent sy= stem confidentiality (none), integrity (none) and availability (none) impac= ts. 2026-05-12 not yet calculated CVE-2025-36510 [ https://www.cve.org/CVER= ecord?id=3DCVE-2025-36510 ] https://intel.com/content/www/us/en/security-ce= nter/advisory/intel-sa-01430.html
    =C2=A0 Intel[.]com--AI Playground software Uncontrolled search path for som=
    e AI Playground software before version 3.0.0 alpha within Ring 3: User App= lications may allow an escalation of privilege. Unprivileged software adver= sary with an authenticated user combined with a high complexity attack may = enable escalation of privilege. This result may potentially occur via local=
    access when attack requirements are present without special internal knowl= edge and requires active user interaction. The potential vulnerability may = impact the confidentiality (high), integrity (high) and availability (high)=
    of the vulnerable system, resulting in subsequent system confidentiality (= none), integrity (none) and availability (none) impacts. 2026-05-12 not yet=
    calculated CVE-2025-36515 [ https://www.cve.org/CVERecord?id=3DCVE-2025-36= 515 ] https://intel.com/content/www/us/en/security-center/advisory/intel-sa= -01438.html
    =C2=A0=20

    Back to top [ #top ]

    body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
    : normal; font-style: normal; color: #333333; }=20

    Having trouble viewing this message?=C2=A0View it as a webpage [ https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/417e991 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]

    You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [ https://www.cisa.gov ] (CISA)
    Manage Subscriptions [ https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [ https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]

    Connect with CISA:=20
    Facebook [ https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [ https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [ https://Instagram.com/cisag=
    ov ]=C2=A0 |=C2=A0 LinkedIn [ https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]

    ________________________________________________________________________

    This email was sent to cisa@toolazy.synchro.net using GovDelivery Communica= tions Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency=
    =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ = https://subscriberhelp.granicus.com/ ]=20
    body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
    y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}

    --===============7146585765089518506==
    Content-Type: text/html; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns=3D"http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
    <title> Vulnerability Summary for the Week of May 11, 2026
    </title>


    </head>
    <body style=3D"">

    <table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
    align=3D"center">
    <tr>
    <td>

    <!--[if (gte mso 9)|(IE)]>
    <table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
    <![endif]-->
    <a name=3D"gd_top" id=3D"gd_top"></a>

    =20



    <p><img src=3D"https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
    <p>You are subscribed to Vulnerability Bulletins for Cybersecurity and In= frastructure Security Agency. This information has recently been updated an=
    d is now available.</p>
    <p>The CISA Vulnerability Bulletin provides a summary of new vulnerabilitie=
    s that have been recorded in the past week. In some cases, the vulnerabilit= ies in the bulletin may not yet have assigned CVSS scores.</p> <p>Vulnerabilities are based on the=C2=A0<a href=3D"https://www.cve.org/" t= arget=3D"_blank" class=3D"ext" data-extlink=3D"" rel=3D"noopener">Common Vu= lnerabilities and Exposures</a>=C2=A0(CVE) vulnerability naming standard an=
    d are organized according to severity, determined by the=C2=A0<a href=3D"ht= tps://www.cve.org/about/relatedefforts" target=3D"_blank" rel=3D"noopener">= Common Vulnerability Scoring System</a>=C2=A0(CVSS) standard. The division =
    of high, medium, and low severities correspond to the following scores:</p>


    <strong>High</strong>: vulnerabilities with a CVSS base score of 7.0=E2=80= =9310.0</li>

    <strong>Medium</strong>: vulnerabilities with a CVSS base score of 4.0=E2= =80=936.9</li>

    <strong>Low</strong>: vulnerabilities with a CVSS base score of 0.0=E2=80= =933.9</li>
    </ul>
    <p>Entries may include additional information provided by organizations and=
    efforts sponsored by CISA. This information may include identifying inform= ation, values, definitions, and related links. Patch information is provide=
    d when available. Please note that some of the information in the bulletin =
    is compiled from external, open-source reports and is not a direct result o=
    f CISA analysis.</p>
    <p>=C2=A0</p>
    <div class=3D"rss_item" style=3D"margin-bottom: 2em;">
    <div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
    n: 0 0 0.3em; padding: 0;"><a href=3D"https://www.cisa.gov/news-events/bull= etins/sb26-138">Vulnerability Summary for the Week of May 11, 2026</a></div=

    <div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">05/18/2026 05:00 PM EDT</div>

    <div class=3D"rss_description" style=3D"margin: 0 0 0.3em; padding: 0;">
    <div id=3D"high_v">
    <h2 id=3D"high_v_title">High Vulnerabilities</h2>
    <table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"High Vulnerabilities">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">acl--ACL Analytics</td>
    <td>ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary cod=
    e execution vulnerability that allows attackers to execute arbitrary comman=
    ds by leveraging the EXECUTE function. Attackers can use bitsadmin to downl= oad malicious PowerShell scripts and execute them with system privileges to=
    establish reverse shells and gain complete system control.</td> <td>2026-05-17</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25320" target=3D= "_blank" rel=3D"noopener">CVE-2018-25320</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44281" target=3D"_blank" rel= =3D"noopener">ExploitDB-44281</a><br><a href=3D"https://www.acl.com" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://www.acl.com/products/acl-analytics/" target=3D"_blank" rel=3D"noopene= r">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisories= /acl-analytics-11-x-arbitrary-code-execution" target=3D"_blank" rel=3D"noop= ener">VulnCheck Advisory: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Ex= ecution</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">gitbucket--GitBucket</td>
    <td>GitBucket 4.23.1 contains an unauthenticated remote code execution vuln= erability that allows attackers to execute arbitrary commands by exploiting=
    weak secret token generation and insecure file upload functionality. Attac= kers can brute-force the Blowfish encryption key, upload a malicious JAR pl= ugin via the git-lfs endpoint, and execute system commands through an expos=
    ed exploit endpoint.</td>
    <td>2026-05-17</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25332" target=3D= "_blank" rel=3D"noopener">CVE-2018-25332</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44668" target=3D"_blank" rel= =3D"noopener">ExploitDB-44668</a><br><a href=3D"https://security.szurek.pl/=
    " target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"https://github.com/gitbucket/gitbucket" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisor= ies/gitbucket-unauthenticated-remote-code-execution" target=3D"_blank" rel= =3D"noopener">VulnCheck Advisory: GitBucket 4.23.1 Unauthenticated Remote C= ode Execution</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">peugeot-music-plugin--Peugeot Music</td> <td>WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vu= lnerability that allows unauthenticated attackers to upload malicious files=
    by sending POST requests to the upload.php endpoint. Attackers can upload = files with arbitrary extensions by manipulating the 'name' parameter to exe= cute code from the uploads directory.</td>
    <td>2026-05-17</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25335" target=3D= "_blank" rel=3D"noopener">CVE-2018-25335</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44737" target=3D"_blank" rel= =3D"noopener">ExploitDB-44737</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/wordpress-plugin-peugeot-music-arbitrary-file-upload" target=3D"_= blank" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin Peugeot Music = 1.0 Arbitrary File Upload</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Paiement--Ecommerce Systempay</td>
    <td>Ecommerce Systempay 1.0 contains a weak cryptographic implementation vu= lnerability that allows attackers to brute force the 16-character productio=
    n secret key used for payment signature generation. Attackers can extract p= ayment form data and signatures from POST requests to the payment endpoint,=
    then use SHA1 hash comparison to iteratively test key candidates until dis= covering the correct production key, enabling them to forge valid payment s= ignatures and manipulate transaction amounts.</td>
    <td>2026-05-13</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37168" target=3D= "_blank" rel=3D"noopener">CVE-2020-37168</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48017" target=3D"_blank" rel= =3D"noopener">ExploitDB-48017</a><br><a href=3D"https://paiement.systempay.= fr/doc/fr-FR/" target=3D"_blank" rel=3D"noopener">Official Product Homepage= </a><br><a href=3D"https://paiement.systempay.fr/doc/fr-FR/module-de-paieme= nt-gratuit/" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a=
    href=3D"https://www.vulncheck.com/advisories/ecommerce-systempay-productio= n-key-brute-force" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: E= commerce Systempay 1.0 Production Key Brute Force</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Yerootech--iDS6 DSSPro Digital Signage System<=

    <td>iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypa=
    ss vulnerability that allows attackers to bypass authentication by requesti=
    ng the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA cod=
    es via the login endpoint and use them to perform brute-force attacks again=
    st user accounts.</td>
    <td>2026-05-16</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37228" target=3D= "_blank" rel=3D"noopener">CVE-2020-37228</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48991" target=3D"_blank" rel= =3D"noopener">ExploitDB-48991</a><br><a href=3D"https://www.zeroscience.mk/= en/vulnerabilities/ZSL-2020-5607.php" target=3D"_blank" rel=3D"noopener">Vu= lnerability Advisory</a><br><a href=3D"http://www.yerootech.com" target=3D"= _blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"https:= //www.vulncheck.com/advisories/ids6-dsspro-digital-signage-system-captcha-s= ecurity-bypass" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: iDS6=
    DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Gegl--libbabl</td>
    <td>libbabl 0.1.62 contains a broken double free detection vulnerability th=
    at allows attackers to bypass memory safety checks by exploiting signature = overwriting in freed chunks. Attackers can call babl_free() twice on the sa=
    me pointer without triggering detection, as libc's malloc metadata overwrit=
    es babl's signature field upon freeing, enabling potential memory corruptio=
    n and code execution.</td>
    <td>2026-05-16</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37239" target=3D= "_blank" rel=3D"noopener">CVE-2020-37239</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49259" target=3D"_blank" rel= =3D"noopener">ExploitDB-49259</a><br><a href=3D"https://www.gegl.org" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.gegl.org/babl/" target=3D"_blank" rel=3D"noopener">Product Refer= ence</a><br><a href=3D"https://www.vulncheck.com/advisories/libbabl-broken-= double-free-detection-memory-safety" target=3D"_blank" rel=3D"noopener">Vul= nCheck Advisory: libbabl 0.1.62 Broken Double Free Detection Memory Safety<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Jsonpickle--python jsonpickle</td>
    <td>python jsonpickle 2.0.0 contains a remote code execution vulnerability = that allows attackers to execute arbitrary Python commands by deserializing=
    malicious JSON payloads containing py/repr objects. Attackers can craft JS=
    ON strings with py/repr directives that invoke the eval function during des= erialization to execute system commands and arbitrary code.</td> <td>2026-05-16</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47952" target=3D= "_blank" rel=3D"noopener">CVE-2021-47952</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49585" target=3D"_blank" rel= =3D"noopener">ExploitDB-49585</a><br><a href=3D"https://jsonpickle.github.i=
    o" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a h= ref=3D"https://github.com/jsonpickle/jsonpickle" target=3D"_blank" rel=3D"n= oopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advi= sories/python-jsonpickle-remote-code-execution-via-py-repr" target=3D"_blan=
    k" rel=3D"noopener">VulnCheck Advisory: python jsonpickle 2.0.0 Remote Code=
    Execution via py/repr</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wp-super-edit--WP Super Edit</td>
    <td>WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestrict=
    ed file upload vulnerability in the FCKeditor component that allows attacke=
    rs to upload dangerous file types without validation. Attackers can upload = arbitrary files through the filemanager upload endpoint to achieve remote c= ode execution and complete system compromise.</td>
    <td>2026-05-15</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47965" target=3D= "_blank" rel=3D"noopener">CVE-2021-47965</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49839" target=3D"_blank" rel= =3D"noopener">ExploitDB-49839</a><br><a href=3D"https://wordpress.org" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"= https://wordpress.org/plugins/wp-super-edit/" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisor= ies/wordpress-plugin-wp-super-edit-unrestricted-file-upload" target=3D"_bla= nk" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin WP Super Edit 2.5=
    .4 Unrestricted File Upload</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Akilli Commerce Software Technologies Ltd. Co.= --E-Commerce Website</td>
    <td>Improper neutralization of special elements used in an SQL command ('SQ=
    L injection') vulnerability in Akilli Commerce Software Technologies Ltd. C=
    o. E-Commerce Website allows Blind SQL Injection. This issue affects E-Comm= erce Website: before 4.5.001.</td>
    <td>2026-05-14</td>
    <td>9.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-11024" target=3D= "_blank" rel=3D"noopener">CVE-2025-11024</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 222" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0222</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Hitachi Vantara--Pentaho Data Integration and = Analytics</td>
    <td>Hitachi Vantara Pentaho Data Integration &amp; Analytics of all version=
    s contain a JDBC driver for H2 databases which is vulnerable to external sc= ript execution when a new connection is created by a=C2=A0data source admin= istrator.</td>
    <td>2026-05-13</td>
    <td>9.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-11159" target=3D= "_blank" rel=3D"noopener">CVE-2025-11159</a></td>

    <a href=3D"https://support.pentaho.com/hc/en-us/articles/39954640408077--Re= solved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Dependency-on-Vul= nerable-Third-Party-Component-Versions-before-10-2-0-7-and-11-0-0-0-Impacte= d-CVE-2025-11159" target=3D"_blank" rel=3D"noopener">https://support.pentah= o.com/hc/en-us/articles/39954640408077--Resolved-Hitachi-Vantara-Pentaho-Da= ta-Integration-Analytics-Dependency-on-Vulnerable-Third-Party-Component-Ver= sions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2025-11159</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">alloksoft--Fast AVI MPEG Splitter</td>
    <td>Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow=
    vulnerability that allows local attackers to execute arbitrary code by sup= plying a malicious license name string. Attackers can craft a payload with = 780 bytes of junk data followed by structured shellcode and place it in the=
    License Name field to trigger the overflow and execute code with applicati=
    on privileges.</td>
    <td>2026-05-17</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25322" target=3D= "_blank" rel=3D"noopener">CVE-2018-25322</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44341" target=3D"_blank" rel= =3D"noopener">ExploitDB-44341</a><br><a href=3D"http://www.alloksoft.com" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"http://www.alloksoft.com/allok_vconverter.exe" target=3D"_blank" rel=3D= "noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/ad= visories/allok-fast-avi-mpeg-splitter-stack-based-buffer-overflow" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Allok Fast AVI MPEG Splitt=
    er 1.2 Stack Based Buffer Overflow</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Alloksoft--Allok AVI DivX MPEG to DVD Converte= r</td>
    <td>Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exc= eption handler buffer overflow vulnerability that allows local attackers to=
    execute arbitrary code by supplying a malicious payload. Attackers can cra=
    ft a text file with a specially crafted buffer containing shellcode and SEH=
    chain overwrite values, then paste the contents into the License Name fiel=
    d to trigger code execution.</td>
    <td>2026-05-17</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25323" target=3D= "_blank" rel=3D"noopener">CVE-2018-25323</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44363" target=3D"_blank" rel= =3D"noopener">ExploitDB-44363</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/allok-avi-divx-mpeg-to-dvd-converter-buffer-overflow-seh" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Allok AVI DivX MPEG to DVD=
    Converter 2.6.1217 Buffer Overflow SEH</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">vxsearch--VX Search</td>
    <td>VX Search 10.6.18 contains a local buffer overflow vulnerability that a= llows attackers to overwrite the instruction pointer by supplying an oversi= zed string in the directory field. Attackers can craft a malicious input fi=
    le containing 271 bytes of junk data followed by a return address to execut=
    e arbitrary code with application privileges.</td>
    <td>2026-05-17</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25328" target=3D= "_blank" rel=3D"noopener">CVE-2018-25328</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44494" target=3D"_blank" rel= =3D"noopener">ExploitDB-44494</a><br><a href=3D"https://www.7elements.co.uk=
    " target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"http://www.vxsearch.com" target=3D"_blank" rel=3D"noopener">Official = Product Homepage</a><br><a href=3D"https://www.vulncheck.com/advisories/vx-= search-local-buffer-overflow-via-directory-field" target=3D"_blank" rel=3D"= noopener">VulnCheck Advisory: VX Search 10.6.18 Local Buffer Overflow via D= irectory Field</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Joomlaextensions--Joomla! extension EkRishta</=

    <td>Joomla! extension EkRishta 2.10 contains persistent cross-site scriptin=
    g and SQL injection vulnerabilities that allow attackers to inject maliciou=
    s code through profile fields and POST parameters. Attackers can inject scr= ipt payloads in profile information fields like Address that execute when u= sers visit the profile, or submit SQL injection payloads via the phone_no p= arameter to the user_setting endpoint to manipulate database queries.</td> <td>2026-05-17</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25330" target=3D= "_blank" rel=3D"noopener">CVE-2018-25330</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44660" target=3D"_blank" rel= =3D"noopener">ExploitDB-44660</a><br><a href=3D"https://www.joomlaextension= s.co.in/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><= br><a href=3D"https://extensions.joomla.org/extensions/extension/living/dat= ing-a-relationships/ek-rishta/" target=3D"_blank" rel=3D"noopener">Product = Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/joomla-ekr= ishta-persistent-xss-and-sql-injection" target=3D"_blank" rel=3D"noopener">= VulnCheck Advisory: Joomla! EkRishta 2.10 Persistent XSS and SQL Injection<= /a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">nordex-online--N149 Wind Turbine Web Server</t=

    <td>Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injecti=
    on vulnerability that allows unauthenticated attackers to execute arbitrary=
    SQL queries by injecting malicious code through the login parameter in log= in.php. Attackers can submit crafted POST requests with SQL injection paylo= ads in the login field to extract sensitive database information and bypass=
    authentication mechanisms.</td>
    <td>2026-05-17</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25333" target=3D= "_blank" rel=3D"noopener">CVE-2018-25333</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44684" target=3D"_blank" rel= =3D"noopener">ExploitDB-44684</a><br><a href=3D"http://www.nordex-online.co=
    m" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a h= ref=3D"https://www.vulncheck.com/advisories/nordex-n149-wind-turbine-web-se= rver-sql-injection" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: = Nordex N149/4.0-4.5 Wind Turbine Web Server SQL Injection</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Bylancer--Zechat</td>
    <td>Zechat 1.5 contains a SQL injection vulnerability in the hashtag parame= ter that allows unauthenticated attackers to extract database information u= sing union-based techniques. Attackers can exploit the hashtag parameter wi=
    th union-based payloads to retrieve table and column names.</td> <td>2026-05-17</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25338" target=3D= "_blank" rel=3D"noopener">CVE-2018-25338</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44685" target=3D"_blank" rel= =3D"noopener">ExploitDB-44685</a><br><a href=3D"https://bylancer.com" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/zechat-sql-injection-via-hashtag-parame= ter" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Zechat 1.5 SQL = Injection via hashtag parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Bylancer--Zechat</td>
    <td>Zechat 1.5 contains a SQL injection vulnerability in the v parameter th=
    at allows unauthenticated attackers to extract database information using t= ime-based blind techniques. Attackers can exploit the v parameter with slee= p-based blind injection to confirm vulnerability and extract data.</td> <td>2026-05-17</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25339" target=3D= "_blank" rel=3D"noopener">CVE-2018-25339</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44685" target=3D"_blank" rel= =3D"noopener">ExploitDB-44685</a><br><a href=3D"https://bylancer.com" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/zechat-sql-injection-via-v-parameter-ti= me-based-blind" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Zech=
    at 1.5 SQL Injection via v parameter (time-based blind)</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">Hdwplayer--com_hdwplayer</td>
    <td>Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the=
    search.php file that allows unauthenticated attackers to execute arbitrary=
    SQL queries by injecting malicious code through the hdwplayersearch parame= ter. Attackers can submit POST requests with crafted SQL payloads in the hd= wplayersearch parameter to extract sensitive database information from the = hdwplayer_videos table.</td>
    <td>2026-05-13</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37218" target=3D= "_blank" rel=3D"noopener">CVE-2020-37218</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48242" target=3D"_blank" rel= =3D"noopener">ExploitDB-48242</a><br><a href=3D"https://www.hdwplayer.com/"=
    target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hre= f=3D"https://www.hdwplayer.com/download/" target=3D"_blank" rel=3D"noopener= ">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/= joomla-com-hdwplayer-sql-injection-via-search-php" target=3D"_blank" rel=3D= "noopener">VulnCheck Advisory: Joomla com_hdwplayer 4.2 SQL Injection via s= earch.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Drive-software--Atomic Alarm Clock</td>
    <td>Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that all= ows local attackers to execute arbitrary code by supplying a malicious stri=
    ng to the display name textbox in the Time Zones Clock configuration. Attac= kers can craft a buffer with structured exception handling overwrite and en= coded shellcode to bypass SafeSEH protections and execute arbitrary command=
    s with application privileges.</td>
    <td>2026-05-13</td>
    <td>8.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37221" target=3D= "_blank" rel=3D"noopener">CVE-2020-37221</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48346" target=3D"_blank" rel= =3D"noopener">ExploitDB-48346</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/atomic-alarm-clock-stack-overflow-via-seh-unicode" target=3D"_bla= nk" rel=3D"noopener">VulnCheck Advisory: Atomic Alarm Clock 6.3 Stack Overf= low via SEH Unicode</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Heliossolutions--HS Brand Logo Slider</td>
    <td>HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerabi= lity that allows authenticated users to bypass client-side file extension v= alidation by uploading arbitrary files. Attackers can intercept upload requ= ests to the logoupload parameter in the admin interface and rename files to=
    executable extensions .php to achieve remote code execution.</td> <td>2026-05-16</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37227" target=3D= "_blank" rel=3D"noopener">CVE-2020-37227</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48913" target=3D"_blank" rel= =3D"noopener">ExploitDB-48913</a><br><a href=3D"https://www.heliossolutions= .co/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><=
    a href=3D"https://ms.wordpress.org/plugins/hs-brand-logo-slider/" target=3D= "_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://www.v= ulncheck.com/advisories/wordpress-plugin-hs-brand-logo-slider-unrestricted-= file-upload" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPre=
    ss Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload</a><br>=C2=A0</=

    </tr>

    <td class=3D"vendor-product">Supsystic--Ultimate Maps</td>
    <td>Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability = that allows unauthenticated attackers to execute arbitrary SQL queries by i= njecting malicious code through the 'sidx' GET parameter. Attackers can sen=
    d crafted requests to the getListForTbl action with boolean-based blind or = time-based blind SQL injection payloads to extract sensitive database infor= mation.</td>
    <td>2026-05-16</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37242" target=3D= "_blank" rel=3D"noopener">CVE-2020-37242</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49532" target=3D"_blank" rel= =3D"noopener">ExploitDB-49532</a><br><a href=3D"https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "https://downloads.wordpress.org/plugin/ultimate-maps-by-supsystic.1.1.12.z= ip" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"= https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-ultimate-ma= ps-sql-injection-via-sidx" target=3D"_blank" rel=3D"noopener">VulnCheck Adv= isory: WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via si= dx</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Supsystic--Pricing Table</td>
    <td>Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability i=
    n the 'sidx' GET parameter that allows unauthenticated attackers to execute=
    arbitrary SQL queries through the getListForTbl action. The plugin also co= ntains stored cross-site scripting vulnerabilities in the 'Edit name' and '= Edit HTML' fields that execute malicious scripts when viewing pricing table= s.</td>
    <td>2026-05-16</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37243" target=3D= "_blank" rel=3D"noopener">CVE-2020-37243</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49533" target=3D"_blank" rel= =3D"noopener">ExploitDB-49533</a><br><a href=3D"https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "https://downloads.wordpress.org/plugin/pricing-table-by-supsystic.1.8.7.zi=
    p" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/wordpress-plugin-supsystic-pricing-tabl= e-sql-injection-xss" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory:=
    WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Supsystic--Membership</td>
    <td>Supsystic Membership 1.4.7 contains an SQL injection vulnerability that=
    allows unauthenticated attackers to execute arbitrary SQL queries by injec= ting malicious code through the 'search' and 'sidx' parameters. Attackers c=
    an send GET requests to the badges module with crafted payloads to extract = sensitive database information using time-based blind or UNION-based SQL in= jection techniques.</td>
    <td>2026-05-16</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37244" target=3D= "_blank" rel=3D"noopener">CVE-2020-37244</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49540" target=3D"_blank" rel= =3D"noopener">ExploitDB-49540</a><br><a href=3D"https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "https://downloads.wordpress.org/plugin/membership-by-supsystic.1.4.7.zip" = target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"http= s://www.vulncheck.com/advisories/wordpress-plugin-supsystic-membership-sql-= injection-via-sidx" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: = WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">LayerBB--LayerBB</td>
    <td>LayerBB 1.1.4 contains an SQL injection vulnerability that allows unaut= henticated attackers to manipulate database queries by injecting SQL code t= hrough the search_query parameter. Attackers can send POST requests to /sea= rch.php with malicious search_query values using CASE WHEN statements to ex= tract sensitive database information.</td>
    <td>2026-05-16</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47954" target=3D= "_blank" rel=3D"noopener">CVE-2021-47954</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49593" target=3D"_blank" rel= =3D"noopener">ExploitDB-49593</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/layerbb-sql-injection-via-search-query-parameter" target=3D"_blan=
    k" rel=3D"noopener">VulnCheck Advisory: LayerBB 1.1.4 SQL Injection via sea= rch_query Parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Egavilanmedia--EgavilanMedia PHPCRUD</td> <td>EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that = allows unauthenticated attackers to manipulate database queries by injectin=
    g SQL code through the firstname parameter. Attackers can send POST request=
    s to insert.php with malicious firstname values to extract sensitive databa=
    se information.</td>
    <td>2026-05-16</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47956" target=3D= "_blank" rel=3D"noopener">CVE-2021-47956</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49878" target=3D"_blank" rel= =3D"noopener">ExploitDB-49878</a><br><a href=3D"https://egavilanmedia.com" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://egavilanmedia.com/crud-operation-with-php-mysql-bootstrap-and-d= ompdf/" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href= =3D"https://www.vulncheck.com/advisories/egavilanmedia-phpcrud-sql-injectio= n-via-firstname" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Ega= vilanMedia PHPCRUD 1.0 SQL Injection via firstname</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Schlix--Schlix CMS</td>
    <td>Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that = allows authenticated attackers to execute arbitrary PHP code by uploading m= alicious extension packages through the block manager. Attackers can upload=
    a crafted ZIP file containing PHP code in the packageinfo.inc file and tri= gger execution by accessing the About tab of the installed extension.</td> <td>2026-05-15</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47964" target=3D= "_blank" rel=3D"noopener">CVE-2021-47964</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49838" target=3D"_blank" rel= =3D"noopener">ExploitDB-49838</a><br><a href=3D"https://www.schlix.com/" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://www.schlix.com/downloads/schlix-cms/schlix-cms-v2.2.6-6.zip" ta= rget=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:= //www.vulncheck.com/advisories/schlix-cms-6-remote-code-execution-via-core-= blockmanager" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Schlix=
    CMS 2.2.6-6 Remote Code Execution via core.blockmanager</a><br>=C2=A0</td> </tr>

    <td class=3D"vendor-product">Timeclock--PHP Timeclock</td>
    <td>PHP Timeclock 1.04 contains time-based and boolean-based blind SQL inje= ction vulnerabilities in the login_userid parameter of login.php that allow=
    s unauthenticated attackers to extract database contents. Attackers can sub= mit crafted POST requests with SQL payloads using SLEEP functions or RLIKE = conditional statements to dump sensitive database information including emp= loyee names and credentials.</td>
    <td>2026-05-15</td>
    <td>8.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47966" target=3D= "_blank" rel=3D"noopener">CVE-2021-47966</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49849" target=3D"_blank" rel= =3D"noopener">ExploitDB-49849</a><br><a href=3D"http://timeclock.sourceforg= e.net" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br>=
    <a href=3D"https://sourceforge.net/projects/timeclock/files/PHP%20Timeclock= /PHP%20Timeclock%201.04/" target=3D"_blank" rel=3D"noopener">Product Refere= nce</a><br><a href=3D"https://www.vulncheck.com/advisories/php-timeclock-sq= l-injection-via-login-php" target=3D"_blank" rel=3D"noopener">VulnCheck Adv= isory: PHP Timeclock 1.04 SQL Injection via login.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Textpattern--TextPattern CMS</td>
    <td>TextPattern CMS 4.9.0-dev contains a remote code execution vulnerabilit=
    y that allows authenticated attackers to upload arbitrary PHP files by expl= oiting the plugin upload functionality. Attackers can authenticate, retriev=
    e a CSRF token from the plugin event page, and upload malicious PHP files t=
    o the textpattern/tmp/ directory for code execution.</td>
    <td>2026-05-16</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47976" target=3D= "_blank" rel=3D"noopener">CVE-2021-47976</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50095" target=3D"_blank" rel= =3D"noopener">ExploitDB-50095</a><br><a href=3D"https://textpattern.com/" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://github.com/textpattern/textpattern" target=3D"_blank" rel=3D"no= opener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advis= ories/textpattern-cms-dev-authenticated-remote-code-execution-via-plugin-up= load" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: TextPattern CM=
    S 4.9.0-dev Authenticated Remote Code Execution via Plugin Upload</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Miniorange--Backup and Restore</td>
    <td>WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file de= letion vulnerability that allows authenticated attackers to delete files by=
    manipulating parameters in AJAX requests. Attackers can send POST requests=
    to admin-ajax.php with crafted file_name and folder_name parameters to del= ete arbitrary files from the WordPress installation directory.</td> <td>2026-05-16</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47979" target=3D= "_blank" rel=3D"noopener">CVE-2021-47979</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50503" target=3D"_blank" rel= =3D"noopener">ExploitDB-50503</a><br><a href=3D"https://www.miniorange.com/=
    " target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"https://wordpress.org/plugins/backup-and-restore-for-wp/" target=3D"_= blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://www.vul= ncheck.com/advisories/wordpress-plugin-backup-and-restore-arbitrary-file-de= letion" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPress Pl= ugin Backup and Restore 1.0.3 Arbitrary File Deletion</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
    <td>The Magic Link authentication flow accepts multiple invalid authenticat= ion requests without adequate rate limiting or resource control, leading to=
    uncontrolled memory usage growth. This vulnerability can result in a denia= l-of-service condition, causing service unavailability for deployments that=
    utilize the Magic Link authenticator. The impact is limited to these speci= fic deployments and requires repeated invalid authentication attempts to tr= igger.</td>
    <td>2026-05-11</td>
    <td>8.6</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-10470" target=3D= "_blank" rel=3D"noopener">CVE-2025-10470</a></td>

    <a href=3D"https://security.docs.wso2.com/en/latest/security-announcements/= security-advisories/2026/WSO2-2025-4469/" target=3D"_blank" rel=3D"noopener= ">https://security.docs.wso2.com/en/latest/security-announcements/security-= advisories/2026/WSO2-2025-4469/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">APPYAP Technology and Information Inc.--Yaay S= ocial Media App</td>
    <td>Authorization bypass through User-Controlled key vulnerability in APPYA=
    P Technology and Information Inc. Yaay Social Media App allows Accessing Fu= nctionality Not Properly Constrained by ACLs. This issue affects Yaay Socia=
    l Media App: from 3.8.0 through 24102025.</td>
    <td>2026-05-14</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-12008" target=3D= "_blank" rel=3D"noopener">CVE-2025-12008</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 238" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0238</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Automation Sys= tem</td>
    <td>Incorrect Authorization vulnerability in Yordam Information Technology = Consulting, Training and Electronic Systems Industry and Trade Inc. Library=
    Automation System allows Exploiting Incorrectly Configured Access Control = Security Levels. This issue affects Library Automation System: from v.19.5 = before v.22.1.</td>
    <td>2026-05-14</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15023" target=3D= "_blank" rel=3D"noopener">CVE-2025-15023</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 240" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0240</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Automation Sys= tem</td>
    <td>Improper Control of Generation of Code ('Code Injection') vulnerability=
    in Yordam Information Technology Consulting, Training and Electronic Syste=
    ms Industry and Trade Inc. Library Automation System allows Remote Code Inc= lusion. This issue affects Library Automation System: from v.19.5 before v.= 22.1.</td>
    <td>2026-05-14</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15024" target=3D= "_blank" rel=3D"noopener">CVE-2025-15024</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 240" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0240</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Automation Sys= tem</td>
    <td>Authorization bypass through User-Controlled key vulnerability in Yorda=
    m Information Technology Consulting, Training and Electronic Systems Indust=
    ry and Trade Inc. Library Automation System allows Exploitation of Trusted = Identifiers. This issue affects Library Automation System: from v.21.6 befo=
    re v.22.1.</td>
    <td>2026-05-14</td>
    <td>8.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15025" target=3D= "_blank" rel=3D"noopener">CVE-2025-15025</a></td>

    <a href=3D"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0= 240" target=3D"_blank" rel=3D"noopener">https://siberguvenlik.gov.tr/guvenl= ik-bildirimleri/detay/tr-26-0240</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wende60--Redaxo CMS Addon MyEvents</td>
    <td>Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability=
    that allows authenticated attackers to manipulate database queries by inje= cting SQL code through the myevents_id parameter. Attackers can send GET re= quests to the event_add.php page with malicious myevents_id values to extra=
    ct or modify sensitive database information.</td>
    <td>2026-05-17</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25319" target=3D= "_blank" rel=3D"noopener">CVE-2018-25319</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44261" target=3D"_blank" rel= =3D"noopener">ExploitDB-44261</a><br><a href=3D"http://www.github.com/wende= 60/myevents" target=3D"_blank" rel=3D"noopener">Official Product Homepage</= a><br><a href=3D"https://www.vulncheck.com/advisories/redaxo-cms-addon-myev= ents-sql-injection-via-event-add-php" target=3D"_blank" rel=3D"noopener">Vu= lnCheck Advisory: Redaxo CMS Addon MyEvents 2.2.1 SQL Injection via event_a= dd.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">woocommerce-csvimport--WooCommerce CSV-Importe= r</td>
    <td>Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability = that allows any registered user to delete arbitrary files by submitting une= scaped filenames through the delete_export_file AJAX action. Attackers can = craft POST requests with directory traversal sequences in the filename para= meter to delete sensitive files like wp-config.php outside the intended exp= ort directory.</td>
    <td>2026-05-17</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25325" target=3D= "_blank" rel=3D"noopener">CVE-2018-25325</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44433" target=3D"_blank" rel= =3D"noopener">ExploitDB-44433</a><br><a href=3D"http://lenonleite.com.br/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://www.vulncheck.com/advisories/woocommerce-csv-importer-path-trav= ersal-file-deletion" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory:=
    Woocommerce CSV Importer 3.3.6 Path Traversal File Deletion</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">wp-google-drive--Google Drive</td>
    <td>Google Drive for WordPress 2.2 contains a path traversal vulnerability = that allows unauthenticated attackers to read arbitrary files by injecting = directory traversal sequences in the file_name parameter. Attackers can sen=
    d POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del= _fl_bkp and file_name containing traversal sequences ../../wp-config.php to=
    access sensitive configuration files.</td>
    <td>2026-05-17</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25326" target=3D= "_blank" rel=3D"noopener">CVE-2018-25326</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44435" target=3D"_blank" rel= =3D"noopener">ExploitDB-44435</a><br><a href=3D"http://lenonleite.com.br/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://www.vulncheck.com/advisories/google-drive-for-wordpress-path-tr= aversal-rce-via-gdrive-ajaxs-php" target=3D"_blank" rel=3D"noopener">VulnCh= eck Advisory: Google Drive for WordPress 2.2 Path Traversal RCE via gdrive-= ajaxs.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wp-with-spritz--WP with Spritz</td>
    <td>WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vu= lnerability that allows unauthenticated attackers to read arbitrary files b=
    y injecting file paths into the url parameter. Attackers can send GET reque= sts to wp.spritz.content.filter.php with malicious url values to access sen= sitive files like system configuration and credentials.</td> <td>2026-05-17</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25329" target=3D= "_blank" rel=3D"noopener">CVE-2018-25329</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44544" target=3D"_blank" rel= =3D"noopener">ExploitDB-44544</a><br><a href=3D"https://downloads.wordpress= .org/plugin/wp-with-spritz.zip" target=3D"_blank" rel=3D"noopener">Product = Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/wordpress-= plugin-wp-with-spritz-remote-file-inclusion" target=3D"_blank" rel=3D"noope= ner">VulnCheck Advisory: WordPress Plugin WP with Spritz 1.0 Remote File In= clusion</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Fabrikar--com_fabrik</td>
    <td>Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability t= hat allows unauthenticated attackers to list arbitrary files by manipulatin=
    g the folder parameter. Attackers can send GET requests to the onAjax_files=
    method with path traversal sequences to enumerate files in system director= ies outside the intended web root.</td>
    <td>2026-05-13</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37219" target=3D= "_blank" rel=3D"noopener">CVE-2020-37219</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48263" target=3D"_blank" rel= =3D"noopener">ExploitDB-48263</a><br><a href=3D"https://fabrikar.com/" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"= https://fabrikar.com/downloads" target=3D"_blank" rel=3D"noopener">Product = Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/joomla-com= -fabrik-directory-traversal-via-image-php" target=3D"_blank" rel=3D"noopene= r">VulnCheck Advisory: Joomla com_fabrik 3.9.11 Directory Traversal via ima= ge.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">www.huawei.com--Huawei HG630 Router</td> <td>Huawei HG630 V2 router contains an authentication bypass vulnerability = that allows unauthenticated attackers to obtain administrative access by re= trieving the device serial number. Attackers can query the /api/system/devi= ceinfo endpoint without authentication to extract the SerialNumber field, t= hen use the last 8 characters as the default password to login to the route= r.</td>
    <td>2026-05-13</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37220" target=3D= "_blank" rel=3D"noopener">CVE-2020-37220</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48310" target=3D"_blank" rel= =3D"noopener">ExploitDB-48310</a><br><a href=3D"https://www.youtube.com/wat= ch?v=3DvOrIL7L_cVc" target=3D"_blank" rel=3D"noopener">Reference</a><br><a = href=3D"https://www.vulncheck.com/advisories/huawei-hg630-v2-router-authent= ication-bypass-via-serial-number" target=3D"_blank" rel=3D"noopener">VulnCh= eck Advisory: Huawei HG630 V2 Router Authentication Bypass via Serial Numbe= r</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Kuicms--Kuicms Php EE</td>
    <td>Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerabil= ity that allows unauthenticated attackers to inject malicious scripts by su= bmitting crafted content through the bbs reply endpoint. Attackers can send=
    POST requests to /web/?c=3Dbbs&amp;a=3Dreply with HTML and JavaScript payl= oads in the content parameter to execute arbitrary scripts in users' browse= rs.</td>
    <td>2026-05-13</td>
    <td>7.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37222" target=3D= "_blank" rel=3D"noopener">CVE-2020-37222</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48526" target=3D"_blank" rel= =3D"noopener">ExploitDB-48526</a><br><a href=3D"https://kuicms.com" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://kuicms.com/kuicms.zip" target=3D"_blank" rel=3D"noopener">Product Ref= erence</a><br><a href=3D"https://www.vulncheck.com/advisories/kuicms-php-ee= -persistent-cross-site-scripting-via-bbs-reply" target=3D"_blank" rel=3D"no= opener">VulnCheck Advisory: Kuicms Php EE 2.0 Persistent Cross-Site Scripti=
    ng via bbs reply</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Iobit--IObit Uninstaller</td>
    <td>IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerabil= ity in the IObitUnSvr service that allows local attackers to escalate privi= leges to SYSTEM level. Attackers can place a malicious executable named IOb= it.exe in the C:\Program Files (x86)\IObit directory and restart the servic=
    e to execute code with SYSTEM privileges.</td>
    <td>2026-05-13</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37223" target=3D= "_blank" rel=3D"noopener">CVE-2020-37223</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48543" target=3D"_blank" rel= =3D"noopener">ExploitDB-48543</a><br><a href=3D"https://www.iobit.com" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"= https://www.iobit.com/en/advanceduninstaller.php" target=3D"_blank" rel=3D"= noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/adv= isories/iobit-uninstaller-unquoted-service-path-privilege-escalation" targe= t=3D"_blank" rel=3D"noopener">VulnCheck Advisory: IObit Uninstaller 9.5.0.1=
    5 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Joomsky--J2 JOBS</td>
    <td>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerabil= ity that allows authenticated attackers to manipulate database queries by i= njecting SQL code through the 'sortby' parameter. Attackers can send POST r= equests to the administrator index with malicious 'sortby' values to extrac=
    t sensitive database information.</td>
    <td>2026-05-13</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37224" target=3D= "_blank" rel=3D"noopener">CVE-2020-37224</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48648" target=3D"_blank" rel= =3D"noopener">ExploitDB-48648</a><br><a href=3D"https://joomsky.com/" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://joomsky.com/products/js-jobs-pro.html" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisor= ies/joomla-j2-jobs-authenticated-sql-injection-via-sortby" target=3D"_blank=
    " rel=3D"noopener">VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated S=
    QL Injection via sortby</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Joomsky--J2 JOBS</td>
    <td>Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerabil= ity that allows authenticated attackers to manipulate database queries by i= njecting SQL code through the 'sortby' parameter. Attackers can send POST r= equests to the administrator index with malicious 'sortby' values to extrac=
    t sensitive database information using automated tools.</td> <td>2026-05-13</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37226" target=3D= "_blank" rel=3D"noopener">CVE-2020-37226</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48670" target=3D"_blank" rel= =3D"noopener">ExploitDB-48670</a><br><a href=3D"https://joomsky.com/" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://joomsky.com/products/js-jobs-pro.html" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisor= ies/joomla-j2-jobs-authenticated-sql-injection-via-sortby-2" target=3D"_bla= nk" rel=3D"noopener">VulnCheck Advisory: Joomla J2 JOBS 1.3.0 Authenticated=
    SQL Injection via sortby</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Oki--OKI sPSV Port Manager</td>
    <td>OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerab= ility in the sPSVOpLclSrv service that allows local attackers to escalate p= rivileges by inserting executable files into the unquoted path. Attackers c=
    an place a malicious executable in a directory within the service path that=
    will execute with LocalSystem privileges when the service restarts or the = system reboots.</td>
    <td>2026-05-16</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37229" target=3D= "_blank" rel=3D"noopener">CVE-2020-37229</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49005" target=3D"_blank" rel= =3D"noopener">ExploitDB-49005</a><br><a href=3D"https://www.oki.com/" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.oki.com/mx/printing/download/sPSV_010041_2_270910.exe" target=3D= "_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://www.v= ulncheck.com/advisories/oki-spsv-port-manager-unquoted-service-path-privile= ge-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: OKI s= PSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Syncplify--Syncplify.me Server!</td> <td>Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerabi= lity in the SMWebRestServicev5 service that allows local attackers to escal= ate privileges by exploiting the unquoted binary path. Attackers can insert=
    a malicious executable into the service path and execute it with LocalSyst=
    em privileges when the service restarts or the system reboots.</td> <td>2026-05-16</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37230" target=3D= "_blank" rel=3D"noopener">CVE-2020-37230</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49009" target=3D"_blank" rel= =3D"noopener">ExploitDB-49009</a><br><a href=3D"https://www.syncplify.me/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://download.syncplify.me/SMServer_Setup.exe" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com= /advisories/syncplify-me-server-unquoted-service-path-privilege-escalation"=
    target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Syncplify.me Server=
    ! 5.0.37 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Cybertronsoft--Privacy Drive</td>
    <td>Privacy Drive 3.17.0 contains an unquoted service path vulnerability in=
    the pdsvc.exe service binary that allows local attackers to escalate privi= leges by exploiting the service startup process. Attackers can place malici= ous executables in the unquoted path directories to execute arbitrary code = with LocalSystem privileges during service startup or system reboot.</td> <td>2026-05-16</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37231" target=3D= "_blank" rel=3D"noopener">CVE-2020-37231</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49023" target=3D"_blank" rel= =3D"noopener">ExploitDB-49023</a><br><a href=3D"https://www.cybertronsoft.c= om/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
    href=3D"https://www.cybertronsoft.com/download/privacy-drive-setup.exe" ta= rget=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:= //www.vulncheck.com/advisories/privacy-drive-unquoted-service-path-privileg= e-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Privac=
    y Drive 3.17.0 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td=

    </tr>

    <td class=3D"vendor-product">Iobit--Advanced System Care Service</td> <td>Advanced System Care Service 13.0.0.157 contains an unquoted service pa=
    th vulnerability in the AdvancedSystemCareService13 service binary path tha=
    t allows local attackers to escalate privileges. Attackers can place malici= ous executables in the system root path that will be executed with LocalSys= tem privileges during service startup or system reboot.</td> <td>2026-05-16</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37232" target=3D= "_blank" rel=3D"noopener">CVE-2020-37232</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49049" target=3D"_blank" rel= =3D"noopener">ExploitDB-49049</a><br><a href=3D"https://www.iobit.com" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"= https://www.iobit.com/es/advancedsystemcarepro.php" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com= /advisories/advanced-system-care-service-unquoted-service-path-privilege-es= calation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Advanced S= ystem Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation</a= ><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Supsystic--Digital Publications</td>
    <td>Supsystic Digital Publications 1.6.9 contains a path traversal vulnerab= ility in the Folder input field that allows attackers to access files outsi=
    de the web root by injecting directory traversal sequences. Additionally, t=
    he plugin fails to sanitize input fields in publication settings, allowing = stored cross-site scripting attacks through script injection in parameters = like Area Width and Publication Width that execute when publications are vi= ewed or edited.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37245" target=3D= "_blank" rel=3D"noopener">CVE-2020-37245</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49542" target=3D"_blank" rel= =3D"noopener">ExploitDB-49542</a><br><a href=3D"https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "https://downloads.wordpress.org/plugin/digital-publications-by-supsystic.1= .6.9.zip" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a hr= ef=3D"https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-digit= al-publications-path-traversal-xss" target=3D"_blank" rel=3D"noopener">Vuln= Check Advisory: WordPress Plugin Supsystic Digital Publications 1.6.9 Path = Traversal XSS</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Kite--Kite</td>
    <td>Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the = KiteService Windows service that allows local attackers to escalate privile= ges by exploiting the service binary path. Attackers can place a malicious = executable in the Program Files directory to be executed with LocalSystem p= rivileges when the service starts.</td>
    <td>2026-05-16</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37247" target=3D= "_blank" rel=3D"noopener">CVE-2020-37247</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50975" target=3D"_blank" rel= =3D"noopener">ExploitDB-50975</a><br><a href=3D"https://www.kite.com/" targ= et=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"= https://www.vulncheck.com/advisories/kite-u1-unquoted-service-path-privileg= e-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Kite 4= .2.0.1 U1 Unquoted Service Path Privilege Escalation</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Home-Assistant--Home Assistant Community Store=
    (HACS)</td>
    <td>Home Assistant Community Store (HACS) 1.10.0 contains a path traversal = vulnerability that allows unauthenticated attackers to read sensitive files=
    by traversing directories via the /hacsfiles/ endpoint. Attackers can retr= ieve the .storage/auth file containing user credentials and refresh tokens,=
    then craft valid JWT tokens to gain administrative access to Home Assistan=
    t instances.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47942" target=3D= "_blank" rel=3D"noopener">CVE-2021-47942</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49495" target=3D"_blank" rel= =3D"noopener">ExploitDB-49495</a><br><a href=3D"https://www.home-assistant.= io/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
    href=3D"https://github.com/hacs/integration" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisor= ies/home-assistant-community-store-path-traversal-account-takeover" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Home Assistant Community S= tore 1.10.0 Path Traversal Account Takeover</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Wpgraphql--WPGraphQL</td>
    <td>WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerabi= lity that allows unauthenticated attackers to exhaust server resources by s= ending batched GraphQL queries with duplicated fields. Attackers can send P= OST requests to the GraphQL endpoint with amplified field duplication paylo= ads to trigger server out-of-memory conditions and MySQL connection errors.= </td>
    <td>2026-05-15</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47959" target=3D= "_blank" rel=3D"noopener">CVE-2021-47959</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49807" target=3D"_blank" rel= =3D"noopener">ExploitDB-49807</a><br><a href=3D"https://www.wpgraphql.com/"=
    target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hre= f=3D"https://www.vulncheck.com/advisories/wordpress-plugin-wpgraphql-denial= -of-service" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPre=
    ss Plugin WPGraphQL 1.3.5 Denial of Service</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AnotherNote--Anote</td>
    <td>Anote 1.0 contains a persistent cross-site scripting vulnerability that=
    allows attackers to execute arbitrary code by injecting malicious payloads=
    into markdown files stored within the application. Attackers can craft mal= icious markdown files with embedded JavaScript that executes system command=
    s when opened, enabling remote code execution on the victim's computer.</td=

    <td>2026-05-15</td>
    <td>7.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47963" target=3D= "_blank" rel=3D"noopener">CVE-2021-47963</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49836" target=3D"_blank" rel= =3D"noopener">ExploitDB-49836</a><br><a href=3D"https://github.com/AnotherN= ote/anote" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"https://www.vulncheck.com/advisories/anote-persistent-cross-= site-scripting-remote-code-execution" target=3D"_blank" rel=3D"noopener">Vu= lnCheck Advisory: Anote 1.0 Persistent Cross-Site Scripting Remote Code Exe= cution</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">color-notes--Color Notes</td>
    <td>Color Notes 1.4 contains a denial of service vulnerability that allows = attackers to crash the application by pasting excessively long character st= rings into note fields. Attackers can generate a payload containing 350,000=
    repeated characters and paste it twice into a new note to cause the applic= ation to stop responding.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47969" target=3D= "_blank" rel=3D"noopener">CVE-2021-47969</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49952" target=3D"_blank" rel= =3D"noopener">ExploitDB-49952</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/color-notes-denial-of-service-via-long-character-string" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Color Notes 1.4 Denial of = Service via Long Character String</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">macaron-notes-great-notebook--Macaron Notes Ge=
    ar Notebook</td>
    <td>Macaron Notes 5.5 contains a denial of service vulnerability that allow=
    s attackers to crash the application by creating notes with excessively lon=
    g character strings. Attackers can generate a payload containing 350000 rep= eated characters and paste it into a note field to trigger application cras=
    h and stop functionality.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47970" target=3D= "_blank" rel=3D"noopener">CVE-2021-47970</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49953" target=3D"_blank" rel= =3D"noopener">ExploitDB-49953</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/macaron-notes-denial-of-service-via-buffer-overflow" target=3D"_b= lank" rel=3D"noopener">VulnCheck Advisory: Macaron Notes 5.5 Denial of Serv= ice via Buffer Overflow</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">my-notes-safe--My Notes Safe</td>
    <td>My Notes Safe 5.3 contains a denial of service vulnerability that allow=
    s attackers to crash the application by pasting excessively long character = strings into note fields. Attackers can generate a payload containing 35000=
    0 repeated characters and paste it twice into a new note to trigger an appl= ication crash.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47971" target=3D= "_blank" rel=3D"noopener">CVE-2021-47971</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49954" target=3D"_blank" rel= =3D"noopener">ExploitDB-49954</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/my-notes-safe-denial-of-service-via-buffer-overflow" target=3D"_b= lank" rel=3D"noopener">VulnCheck Advisory: My Notes Safe 5.3 Denial of Serv= ice via Buffer Overflow</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">sticky-notes-color-widgets--Sticky Notes Color=
    Widgets</td>
    <td>Sticky Notes &amp; Color Widgets 1.4.2 contains a denial of service vul= nerability that allows attackers to crash the application by creating notes=
    with excessively long character strings. Attackers can paste large payload=
    s of repeated characters into note fields to trigger application crashes an=
    d make the application stop responding.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47972" target=3D= "_blank" rel=3D"noopener">CVE-2021-47972</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49957" target=3D"_blank" rel= =3D"noopener">ExploitDB-49957</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/sticky-notes-color-widgets-denial-of-service" target=3D"_blank" r= el=3D"noopener">VulnCheck Advisory: Sticky Notes &amp; Color Widgets 1.4.2 = Denial of Service</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">sticky-notes--Sticky Notes Widget</td>
    <td>Sticky Notes Widget 3.0.6 contains a denial of service vulnerability th=
    at allows attackers to crash the application by pasting excessively long ch= aracter strings into note fields. Attackers can generate a payload containi=
    ng 350000 repeated characters and paste it twice into a new note to trigger=
    an application crash on iOS devices.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47973" target=3D= "_blank" rel=3D"noopener">CVE-2021-47973</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49978" target=3D"_blank" rel= =3D"noopener">ExploitDB-49978</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/sticky-notes-widget-denial-of-service-via-buffer-overflow" target= =3D"_blank" rel=3D"noopener">VulnCheck Advisory: Sticky Notes Widget 3.0.6 = Denial of Service via Buffer Overflow</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Vxsearch--VX Search</td>
    <td>VX Search 13.5.28 contains an unquoted service path vulnerability in bo=
    th VX Search Server and VX Search Enterprise services that allows local att= ackers to escalate privileges. Attackers can place malicious executables in=
    unquoted path directories like C:\Program Files\VX Search to execute arbit= rary code with LocalSystem privileges when services restart.</td> <td>2026-05-16</td>
    <td>7.8</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47974" target=3D= "_blank" rel=3D"noopener">CVE-2021-47974</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50026" target=3D"_blank" rel= =3D"noopener">ExploitDB-50026</a><br><a href=3D"https://www.vxsearch.com" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://www.vulncheck.com/advisories/vx-search-unquoted-service-path-pr= ivilege-escalation" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: =
    VX Search 13.5.28 Unquoted Service Path Privilege Escalation</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">Wplearnmanager--WP Learn Manager</td>
    <td>WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerabi= lity that allows unauthenticated attackers to inject malicious scripts thro= ugh the fieldtitle parameter. Attackers can submit POST requests to the jsl= m_fieldordering page with XSS payloads in the fieldtitle field to execute a= rbitrary JavaScript when administrators view the field ordering interface.<=

    <td>2026-05-16</td>
    <td>7.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47975" target=3D= "_blank" rel=3D"noopener">CVE-2021-47975</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50086" target=3D"_blank" rel= =3D"noopener">ExploitDB-50086</a><br><a href=3D"https://wplearnmanager.com/=
    " target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"https://wordpress.org/plugins/learn-manager/" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com= /advisories/wordpress-plugin-wp-learn-manager-stored-xss" target=3D"_blank"=
    rel=3D"noopener">VulnCheck Advisory: WordPress Plugin WP Learn Manager 1.1=
    .2 Stored XSS</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Gotmls--Malware Security and Bruteforce Firewa= ll</td>
    <td>WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 = contains a directory traversal vulnerability that allows unauthenticated at= tackers to read arbitrary files by manipulating the file parameter. Attacke=
    rs can send requests to the duplicator_download action via admin-ajax.php w= ith path traversal sequences to access sensitive system files outside the i= ntended directory.</td>
    <td>2026-05-16</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47977" target=3D= "_blank" rel=3D"noopener">CVE-2021-47977</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50107" target=3D"_blank" rel= =3D"noopener">ExploitDB-50107</a><br><a href=3D"https://gotmls.net/" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://gotmls.net/downloads/" target=3D"_blank" rel=3D"noopener">Product Ref= erence</a><br><a href=3D"https://www.vulncheck.com/advisories/wordpress-ant= i-malware-security-bruteforce-firewall-directory-traversal" target=3D"_blan=
    k" rel=3D"noopener">VulnCheck Advisory: WordPress Anti-Malware Security Bru= teforce Firewall 4.20.59 Directory Traversal</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Getfuelcms--Fuel CMS</td>
    <td>Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allow=
    s authenticated attackers to manipulate database queries by injecting SQL c= ode through the 'col' parameter in the Activity Log interface. Attackers ca=
    n send requests to the logs endpoint with malicious SQL payloads in the 'co=
    l' parameter to extract database information based on response time delays.= </td>
    <td>2026-05-16</td>
    <td>7.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47980" target=3D= "_blank" rel=3D"noopener">CVE-2021-47980</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50523" target=3D"_blank" rel= =3D"noopener">ExploitDB-50523</a><br><a href=3D"https://www.getfuelcms.com/=
    " target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a hr= ef=3D"https://github.com/daylightstudio/FUEL-CMS/archive/1.4.13.zip" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://ww= w.vulncheck.com/advisories/fuel-cms-blind-sql-injection-via-col-parameter" = target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Fuel CMS 1.4.13 Blin=
    d SQL Injection via col Parameter</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">GitLab--GitLab</td>
    <td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that=
    could have allowed an unauthenticated user to cause denial of service by s= ending specially crafted payloads on certain API endpoints.</td> <td>2026-05-14</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14869" target=3D= "_blank" rel=3D"noopener">CVE-2025-14869</a></td>

    <a href=3D"https://hackerone.com/reports/3447146" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3447146</a><br><a href=3D"https://gi= tlab.com/gitlab-org/gitlab/-/work_items/584489" target=3D"_blank" rel=3D"no= opener">https://gitlab.com/gitlab-org/gitlab/-/work_items/584489</a><br><a = href=3D"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">GitLab--GitLab</td>
    <td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that=
    could have allowed an unauthenticated user to cause denial of service by s= ending specially crafted JSON payloads due to insufficient input validation= .</td>
    <td>2026-05-14</td>
    <td>7.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14870" target=3D= "_blank" rel=3D"noopener">CVE-2025-14870</a></td>

    <a href=3D"https://hackerone.com/reports/3446641" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3446641</a><br><a href=3D"https://gi= tlab.com/gitlab-org/gitlab/-/work_items/584490" target=3D"_blank" rel=3D"no= opener">https://gitlab.com/gitlab-org/gitlab/-/work_items/584490</a><br><a = href=3D"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    <div id=3D"medium_v">
    <h2 id=3D"medium_v_title">Medium Vulnerabilities</h2>
    <table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Medium Vulnerabilities">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">Simple-Fields--Simple Fields</td>
    <td>Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file = inclusion vulnerability that allows unauthenticated attackers to read arbit= rary files by injecting null bytes into the wp_abspath parameter on PHP ver= sions before 5.3.4. Attackers can supply malicious wp_abspath values to sim= ple_fields.php to include files like /etc/passwd or inject PHP code into Ap= ache logs for remote code execution when allow_url_include is enabled.</td> <td>2026-05-17</td>
    <td>6.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25324" target=3D= "_blank" rel=3D"noopener">CVE-2018-25324</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44425" target=3D"_blank" rel= =3D"noopener">ExploitDB-44425</a><br><a href=3D"http://simple-fields.com" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://downloads.wordpress.org/plugin/simple-fields.0.3.5.zip" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://ww= w.vulncheck.com/advisories/simple-fields-local-file-inclusion-via-wp-abspat=
    h" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Simple Fields 0.2= -0.3.5 Local File Inclusion via wp_abspath</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">zenar--Zenar Content Management System</td> <td>Zenar Content Management System contains a cross-site scripting vulnera= bility that allows unauthenticated attackers to inject malicious scripts by=
    manipulating form parameters in POST requests. Attackers can inject script=
    tags through the current_page parameter sent to the ajax.php endpoint, whi=
    ch reflects unsanitized user input in the response HTML to execute arbitrar=
    y JavaScript in victim browsers.</td>
    <td>2026-05-17</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25331" target=3D= "_blank" rel=3D"noopener">CVE-2018-25331</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44664" target=3D"_blank" rel= =3D"noopener">ExploitDB-44664</a><br><a href=3D"http://demo.zenar.io" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://zenar.io/" target=3D"_blank" rel=3D"noopener">Product Reference</a><= br><a href=3D"https://www.vulncheck.com/advisories/zenar-content-management= -system-cross-site-scripting-via-ajax-php" target=3D"_blank" rel=3D"noopene= r">VulnCheck Advisory: Zenar Content Management System Cross-Site Scripting=
    via ajax.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Powie--WHOIS Domain Check</td>
    <td>Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scri= pting vulnerability that allows authenticated attackers to inject arbitrary=
    JavaScript by exploiting unsanitized input fields in plugin settings. Atta= ckers can submit malicious payloads through textarea and input elements in = the pwhois_settings.php configuration page to execute JavaScript in the adm=
    in context and escalate privileges.</td>
    <td>2026-05-13</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37225" target=3D= "_blank" rel=3D"noopener">CVE-2020-37225</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48656" target=3D"_blank" rel= =3D"noopener">ExploitDB-48656</a><br><a href=3D"https://powie.de" target=3D= "_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"https= ://blog.haao.sh" target=3D"_blank" rel=3D"noopener">Official Product Homepa= ge</a><br><a href=3D"https://wordpress.org/plugins/powies-whois/" target=3D= "_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://www.v= ulncheck.com/advisories/powie-s-whois-domain-check-persistent-cross-site-sc= ripting" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Powie's WHO=
    IS Domain Check 0.9.31 Persistent Cross-Site Scripting</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Wordpress--Buddypress</td>
    <td>WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scri= pting vulnerability that allows authenticated attackers with moderator priv= ileges to inject malicious script code through the figure parameter in wp:h= tml blocks. Attackers can inject iframe elements with event handlers like o= nload that execute when administrators or privileged users preview or view = the affected page content, enabling session hijacking and persistent phishi=
    ng attacks.</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37233" target=3D= "_blank" rel=3D"noopener">CVE-2020-37233</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49061" target=3D"_blank" rel= =3D"noopener">ExploitDB-49061</a><br><a href=3D"https://wordpress.org/plugi= ns/buddypress/" target=3D"_blank" rel=3D"noopener">Official Product Homepag= e</a><br><a href=3D"https://www.vulncheck.com/advisories/wordpress-plugin-b= uddypress-persistent-cross-site-scripting" target=3D"_blank" rel=3D"noopene= r">VulnCheck Advisory: WordPress Plugin Buddypress 6.2.0 Persistent Cross-S= ite Scripting</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Internetdownloadmanager--Internet Download Man= ager</td>
    <td>Internet Download Manager 6.38.12 contains a buffer overflow vulnerabil= ity in the Scheduler component that allows local attackers to crash the app= lication by supplying oversized input. Attackers can paste malicious data e= xceeding 5000 bytes into the 'Open the following file when done' field to t= rigger a denial of service condition.</td>
    <td>2026-05-16</td>
    <td>6.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37234" target=3D= "_blank" rel=3D"noopener">CVE-2020-37234</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49083" target=3D"_blank" rel= =3D"noopener">ExploitDB-49083</a><br><a href=3D"http://www.internetdownload= manager.com/" target=3D"_blank" rel=3D"noopener">Official Product Homepage<= /a><br><a href=3D"http://www.internetdownloadmanager.com/download.html" tar= get=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:/= /www.vulncheck.com/advisories/internet-download-manager-scheduler-buffer-ov= erflow" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Internet Dow= nload Manager 6.38.12 Scheduler Buffer Overflow</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">themeftc--Theme Wibar</td>
    <td>WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vuln= erability in the Brand component that allows authenticated users to inject = malicious scripts by manipulating the Logo URL parameter. Attackers with ed= itor, administrator, contributor, or author privileges can inject base64-en= coded script payloads through the ftc_brand_url input field to execute arbi= trary JavaScript when users visit the brand page.</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37235" target=3D= "_blank" rel=3D"noopener">CVE-2020-37235</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49107" target=3D"_blank" rel= =3D"noopener">ExploitDB-49107</a><br><a href=3D"http://demo.themeftc.com/wi= bar" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
    href=3D"https://themeforest.net/item/wibar-responsive-woocommerce-wordpres= s-theme/20994798" target=3D"_blank" rel=3D"noopener">Product Reference</a><= br><a href=3D"https://www.vulncheck.com/advisories/wordpress-theme-wibar-st= ored-cross-site-scripting-via-brand-component" target=3D"_blank" rel=3D"noo= pener">VulnCheck Advisory: WordPress Theme Wibar 1.1.8 Stored Cross-Site Sc= ripting via Brand Component</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Netartmedia--NewsLister</td>
    <td>NewsLister contains an authenticated persistent cross-site scripting vu= lnerability that allows authenticated administrators to inject malicious sc= ripts through the title parameter in the news addition interface. Attackers=
    can inject JavaScript payloads via the title field in the admin panel that=
    execute when news items are viewed by other users.</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37236" target=3D= "_blank" rel=3D"noopener">CVE-2020-37236</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49160" target=3D"_blank" rel= =3D"noopener">ExploitDB-49160</a><br><a href=3D"https://www.netartmedia.net= /newslister.html" target=3D"_blank" rel=3D"noopener">Official Product Homep= age</a><br><a href=3D"https://www.vulncheck.com/advisories/newslister-authe= nticated-persistent-cross-site-scripting-via-admin-panel" target=3D"_blank"=
    rel=3D"noopener">VulnCheck Advisory: NewsLister Authenticated Persistent C= ross-Site Scripting via Admin Panel</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Compo--Composr CMS</td>
    <td>Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerab= ility that allows authenticated administrators to inject malicious scripts = through the banner management interface. Attackers with admin credentials c=
    an inject XSS payloads in the Description field of the Add banner functiona= lity, which execute for all website visitors when they access the home page= .</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37237" target=3D= "_blank" rel=3D"noopener">CVE-2020-37237</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49190" target=3D"_blank" rel= =3D"noopener">ExploitDB-49190</a><br><a href=3D"https://compo.sr/" target= =3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"ht= tps://compo.sr/download.htm" target=3D"_blank" rel=3D"noopener">Product Ref= erence</a><br><a href=3D"https://www.vulncheck.com/advisories/composr-cms-p= ersistent-cross-site-scripting-via-banners" target=3D"_blank" rel=3D"noopen= er">VulnCheck Advisory: Composr CMS 10.0.34 Persistent Cross-Site Scripting=
    via banners</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Cmsmadesimple--CMS Made Simple</td>
    <td>CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerabi= lity that allows authenticated users with Content Manager access to inject = malicious scripts through SVG file uploads. Attackers can upload SVG files = containing embedded JavaScript to the file manager, which executes when oth=
    er authenticated users access the uploaded file, enabling cookie theft and = session hijacking.</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37238" target=3D= "_blank" rel=3D"noopener">CVE-2020-37238</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49199" target=3D"_blank" rel= =3D"noopener">ExploitDB-49199</a><br><a href=3D"https://www.cmsmadesimple.o= rg/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a=
    href=3D"https://www.cmsmadesimple.org/downloads" target=3D"_blank" rel=3D"= noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/adv= isories/cms-made-simple-stored-xss-via-svg-file-upload" target=3D"_blank" r= el=3D"noopener">VulnCheck Advisory: CMS Made Simple 2.2.15 Stored XSS via S=
    VG File Upload</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Codekernel--Queue Management System</td>
    <td>Queue Management System 4.0.0 contains a stored cross-site scripting vu= lnerability that allows authenticated administrators to inject malicious sc= ripts through user creation fields. Attackers can insert JavaScript payload=
    s in the First Name, Last Name, and Email fields during user creation, whic=
    h execute when viewing the User List page.</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37240" target=3D= "_blank" rel=3D"noopener">CVE-2020-37240</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49296" target=3D"_blank" rel= =3D"noopener">ExploitDB-49296</a><br><a href=3D"http://codekernel.net/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "https://codecanyon.net/item/queue-management-system/22029961" target=3D"_b= lank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://www.vuln= check.com/advisories/queue-management-system-stored-xss-via-add-user" targe= t=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Queue Management System 4= .0.0 Stored XSS via Add User</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Supsystic--Backup</td>
    <td>Supsystic Backup 2.3.9 contains a local file inclusion vulnerability th=
    at allows unauthenticated attackers to read and delete arbitrary files by m= anipulating the download path parameter. Attackers can modify the download = parameter in admin.php requests with directory traversal sequences to acces=
    s sensitive files like /etc/passwd or delete files via the removeAction par= ameter.</td>
    <td>2026-05-16</td>
    <td>6.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37246" target=3D= "_blank" rel=3D"noopener">CVE-2020-37246</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49545" target=3D"_blank" rel= =3D"noopener">ExploitDB-49545</a><br><a href=3D"https://supsystic.com/" tar= get=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D= "https://downloads.wordpress.org/plugin/backup-by-supsystic.zip" target=3D"= _blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://www.vu= lncheck.com/advisories/wordpress-plugin-supsystic-backup-local-file-inclusi= on" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin=
    Supsystic Backup 2.3.9 Local File Inclusion</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Cookielawinfo--Cookie Law Bar</td>
    <td>Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerabili=
    ty that allows authenticated attackers to inject malicious scripts by submi= tting unsanitized input to the Bar Message field. Attackers can inject scri=
    pt payloads through the plugin settings page that execute in the browsers o=
    f all WordPress users viewing the site, enabling cookie theft and sensitive=
    data exfiltration.</td>
    <td>2026-05-16</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47957" target=3D= "_blank" rel=3D"noopener">CVE-2021-47957</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49905" target=3D"_blank" rel= =3D"noopener">ExploitDB-49905</a><br><a href=3D"https://www.cookielawinfo.c= om/wordpress-plugin/" target=3D"_blank" rel=3D"noopener">Official Product H= omepage</a><br><a href=3D"https://wordpress.org/plugins/cookie-law-bar/" ta= rget=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https:= //www.vulncheck.com/advisories/wordpress-plugin-cookie-law-bar-stored-xss-v= ia-clb-bar-msg" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Word= Press Plugin Cookie Law Bar 1.2.1 Stored XSS via clb_bar_msg</a><br>=C2=A0<=

    </tr>

    <td class=3D"vendor-product">savsofts--Savsoft Quiz</td>
    <td>Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerabili=
    ty in the user account settings page that allows authenticated attackers to=
    inject malicious HTML and JavaScript code. Attackers can inject script pay= loads into user profile fields at the edit_user endpoint, which execute in = the browsers of users viewing the affected profile after submission.</td> <td>2026-05-15</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47962" target=3D= "_blank" rel=3D"noopener">CVE-2021-47962</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49825" target=3D"_blank" rel= =3D"noopener">ExploitDB-49825</a><br><a href=3D"https://savsoftquiz.com" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://github.com/savsofts/savsoftquiz_v5" target=3D"_blank" rel=3D"no= opener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advis= ories/savsoft-quiz-persistent-cross-site-scripting-via-user-settings" targe= t=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Savsoft Quiz 5.0 Persiste=
    nt Cross-Site Scripting via User Settings</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Timeclock--PHP Timeclock</td>
    <td>PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabiliti=
    es that allow unauthenticated attackers to inject arbitrary JavaScript by m= anipulating URL paths and POST parameters. Attackers can append malicious p= ayloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, =
    or inject code through from_date and to_date parameters in report requests =
    to execute scripts in user browsers.</td>
    <td>2026-05-15</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47967" target=3D= "_blank" rel=3D"noopener">CVE-2021-47967</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49853" target=3D"_blank" rel= =3D"noopener">ExploitDB-49853</a><br><a href=3D"http://timeclock.sourceforg= e.net" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br>=
    <a href=3D"https://sourceforge.net/projects/timeclock/files/PHP%20Timeclock= /PHP%20Timeclock%201.04/" target=3D"_blank" rel=3D"noopener">Product Refere= nce</a><br><a href=3D"https://www.vulncheck.com/advisories/php-timeclock-mu= ltiple-cross-site-scripting-via-parameters" target=3D"_blank" rel=3D"noopen= er">VulnCheck Advisory: PHP Timeclock 1.04 Multiple Cross-Site Scripting vi=
    a Parameters</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Podcastgenerator--Podcast Generator</td> <td>Podcast Generator 3.1 contains a persistent cross-site scripting vulner= ability that allows authenticated attackers to inject malicious scripts by = submitting unfiltered JavaScript code in the long_description parameter. At= tackers can inject script tags through episode creation or editing requests=
    to execute arbitrary JavaScript when other users view the episode details.= </td>
    <td>2026-05-15</td>
    <td>6.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47968" target=3D= "_blank" rel=3D"noopener">CVE-2021-47968</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49866" target=3D"_blank" rel= =3D"noopener">ExploitDB-49866</a><br><a href=3D"https://podcastgenerator.ne= t/demoV2/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"https://podcastgenerator.net/download" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com= /advisories/podcast-generator-persistent-cross-site-scripting-via-long-desc= ription" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Podcast Gen= erator 3.1 Persistent Cross-Site Scripting via long_description</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Processmaker--ProcessMaker</td>
    <td>ProcessMaker 3.5.4 contains a local file inclusion vulnerability that a= llows unauthenticated attackers to read arbitrary files by exploiting impro= per path traversal validation. Attackers can send requests with directory t= raversal sequences to access sensitive system files like /etc/passwd withou=
    t authentication.</td>
    <td>2026-05-16</td>
    <td>6.2</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47978" target=3D= "_blank" rel=3D"noopener">CVE-2021-47978</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50229" target=3D"_blank" rel= =3D"noopener">ExploitDB-50229</a><br><a href=3D"https://www.processmaker.co= m/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a = href=3D"https://www.vulncheck.com/advisories/processmaker-local-file-inclus= ion-via-path-traversal" target=3D"_blank" rel=3D"noopener">VulnCheck Adviso= ry: ProcessMaker 3.5.4 Local File Inclusion via Path Traversal</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">interactivegeomaps--MapGeo Interactive Geo Map= s</td>
    <td>The MapGeo - Interactive Geo Maps plugin for WordPress is vulnerable to=
    Reflected Cross-Site Scripting via the 'map' parameter in the display-map = shortcode in all versions up to, and including, 1.6.27 due to insufficient = input sanitization and output escaping. This makes it possible for unauthen= ticated attackers to inject arbitrary web scripts in pages that execute if = they can successfully trick a user into performing an action such as clicki=
    ng on a link.</td>
    <td>2026-05-14</td>
    <td>6.1</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15345" target=3D= "_blank" rel=3D"noopener">CVE-2025-15345</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/bfccbf= 41-c861-4bf1-b400-7858cb255b9a?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/bfccbf41-c86= 1-4bf1-b400-7858cb255b9a?source=3Dcve</a><br><a href=3D"https://research.cl= eantalk.org/cve-2025-15345" target=3D"_blank" rel=3D"noopener">https://rese= arch.cleantalk.org/cve-2025-15345</a><br><a href=3D"https://plugins.trac.wo= rdpress.org/changeset?old_path=3D/interactive-geo-maps/tags/1.6.27/src/Plug= in/Map.php&new_path=3D/interactive-geo-maps/tags/1.6.28/src/Plugin/Map.php"=
    target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/chan= geset?old_path=3D/interactive-geo-maps/tags/1.6.27/src/Plugin/Map.php&new_p= ath=3D/interactive-geo-maps/tags/1.6.28/src/Plugin/Map.php</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">hwk-fr--Advanced Custom Fields: Extended</td> <td>The The Advanced Custom Fields: Extended plugin for WordPress is vulner= able to arbitrary shortcode execution in all versions up to, and including,=
    0.9.2.3. This is due to the software allowing users to execute an action t= hat does not properly validate a value before running do_shortcode. This ma= kes it possible for unauthenticated attackers to execute arbitrary shortcod= es.</td>
    <td>2026-05-12</td>
    <td>6.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-15463" target=3D= "_blank" rel=3D"noopener">CVE-2025-15463</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/f85447= 84-1994-47e2-be39-568d0ab9ee00?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/f8544784-199= 4-47e2-be39-568d0ab9ee00?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/modules/form/mod= ule-form-action-email.php#L111" target=3D"_blank" rel=3D"noopener">https://= plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/modul= es/form/module-form-action-email.php#L111</a><br><a href=3D"https://plugins= .trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/modules/form= /module-form-front-render.php#L35" target=3D"_blank" rel=3D"noopener">https= ://plugins.trac.wordpress.org/browser/acf-extended/tags/0.9.2.2/includes/mo= dules/form/module-form-front-render.php#L35</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Joomsky--JS Jobs</td>
    <td>Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery v= ulnerability that allows attackers to perform state-changing actions withou=
    t token validation. Attackers can craft malicious HTML forms targeting admi= nistrative endpoints like job.jobenforcedelete to delete job entries or mod= ify component settings when administrators visit attacker-controlled pages.= </td>
    <td>2026-05-17</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25327" target=3D= "_blank" rel=3D"noopener">CVE-2018-25327</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44492" target=3D"_blank" rel= =3D"noopener">ExploitDB-44492</a><br><a href=3D"https://www.joomsky.com" ta= rget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://extensions.joomla.org/extension/js-jobs/" target=3D"_blank" rel= =3D"noopener">Product Reference</a><br><a href=3D"https://www.vulncheck.com= /advisories/joomla-component-js-jobs-cross-site-request-forgery" target=3D"= _blank" rel=3D"noopener">VulnCheck Advisory: Joomla! Component Js Jobs 1.2.=
    0 Cross-Site Request Forgery</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Bylancer--Zechat</td>
    <td>Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability t= hat allows an attacker to change a user's information by bypassing anti-CSR=
    F protections. The application uses a CSRF token, but an attacker can use t=
    he hashtag parameter to inject an encoded payload and bypass the CSRF prote= ction, allowing for unauthorized changes to user data. This can be exploite=
    d by tricking a user into submitting a crafted form or by using a script to=
    obtain and set the CSRF token.</td>
    <td>2026-05-17</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25334" target=3D= "_blank" rel=3D"noopener">CVE-2018-25334</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44685" target=3D"_blank" rel= =3D"noopener">ExploitDB-44685</a><br><a href=3D"https://bylancer.com" targe= t=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href=3D"h= ttps://www.vulncheck.com/advisories/zechat-cross-site-request-forgery-csrf-= via-hashtag-parameter" target=3D"_blank" rel=3D"noopener">VulnCheck Advisor=
    y: Zechat 1.5 Cross-Site Request Forgery (CSRF) via hashtag parameter</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Joomlaextensions--Joomla! extension jCart for = OpenCart</td>
    <td>Joomla jCart for OpenCart 2.3.0.2 contains a cross-site request forgery=
    vulnerability that allows attackers to modify user account information wit= hout authentication. Attackers can craft malicious HTML forms targeting end= points , and to change user credentials, passwords, and affiliate account d= etails when victims visit the attacker-controlled page.</td> <td>2026-05-17</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25336" target=3D= "_blank" rel=3D"noopener">CVE-2018-25336</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44788" target=3D"_blank" rel= =3D"noopener">ExploitDB-44788</a><br><a href=3D"https://www.joomlaextension= s.co.in/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><= br><a href=3D"https://extensions.joomla.org/extensions/extension/e-commerce= /e-commerce-integrations/jcart-for-opencart/" target=3D"_blank" rel=3D"noop= ener">Product Reference</a><br><a href=3D"https://www.vulncheck.com/advisor= ies/joomla-jcart-for-opencart-cross-site-request-forgery" target=3D"_blank"=
    rel=3D"noopener">VulnCheck Advisory: Joomla jCart for OpenCart 2.3.0.2 Cro= ss-Site Request Forgery</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Ultimate Member--ultimate-member</td> <td>WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion = vulnerability that allows authenticated attackers to include arbitrary file=
    s by manipulating the pack parameter in class-admin-upgrade.php. Attackers = can send POST requests with malicious pack values to include unintended PHP=
    files from the packages directory and execute arbitrary code.</td> <td>2026-05-13</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37169" target=3D= "_blank" rel=3D"noopener">CVE-2020-37169</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48065" target=3D"_blank" rel= =3D"noopener">ExploitDB-48065</a><br><a href=3D"https://www.vulncheck.com/a= dvisories/wordpress-plugin-ultimate-member-local-file-inclusion" target=3D"= _blank" rel=3D"noopener">VulnCheck Advisory: WordPress Plugin ultimate-memb=
    er 2.1.3 Local File Inclusion</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">HUSKY--Products Filter Professional for WooCom= merce</td>
    <td>WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-= site scripting vulnerability that allows authenticated attackers to inject = malicious scripts by entering XSS payloads in design tab textfields. Attack= ers can inject JavaScript code through fields like 'Text for block toggle' = and 'Custom front css styles' that executes on frontend pages when saved, a= ffecting all site visitors.</td>
    <td>2026-05-13</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37174" target=3D= "_blank" rel=3D"noopener">CVE-2020-37174</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48088" target=3D"_blank" rel= =3D"noopener">ExploitDB-48088</a><br><a href=3D"https://products-filter.com=
    /" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a h= ref=3D"https://wordpress.org/plugins/woocommerce-products-filter/" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://ww= w.vulncheck.com/advisories/woof-products-filter-for-woocommerce-persistent-= xss" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: WOOF Products F= ilter for WooCommerce 1.2.3 Persistent XSS</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Bloofox--bloofoxCMS</td>
    <td>bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability = that allows attackers to perform administrative actions by tricking logged-=
    in users into visiting malicious pages. Attackers can craft hidden forms ta= rgeting the admin user creation endpoint to add new administrative accounts=
    with arbitrary credentials without requiring explicit user consent.</td> <td>2026-05-16</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37241" target=3D= "_blank" rel=3D"noopener">CVE-2020-37241</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49507" target=3D"_blank" rel= =3D"noopener">ExploitDB-49507</a><br><a href=3D"https://www.bloofox.com/" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://github.com/alexlang24/bloofoxCMS/releases/tag/0.5.2.1" target= =3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"https://ww= w.vulncheck.com/advisories/bloofoxcms-cross-site-request-forgery-via-user-a= dd" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: bloofoxCMS 0.5.2=
    .1 Cross-Site Request Forgery via user add</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">MyBB--MyBB Timeline Plugin</td>
    <td>MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities = that allow attackers to inject malicious scripts through thread titles, pos=
    t content, and user profile fields like Location and Bio. Attackers can als=
    o exploit a cross-site request forgery vulnerability in the timeline.php pr= ofile action to change a user's cover picture by crafting malicious forms t= hat execute when victims visit affected profiles.</td>
    <td>2026-05-16</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47934" target=3D= "_blank" rel=3D"noopener">CVE-2021-47934</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49467" target=3D"_blank" rel= =3D"noopener">ExploitDB-49467</a><br><a href=3D"https://community.mybb.com/= mods.php?action=3Dview&pid=3D1428" target=3D"_blank" rel=3D"noopener">Produ=
    ct Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/mybb-ti= meline-plugin-cross-site-scripting-and-csrf" target=3D"_blank" rel=3D"noope= ner">VulnCheck Advisory: MyBB Timeline Plugin 1.0 Cross-Site Scripting and = CSRF</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">CouchCMS--CouchCMS</td>
    <td>CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allow=
    s authenticated attackers to execute arbitrary JavaScript by uploading mali= cious SVG files through the file upload functionality. Attackers can upload=
    SVG files containing embedded script tags to the browse.php endpoint, whic=
    h are then executed in users' browsers when the files are accessed or previ= ewed.</td>
    <td>2026-05-16</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47955" target=3D= "_blank" rel=3D"noopener">CVE-2021-47955</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49636" target=3D"_blank" rel= =3D"noopener">ExploitDB-49636</a><br><a href=3D"https://github.com/CouchCMS= /CouchCMS" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"https://www.vulncheck.com/advisories/couchcms-cross-site-scr= ipting-via-svg-file-upload" target=3D"_blank" rel=3D"noopener">VulnCheck Ad= visory: CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload</a><br>=C2= =A0</td>
    </tr>

    <td class=3D"vendor-product">Opensolution--Quick.CMS</td>
    <td>Quick.CMS 6.7 contains a cross-site scripting vulnerability in the slid= ers form that allows authenticated attackers to inject malicious scripts by=
    submitting XSS payloads through the sDescription parameter. Attackers can = craft CSRF forms targeting the admin.php?p=3Dsliders-form endpoint to execu=
    te arbitrary JavaScript in victim browsers when the form is submitted.</td> <td>2026-05-16</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47981" target=3D= "_blank" rel=3D"noopener">CVE-2021-47981</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/50530" target=3D"_blank" rel= =3D"noopener">ExploitDB-50530</a><br><a href=3D"https://opensolution.org/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://opensolution.org/download/home.html?sFile=3DQuick.Cms_v6.7-en.z= ip" target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"= https://www.vulncheck.com/advisories/quick-cms-cross-site-scripting-via-csr= f-to-sliders-form" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory: Q= uick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
    <td>The check user account lock states feature within the email OTP flow fa= ils to validate user input, allowing an attacker to infer the existence of = registered user accounts. The discovery of valid usernames can increase the=
    risk of brute-force and social engineering attacks. Attackers can leverage=
    this information to craft targeted phishing campaigns or other malicious a= ctivities aimed at tricking users into divulging sensitive data, potentiall=
    y damaging the organization's reputation and leading to regulatory non-comp= liance and financial consequences.</td>
    <td>2026-05-11</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-0391" target=3D"= _blank" rel=3D"noopener">CVE-2024-0391</a></td>

    <a href=3D"https://security.docs.wso2.com/en/latest/security-announcements/= security-advisories/2026/WSO2-2024-3115/" target=3D"_blank" rel=3D"noopener= ">https://security.docs.wso2.com/en/latest/security-announcements/security-= advisories/2026/WSO2-2024-3115/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Siemens--SIPROTEC 5 6MD84 (CP300)</td>
    <td>A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All ve= rsions &lt; V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD=
    85 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 6MD86 (CP200=
    ) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions &gt;=3D V7.80 &lt;=
    V11.0), SIPROTEC 5 6MD89 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), = SIPROTEC 5 6MU85 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC =
    5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions &gt;= =3D V7.80 &lt; V11.0), SIPROTEC 5 7SA82 (CP100) (All versions &gt;=3D V7.80=
    ), SIPROTEC 5 7SA82 (CP150) (All versions &lt; V11.0), SIPROTEC 5 7SA84 (CP= 200) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7S= A86 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7SA87 (CP20=
    0) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions &gt;=3D V7.80 &lt=
    ; V11.0), SIPROTEC 5 7SD82 (CP100) (All versions &gt;=3D V7.80), SIPROTEC 5=
    7SD82 (CP150) (All versions &lt; V11.0), SIPROTEC 5 7SD84 (CP200) (All ver= sions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (= All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7SD87 (CP200) (All versi= ons), SIPROTEC 5 7SD87 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIP= ROTEC 5 7SJ81 (CP100) (All versions &gt;=3D V7.80), SIPROTEC 5 7SJ81 (CP150=
    ) (All versions &lt; V11.0), SIPROTEC 5 7SJ82 (CP100) (All versions &gt;=3D=
    V7.80), SIPROTEC 5 7SJ82 (CP150) (All versions &lt; V11.0), SIPROTEC 5 7SJ=
    85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions &gt;=3D V= 7.80 &lt; V11.0), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86=
    (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7SK82 (CP100) = (All versions &gt;=3D V7.80), SIPROTEC 5 7SK82 (CP150) (All versions &lt; V= 11.0), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (A=
    ll versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7SL82 (CP100) (All versio=
    ns &gt;=3D V7.80), SIPROTEC 5 7SL82 (CP150) (All versions &lt; V11.0), SIPR= OTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions=
    &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROT=
    EC 5 7SL87 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7SS8=
    5 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions &gt;=3D V7= .80 &lt; V11.0), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 = (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7ST86 (CP300) (= All versions &lt; V11.0), SIPROTEC 5 7SX82 (CP150) (All versions &lt; V11.0=
    ), SIPROTEC 5 7SX85 (CP300) (All versions &lt; V11.0), SIPROTEC 5 7SY82 (CP= 150) (All versions &lt; V11.0), SIPROTEC 5 7UM85 (CP300) (All versions &gt;= =3D V7.80 &lt; V11.0), SIPROTEC 5 7UT82 (CP100) (All versions &gt;=3D V7.80=
    ), SIPROTEC 5 7UT82 (CP150) (All versions &lt; V11.0), SIPROTEC 5 7UT85 (CP= 200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions &gt;=3D V7.80 &= lt; V11.0), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP30=
    0) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC 5 7UT87 (CP200) (All v= ersions), SIPROTEC 5 7UT87 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0),=
    SIPROTEC 5 7VE85 (CP300) (All versions &gt;=3D V7.80 &lt; V11.0), SIPROTEC=
    5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions &gt= ;=3D V7.80 &lt; V11.0), SIPROTEC 5 7VU85 (CP300) (All versions &lt; V11.0),=
    SIPROTEC 5 Compact 7SX800 (CP050) (All versions &lt; V11.0). Affected devi= ces do not use sufficiently random values to create session identifiers. Th=
    is could allow an unauthenticated remote attacker to brute force a session = identifier and gain read access to limited information from the web server = without authorization.</td>
    <td>2026-05-12</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-54017" target=3D= "_blank" rel=3D"noopener">CVE-2024-54017</a></td>

    <a href=3D"https://cert-portal.siemens.com/productcert/html/ssa-786884.html=
    " target=3D"_blank" rel=3D"noopener">https://cert-portal.siemens.com/produc= tcert/html/ssa-786884.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">GitLab--GitLab</td>
    <td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 tha=
    t could have allowed an authenticated user to inject HTML and JavaScript in=
    to email notifications sent to other users due to improper input sanitizati= on.</td>
    <td>2026-05-14</td>
    <td>5.4</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-12669" target=3D= "_blank" rel=3D"noopener">CVE-2025-12669</a></td>

    <a href=3D"https://hackerone.com/reports/3368096" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3368096</a><br><a href=3D"https://gi= tlab.com/gitlab-org/gitlab/-/work_items/579385" target=3D"_blank" rel=3D"no= opener">https://gitlab.com/gitlab-org/gitlab/-/work_items/579385</a><br><a = href=3D"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">ghera74--ilGhera Support System for WooCommerc= e</td>
    <td>The ilGhera Support System for WooCommerce plugin for WordPress is vuln= erable to unauthorized access of data due to a missing capability check on = the 'get_ticket_content_callback' function in all versions up to, and inclu= ding, 1.3.0. This makes it possible for unauthenticated attackers to view a=
    ny support ticket content, including sensitive customer information and pri= vate communications, by providing a ticket ID.</td>
    <td>2026-05-13</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14033" target=3D= "_blank" rel=3D"noopener">CVE-2025-14033</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/40ceea= 17-ec60-4775-8495-e2f7643d1b7c?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/40ceea17-ec6= 0-4775-8495-e2f7643d1b7c?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/wc-support-system/trunk/includes/class-wc-support-s= ystem.php#L68" target=3D"_blank" rel=3D"noopener">https://plugins.trac.word= press.org/browser/wc-support-system/trunk/includes/class-wc-support-system.= php#L68</a><br><a href=3D"https://plugins.trac.wordpress.org/browser/wc-sup= port-system/tags/1.2.6/includes/class-wc-support-system.php#L68" target=3D"= _blank" rel=3D"noopener">https://plugins.trac.wordpress.org/browser/wc-supp= ort-system/tags/1.2.6/includes/class-wc-support-system.php#L68</a><br><a hr= ef=3D"https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/in= cludes/class-wc-support-system.php#L643" target=3D"_blank" rel=3D"noopener"= >https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/include= s/class-wc-support-system.php#L643</a><br><a href=3D"https://plugins.trac.w= ordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support= -system.php#L643" target=3D"_blank" rel=3D"noopener">https://plugins.trac.w= ordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support= -system.php#L643</a><br><a href=3D"https://plugins.trac.wordpress.org/brows= er/wc-support-system/tags/1.3.1/includes/class-wc-support-system.php#L780" = target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/brows= er/wc-support-system/tags/1.3.1/includes/class-wc-support-system.php#L780</= a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">stylemix--Cost Calculator Builder</td>
    <td>The Cost Calculator Builder plugin for WordPress is vulnerable to Unaut= henticated Price Manipulation and Insecure Direct Object Reference (IDOR) i=
    n all versions up to, and including, 4.0.1 only when used in combination wi=
    th Cost Calculator Builder PRO. This is due to the ccb_woocommerce_payment = AJAX action being registered via wp_ajax_nopriv, making it accessible to un= authenticated users, and the renderWooCommercePayment() function passing us= er-controlled data directly to CCBWooCheckout::init() without authorization=
    checks. This makes it possible for unauthenticated attackers to add WooCom= merce products to their cart with attacker-controlled prices.</td> <td>2026-05-13</td>
    <td>5.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14755" target=3D= "_blank" rel=3D"noopener">CVE-2025-14755</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/fe684f= 43-8442-4b29-84a8-da8c6863e62b?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/fe684f43-844= 2-4b29-84a8-da8c6863e62b?source=3Dcve</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes= /CCBOrderController.php#L484" target=3D"_blank" rel=3D"noopener">https://pl= ugins.trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/include= s/classes/CCBOrderController.php#L484</a><br><a href=3D"https://plugins.tra= c.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/classes= /CCBAjaxAction.php#L99" target=3D"_blank" rel=3D"noopener">https://plugins.= trac.wordpress.org/browser/cost-calculator-builder/tags/3.6.7/includes/clas= ses/CCBAjaxAction.php#L99</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">wpclever--WPC Badge Management for WooCommerce= </td>
    <td>The WPC Badge Management for WooCommerce plugin for WordPress is vulner= able to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_= best_seller` shortcode in all versions up to, and including, 3.1.6 due to i= nsufficient input sanitization and output escaping. This makes it possible = for authenticated attackers, with Shop Manager-level access and above, to i= nject arbitrary web scripts in pages that will execute whenever a user acce= sses an injected page.</td>
    <td>2026-05-13</td>
    <td>5.5</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14767" target=3D= "_blank" rel=3D"noopener">CVE-2025-14767</a></td>

    <a href=3D"https://www.wordfence.com/threat-intel/vulnerabilities/id/bf02ed= c9-2bb6-4ceb-b2a1-63f95c8becb3?source=3Dcve" target=3D"_blank" rel=3D"noope= ner">https://www.wordfence.com/threat-intel/vulnerabilities/id/bf02edc9-2bb= 6-4ceb-b2a1-63f95c8becb3?source=3Dcve</a><br><a href=3D"https://wordpress.o= rg/plugins/wpc-badge-management" target=3D"_blank" rel=3D"noopener">https:/= /wordpress.org/plugins/wpc-badge-management</a><br><a href=3D"https://plugi= ns.trac.wordpress.org/browser/wpc-badge-management/trunk/includes/class-sho= rtcode.php#L98" target=3D"_blank" rel=3D"noopener">https://plugins.trac.wor= dpress.org/browser/wpc-badge-management/trunk/includes/class-shortcode.php#= L98</a><br><a href=3D"https://plugins.trac.wordpress.org/changeset/3519100/=
    " target=3D"_blank" rel=3D"noopener">https://plugins.trac.wordpress.org/cha= ngeset/3519100/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Tp-link--TL-WR720NMbps Wireless N Router</td> <td>TP-Link TL-WR720N wireless router contains a cross-site request forgery=
    vulnerability that allows attackers to perform unauthorized administrative=
    actions by crafting malicious web requests. Attackers can modify port forw= arding rules via VirtualServerRpm.htm or change WiFi security settings via = WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-= controlled pages.</td>
    <td>2026-05-17</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25321" target=3D= "_blank" rel=3D"noopener">CVE-2018-25321</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44335" target=3D"_blank" rel= =3D"noopener">ExploitDB-44335</a><br><a href=3D"https://www.tp-link.com/" t= arget=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://static.tp-link.com/resources/software/TL-WR720N_V1_130719.zip" = target=3D"_blank" rel=3D"noopener">Product Reference</a><br><a href=3D"http= s://www.vulncheck.com/advisories/tp-link-tl-wr720n-all-versions-csrf-via-ad= ministrative-interfaces" target=3D"_blank" rel=3D"noopener">VulnCheck Advis= ory: TP-Link TL-WR720N All Versions CSRF via Administrative Interfaces</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Joomlaextensions--Joomla! extension JoomOCShop= </td>
    <td>Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerabili=
    ty that allows attackers to perform unauthorized actions on behalf of authe= nticated users. Attackers can craft malicious HTML forms targeting account = endpoints like /joomoc2/?route=3Daccount/edit and to modify user informatio=
    n or reset passwords without user consent.</td>
    <td>2026-05-17</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2018-25337" target=3D= "_blank" rel=3D"noopener">CVE-2018-25337</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/44789" target=3D"_blank" rel= =3D"noopener">ExploitDB-44789</a><br><a href=3D"https://www.joomlaextension= s.co.in/" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><= br><a href=3D"https://extensions.joomla.org/extensions/extension/e-commerce= /e-commerce-integrations/joomocshop/" target=3D"_blank" rel=3D"noopener">Pr= oduct Reference</a><br><a href=3D"https://www.vulncheck.com/advisories/joom= la-joomocshop-cross-site-request-forgery" target=3D"_blank" rel=3D"noopener= ">VulnCheck Advisory: Joomla JoomOCShop 1.0 Cross-Site Request Forgery</a><= br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Easy2pilot-v7--Easy2Pilot</td>
    <td>Easy2Pilot 7 contains a cross-site request forgery vulnerability that a= llows attackers to add unauthorized user accounts by tricking authenticated=
    administrators into visiting malicious pages. Attackers can craft HTML for=
    ms targeting the admin.php?action=3Dadd_user endpoint with POST requests co= ntaining username and password parameters to create new administrative acco= unts without explicit user consent.</td>
    <td>2026-05-13</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2020-37217" target=3D= "_blank" rel=3D"noopener">CVE-2020-37217</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/48099" target=3D"_blank" rel= =3D"noopener">ExploitDB-48099</a><br><a href=3D"http://easy2pilot-v7.com/" = target=3D"_blank" rel=3D"noopener">Official Product Homepage</a><br><a href= =3D"https://www.vulncheck.com/advisories/easy2pilot-7-cross-site-request-fo= rgery-via-admin-php" target=3D"_blank" rel=3D"noopener">VulnCheck Advisory:=
    Easy2Pilot 7 Cross-Site Request Forgery via admin.php</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">CouchCMS--CouchCMS</td>
    <td>CouchCMS 2.2.1 contains a server-side request forgery vulnerability tha=
    t allows authenticated attackers to make arbitrary HTTP requests by uploadi=
    ng malicious SVG files. Attackers can upload SVG files containing external = entity references through the browse.php endpoint to access internal servic=
    es and resources.</td>
    <td>2026-05-15</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-47958" target=3D= "_blank" rel=3D"noopener">CVE-2021-47958</a></td>

    <a href=3D"https://www.exploit-db.com/exploits/49675" target=3D"_blank" rel= =3D"noopener">ExploitDB-49675</a><br><a href=3D"https://github.com/CouchCMS= /CouchCMS" target=3D"_blank" rel=3D"noopener">Official Product Homepage</a>= <br><a href=3D"https://www.vulncheck.com/advisories/couchcms-server-side-re= quest-forgery-via-svg-upload" target=3D"_blank" rel=3D"noopener">VulnCheck = Advisory: CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">GitLab--GitLab</td>
    <td>GitLab has remediated an issue in GitLab CE/EE affecting all versions f= rom 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that=
    could have allowed an authenticated user with Guest permissions to view is= sues in projects they were not authorized to access.</td>
    <td>2026-05-14</td>
    <td>4.3</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-13874" target=3D= "_blank" rel=3D"noopener">CVE-2025-13874</a></td>

    <a href=3D"https://hackerone.com/reports/3445398" target=3D"_blank" rel=3D"= noopener">HackerOne Bug Bounty Report #3445398</a><br><a href=3D"https://gi= tlab.com/gitlab-org/gitlab/-/work_items/582634" target=3D"_blank" rel=3D"no= opener">https://gitlab.com/gitlab-org/gitlab/-/work_items/582634</a><br><a = href=3D"https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-1= 8-11-3-released/" target=3D"_blank" rel=3D"noopener">https://about.gitlab.c= om/releases/2026/05/13/patch-release-gitlab-18-11-3-released/</a><br>=C2=A0= </td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    <div id=3D"low_v">
    <h2 id=3D"low_v_title">Low Vulnerabilities</h2>
    <table class=3D"table no-tablesaw" style=3D"table-layout: fixed; width: 100= %;" border=3D"1" summary=3D"Low Vulnerabilities">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td style=3D"text-align: center;" colspan=3D"5" align=3D"center">There were=
    no low vulnerabilities recorded this week.</td>
    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    <div id=3D"snya_v">
    <h2 id=3D"snya_v_title">Severity Not Yet Assigned</h2>
    <table id=3D"table_severity_not_yet_assigned" class=3D"table no-tablesaw" s= tyle=3D"table-layout: fixed; width: 100%;" border=3D"1" summary=3D"Severity=
    Not Yet Assigned">
    <thead>

    <th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
    <span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
    <th style=3D"width: 44%;" scope=3D"col">Description</th>
    <th style=3D"width: 10%;" scope=3D"col">Published</th>
    <th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
    <th style=3D"width: 7%;" scope=3D"col">Source Info</th>
    <th style=3D"width: 7%;" scope=3D"col">Patch Info</th>
    </tr>
    </thead>
    <tbody>

    <td class=3D"vendor-product">AMD--AMD Ryzen 5000 Series Desktop Processors = with Radeon Graphics</td>
    <td>A compromised Trusted OS (TOS) driver could issue a malformed call that=
    could potentially allow memory access outside the intended range resulting=
    in loss of integrity.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2021-26380" target=3D= "_blank" rel=3D"noopener">CVE-2021-26380</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD--AMD Ryzen 3000 Series Mobile Processors w= ith Radeon Graphics</td>
    <td>A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may a= llow an attacker to load registers repeatedly creating a race condition pot= entially leading to a loss of integrity.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2022-23826" target=3D= "_blank" rel=3D"noopener">CVE-2022-23826</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">KMX--Alien::FreeImage</td>
    <td>Alien::FreeImage versions through 1.001 for Perl contains several vulne= rable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage = library from 2017, which has known vulnerabilities such as CVE-2015-0852 an=
    d CVE-2025-65803. The library embeds other images libraries that also have = known vulnerabilities.</td>
    <td>2026-05-11</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2022-4988" target=3D"= _blank" rel=3D"noopener">CVE-2022-4988</a></td>

    <a href=3D"https://freeimage.sourceforge.io/" target=3D"_blank" rel=3D"noop= ener">https://freeimage.sourceforge.io/</a><br><a href=3D"https://metacpan.= org/release/KMX/Alien-FreeImage-1.001/source/src/Source" target=3D"_blank" = rel=3D"noopener">https://metacpan.org/release/KMX/Alien-FreeImage-1.001/sou= rce/src/Source</a><br><a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2015-= 0852" target=3D"_blank" rel=3D"noopener">https://nvd.nist.gov/vuln/detail/C= VE-2015-0852</a><br><a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2025-65= 803" target=3D"_blank" rel=3D"noopener">https://nvd.nist.gov/vuln/detail/CV= E-2025-65803</a><br><a href=3D"https://github.com/kmx/alien-freeimage/issue= s/4" target=3D"_blank" rel=3D"noopener">https://github.com/kmx/alien-freeim= age/issues/4</a><br><a href=3D"https://github.com/kmx/alien-freeimage/issue= s/5" target=3D"_blank" rel=3D"noopener">https://github.com/kmx/alien-freeim= age/issues/5</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--MK-Auth 23.01K4.9</td>
    <td>An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows atta= ckers to execute arbitrary code via uploading a crafted PHP file.</td> <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-27753" target=3D= "_blank" rel=3D"noopener">CVE-2023-27753</a></td>

    <a href=3D"https://github.com/yueslly/MKAUTH-RCE/blob/main/README.md" targe= t=3D"_blank" rel=3D"noopener">https://github.com/yueslly/MKAUTH-RCE/blob/ma= in/README.md</a><br><a href=3D"https://github.com/yueslly/MKAUTH-RCE" targe= t=3D"_blank" rel=3D"noopener">https://github.com/yueslly/MKAUTH-RCE</a><br>= =C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--MK-Auth 23.01K4.9</td>
    <td>An insecure direct object reference in MK-Auth 23.01K4.9 allows attacke=
    rs to access and send support calls for other users via manipulation of the=
    chamado parameter through a crafted GET request.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-30059" target=3D= "_blank" rel=3D"noopener">CVE-2023-30059</a></td>

    <a href=3D"https://github.com/yueslly/MKAUTH-IDOR" target=3D"_blank" rel=3D= "noopener">https://github.com/yueslly/MKAUTH-IDOR</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 6000 Series Graphics = Products</td>
    <td>Improper validation in Power Management Firmware (PMFW) may allow an at= tacker with privileges to pass malformed workload arguments when exporting = table data from SMU to DRAM potentially resulting in a loss of confidential= ity and/or availability.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-31309" target=3D= "_blank" rel=3D"noopener">CVE-2023-31309</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 5000 Series Mobile Proces= sors with Radeon Graphics</td>
    <td>Improperly preserved integrity of hardware configuration state during a=
    power save/restore operation in the AMD Secure Processor (ASP) could allow=
    an attacker with the ability to write outside the trusted memory range (TM=
    R) to change the execution flow of the Video Core Next (VCN) firmware poten= tially impacting confidentiality, integrity, or availability.</td> <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-31316" target=3D= "_blank" rel=3D"noopener">CVE-2023-31316</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 6000 Series Graphics = Products</td>
    <td>Improper restriction of operations within the bounds of a memory buffer=
    in the AMD secure processer (ASP) could allow an attacker to read or write=
    to protected memory potentially resulting in arbitrary code execution.</td=

    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2023-31317" target=3D= "_blank" rel=3D"noopener">CVE-2023-31317</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Instinct MI300X</td>
    <td>An out of bounds read in the remote management firmware could allow a p= rivileged attacker read a limited section of memory outside of established = bounds potentially resulting in loss of confidentiality or availability.</t=

    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-21950" target=3D= "_blank" rel=3D"noopener">CVE-2024-21950</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD EPYC 4005 Series Processors</td=

    <td>Improper Input Validation in the AMD RAID driver could allow an attacke=
    r to point to an arbitrary memory location potentially resulting in privile=
    ge escalation and arbitrary code execution.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-21962" target=3D= "_blank" rel=3D"noopener">CVE-2024-21962</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4016.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4016.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD EPYC Series 9004 Processors</td=

    <td>Improper enforcement of the LFENCE serialization property may allow an = attacker to bypass speculation barriers and potentially disclose sensitive = information, potentially resulting in loss of confidentiality.</td> <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36315" target=3D= "_blank" rel=3D"noopener">CVE-2024-36315</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-3030.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-3030.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-4017.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 7000 Series Graphics = Products</td>
    <td>Improper isolation of VCN-JPEG HW register space could allow a maliciou=
    s Guest Virtual Machine (VM) or a process to perform unauthorized access to=
    the register space of the JPEG cores assigned a victim VM/process, potenti= ally gaining arbitrary read/write access to the victim VM/process data.</td=

    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36323" target=3D= "_blank" rel=3D"noopener">CVE-2024-36323</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Radeon PRO V710</td>
    <td>Improper isolation of GPU HW register space could allow a privileged at= tacker in malicious Guest Virtual Machine (VM) to perform unauthorized acce=
    ss to specific victim range of GPU MMIO register space, potentially causing=
    the host OS to reboot and creating a Denial of Service (DOS) condition.</t=

    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36332" target=3D= "_blank" rel=3D"noopener">CVE-2024-36332</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 5000 Series Graphics = Products</td>
    <td>A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an=
    attacker to achieve privilege escalation potentially resulting in arbitrar=
    y code execution.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36333" target=3D= "_blank" rel=3D"noopener">CVE-2024-36333</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Radeon RX 7000 Series Graphics = Products</td>
    <td>Improper verification of cryptographic signature in the Radeon RGB tool=
    could allow a malicious file placed in the installation directory to be ru=
    n with elevated privileges potentially leading to arbitrary code execution.= </td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36334" target=3D= "_blank" rel=3D"noopener">CVE-2024-36334</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD EPYC 4004</td>
    <td>Improper input validation in the AMD OverDrive (AOD) System Management = Mode (SMM) module could allow a privileged attacker to perform an out-of-bo= unds read, potentially resulting in loss of confidentiality.</td> <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-36345" target=3D= "_blank" rel=3D"noopener">CVE-2024-36345</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-3030.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-3030.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-4017.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-4017.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Checkmk GmbH--Checkmk</td>
    <td>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk=
    &lt;2.4.0p29, &lt;2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged us=
    er able to create a Windows service whose name matches 'MySQL' or 'MariaDB'=
    (or with write access to a binary referenced by such a service) to execute=
    arbitrary code in the context of the Checkmk agent service, which typicall=
    y runs as SYSTEM.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-47091" target=3D= "_blank" rel=3D"noopener">CVE-2024-47091</a></td>

    <a href=3D"https://checkmk.com/werk/19198" target=3D"_blank" rel=3D"noopene= r">https://checkmk.com/werk/19198</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--Ardupilot</td>
    <td>Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162= 058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of se= rvice via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor = component.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-48519" target=3D= "_blank" rel=3D"noopener">CVE-2024-48519</a></td>

    <a href=3D"https://github.com/ArduPilot/ardupilot/issues/27937" target=3D"_= blank" rel=3D"noopener">https://github.com/ArduPilot/ardupilot/issues/27937= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--Ardupilot</td>
    <td>Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e02= 3793133e49a035daf37c14433e484778 allows a local attacker to cause a denial =
    of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp components.</td> <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-51394" target=3D= "_blank" rel=3D"noopener">CVE-2024-51394</a></td>

    <a href=3D"https://github.com/ArduPilot/ardupilot/issues/28458" target=3D"_= blank" rel=3D"noopener">https://github.com/ArduPilot/ardupilot/issues/28458= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--Ardupilot</td>
    <td>Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e02= 3793133e49a035daf37c14433e484778 allows a local attacker to cause a denial =
    of service via the AP_SmartAudio::loop, AP_SmartAudio, AP_SmartAudio.cpp co= mponents.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-51395" target=3D= "_blank" rel=3D"noopener">CVE-2024-51395</a></td>

    <a href=3D"https://github.com/ArduPilot/ardupilot/issues/28374" target=3D"_= blank" rel=3D"noopener">https://github.com/ArduPilot/ardupilot/issues/28374= </a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">n/a--FMT-Firmware</td>
    <td>Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contai=
    n a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c= .</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2024-55045" target=3D= "_blank" rel=3D"noopener">CVE-2024-55045</a></td>

    <a href=3D"https://github.com/Firmament-Autopilot/FMT-Firmware/issues/133" = target=3D"_blank" rel=3D"noopener">https://github.com/Firmament-Autopilot/F= MT-Firmware/issues/133</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
    th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
    <td>An unchecked return value within the AMD Platform Management Framework = (PMF) could allow an attacker to read or modify an arbitrary address potent= ially resulting in loss of confidentiality, integrity, or availability.</td=

    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-0028" target=3D"= _blank" rel=3D"noopener">CVE-2025-0028</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7040 Series Mobile Proces= sors with Radeon Graphics</td>
    <td>Improper access control between the Joint Test Action Group (JTAG) and = Advanced Extensible Interface (AXI) could allow an attacker with physical a= ccess to read or overwrite the contents of cross-chip debug (XCD) registers=
    potentially resulting in loss of data integrity or confidentiality.</td> <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-0040" target=3D"= _blank" rel=3D"noopener">CVE-2025-0040</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4017.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4017.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-6027.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen Al Max+</td>
    <td>An out-of-bounds read in power management firmware by a malicious local=
    attacker with low privileges could potentially lead to a partial loss of c= onfidentiality and availability.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-0044" target=3D"= _blank" rel=3D"noopener">CVE-2025-0044</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-6027.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-6027.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--Athlon 3000 Series Mobile Processor=
    s with Radeon Graphics</td>
    <td>Improper Input validation in the AMD Secure Processor (ASP) PCI driver = may allow a local attacker to create a buffer overflow condition, potential=
    ly resulting in a crash or denial of service</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-0045" target=3D"= _blank" rel=3D"noopener">CVE-2025-0045</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br><a href=3D"https://= www.amd.com/en/resources/product-security/bulletin/AMD-SB-3047.html" target= =3D"_blank" rel=3D"noopener">https://www.amd.com/en/resources/product-secur= ity/bulletin/AMD-SB-3047.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">WSO2--WSO2 Identity Server</td>
    <td>Due to a lack of user account state validation during authentication, l= ocked user accounts can be successfully authenticated using Magic Link or P= ass Key methods. This bypasses the intended security control that should pr= event access to accounts that have been locked. This vulnerability may allo=
    w unauthorized access to applications and sensitive data associated with ac= counts that should have been restricted via the account lock mechanism. It = also undermines the effectiveness of the account lock mechanism intended to=
    prevent further login attempts.</td>
    <td>2026-05-11</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-10908" target=3D= "_blank" rel=3D"noopener">CVE-2025-10908</a></td>

    <a href=3D"https://security.docs.wso2.com/en/latest/security-announcements/= security-advisories/2026/WSO2-2025-4388/" target=3D"_blank" rel=3D"noopener= ">https://security.docs.wso2.com/en/latest/security-announcements/security-= advisories/2026/WSO2-2025-4388/</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Siemens--Simcenter Femap</td>
    <td>The affected applications contains a memory corruption vulnerability wh= ile parsing specially crafted IPT files. This could allow an attacker to ex= ecute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-2= 7389)</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-12659" target=3D= "_blank" rel=3D"noopener">CVE-2025-12659</a></td>

    <a href=3D"https://cert-portal.siemens.com/productcert/html/ssa-870926.html=
    " target=3D"_blank" rel=3D"noopener">https://cert-portal.siemens.com/produc= tcert/html/ssa-870926.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">silabs.com--Simplicity SDK</td>
    <td>* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices=
    are not sufficiently random and will eventually repeat. * KSU keys using S= YMCRYPTO will be impacted by this vulnerability.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-14972" target=3D= "_blank" rel=3D"noopener">CVE-2025-14972</a></td>

    <a href=3D"https://community.silabs.com/068Vm00000M3cAX" target=3D"_blank" = rel=3D"noopener">https://community.silabs.com/068Vm00000M3cAX</a><br>=C2=A0= </td>
    </tr>

    <td class=3D"vendor-product">n/a--Intel(R) Ethernet 800 series</td>
    <td>Use after free for some Linux kernel driver for the Intel(R) Ethernet 8=
    00 series before version 2.3.14 within Ring 0: Kernel may allow a denial of=
    service. Unprivileged software adversary with an authenticated user combin=
    ed with a low complexity attack may enable denial of service. This result m=
    ay potentially occur via local access when attack requirements are present = without special internal knowledge and requires no user interaction. The po= tential vulnerability may impact the confidentiality (none), integrity (non=
    e) and availability (high) of the vulnerable system, resulting in subsequen=
    t system confidentiality (none), integrity (none) and availability (high) i= mpacts.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-27723" target=3D= "_blank" rel=3D"noopener">CVE-2025-27723</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01426.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01426.html</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
    <td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows a symlink attack. If a malicious graphics package containing symlinks i=
    s uploaded, the web server follows the supplied links when serving content.=
    No mechanisms to restrict those link targets to a specific area of the fil= esystem is enabled. This allows an attacker to retrieve arbitrary files fro=
    m the device.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-27850" target=3D= "_blank" rel=3D"noopener">CVE-2025-27850</a></td>

    <a href=3D"https://garmin.com" target=3D"_blank" rel=3D"noopener">https://g= armin.com</a><br><a href=3D"https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
    <td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows a cross-site origin WebSocket hijacking attack. Among other uses, the W=
    DU utilizes WebSockets to control settings, including administrative settin= gs. This allows a network attacker to take full control of a WDU. To initia=
    te an exploit of this vulnerability, the victim must (1) be utilizing a web=
    browser on a multihomed host that has local interfaces on the Garmin Marin=
    e Network as well as another network, and (2) access a malicious third part=
    y website created by the attacker.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-27851" target=3D= "_blank" rel=3D"noopener">CVE-2025-27851</a></td>

    <a href=3D"https://garmin.com" target=3D"_blank" rel=3D"noopener">https://g= armin.com</a><br><a href=3D"https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
    <td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows a reflected cross site scripting (XSS) attack. This allows an attacker =
    on the local network segment to execute arbitrary JavaScript code within th=
    e context of the WDU webpage. Full administrator level access to the device=
    is possible. To initiate an exploit of this vulnerability, the victim must=
    execute two actions: (1) view a specific URL served by the WDU, and (2) cl= ick an element on the rendered page.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-27852" target=3D= "_blank" rel=3D"noopener">CVE-2025-27852</a></td>

    <a href=3D"https://garmin.com" target=3D"_blank" rel=3D"noopener">https://g= armin.com</a><br><a href=3D"https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Garmin[.]com--Garmin WDU</td>
    <td>The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) all= ows its authentication to be bypassed. The WDU web site only performs authe= ntication with the client within the client's browser. The WebSockets used =
    to communicate with the WDU server do not enforce any authentication. An at= tacker may bypass all authentication mechanisms by directly utilizing the r= emote APIs available on the websocket.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-27853" target=3D= "_blank" rel=3D"noopener">CVE-2025-27853</a></td>

    <a href=3D"https://garmin.com" target=3D"_blank" rel=3D"noopener">https://g= armin.com</a><br><a href=3D"https://www8.garmin.com/support/ch.jsp?product= =3D010-02642-00" target=3D"_blank" rel=3D"noopener">https://www8.garmin.com= /support/ch.jsp?product=3D010-02642-00</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">ThreadReadButtons--ThreadReadButtons</td> <td>striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in fun= ction ThreadReadButtons.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-28343" target=3D= "_blank" rel=3D"noopener">CVE-2025-28343</a></td>

    <a href=3D"https://github.com/striso/striso-control-firmware/issues/5" targ= et=3D"_blank" rel=3D"noopener">https://github.com/striso/striso-control-fir= mware/issues/5</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AuxJack--AuxJack</td>
    <td>striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in fun= ction AuxJack.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-28344" target=3D= "_blank" rel=3D"noopener">CVE-2025-28344</a></td>

    <a href=3D"https://github.com/striso/striso-control-firmware/issues/6" targ= et=3D"_blank" rel=3D"noopener">https://github.com/striso/striso-control-fir= mware/issues/6</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">NXP[.]com--NXP</td>
    <td>NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v= 17.92.1.p149.157 was discovered to contain a buffer overflow via the mod_pa=
    ra parameter in the woal_init_module_param function.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-29338" target=3D= "_blank" rel=3D"noopener">CVE-2025-29338</a></td>

    <a href=3D"https://www.nxp.com/docs/en/release-note/RN00104.pdf" target=3D"= _blank" rel=3D"noopener">https://www.nxp.com/docs/en/release-note/RN00104.p= df</a><br><a href=3D"https://github.com/masjadaan/CVE-2025-29338" target=3D= "_blank" rel=3D"noopener">https://github.com/masjadaan/CVE-2025-29338</a><b= r>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
    th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
    <td>An out of bounds write within the AMD Platform Management Framework (PM=
    F) could allow an attacker to execute arbitrary code at an elevated privile=
    ge level potentially leading to loss of confidentiality integrity, or avail= ability.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-29935" target=3D= "_blank" rel=3D"noopener">CVE-2025-29935</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
    th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
    <td>Improper input validation within the AMD Platform Management Framework = (PMF) could allow an attacker to unmap arbitrary memory pages potentially i= mpacting integrity and availability, or allowing privilege escalation resul= ting in loss of confidentiality.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-29936" target=3D= "_blank" rel=3D"noopener">CVE-2025-29936</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
    th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
    <td>An out of bounds read within the AMD Platform Management Framework (PMF=
    ) could allow an attacker to trigger a read of an arbitrary memory location=
    potentially resulting in loss of availability or confidentiality.</td> <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-29937" target=3D= "_blank" rel=3D"noopener">CVE-2025-29937</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 7035 Series Processors wi=
    th Radeon Graphics (formerly codenamed "Rembrandt R")</td>
    <td>An unchecked return value within the AMD Platform Management Framework = (PMF) could allow an attacker to write to an arbitrary memory address resul= ting in denial of service or arbitrary code execution.</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-29938" target=3D= "_blank" rel=3D"noopener">CVE-2025-29938</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">AMD[.]com--AMD Ryzen 4000 Series Mobile Proces= sors with Radeon Graphics (formerly codenamed "Renoir")</td>
    <td>A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can=
    allow a local attacker to write out of bounds, potentially resulting in de= nial of service or crash</td>
    <td>2026-05-15</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-29944" target=3D= "_blank" rel=3D"noopener">CVE-2025-29944</a></td>

    <a href=3D"https://www.amd.com/en/resources/product-security/bulletin/AMD-S= B-4015.html" target=3D"_blank" rel=3D"noopener">https://www.amd.com/en/reso= urces/product-security/bulletin/AMD-SB-4015.html</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Significant-Gravitas--AutoGPT</td>
    <td>AutoGPT is a platform that allows users to create, deploy, and manage c= ontinuous artificial intelligence agents that automate complex workflows. I=
    n AutoGPT, the execution process is recorded to the console (stdout/stderr)=
    , and deployed in container mode, which is automatically captured by Docker=
    and stored as "container logs". However, prior to 0.6.32, there is no limi=
    t on the log size when the container is deployed. When the number of user a= ccesses is too large, the log on the server disk will be too large, causing=
    disk resource exhaustion and eventually causing DoS. autogpt-platform-beta= -v0.6.32 fixes the issue.</td>
    <td>2026-05-13</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-32425" target=3D= "_blank" rel=3D"noopener">CVE-2025-32425</a></td>

    <a href=3D"https://github.com/Significant-Gravitas/AutoGPT/security/advisor= ies/GHSA-vw3v-whvp-33v5" target=3D"_blank" rel=3D"noopener">https://github.= com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-vw3v-whvp-33v5</a= ><br><a href=3D"https://github.com/Significant-Gravitas/AutoGPT/commit/57a0= 6f70883ce6be18738c6ae8bb41085c71e266" target=3D"_blank" rel=3D"noopener">ht= tps://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be18738c= 6ae8bb41085c71e266</a><br><a href=3D"https://github.com/Significant-Gravita= s/AutoGPT/blob/62361ccc48327b3124549543b45d933d16f622d2/autogpt_platform/au= togpt_libs/autogpt_libs/logging/config.py#L83-L102" target=3D"_blank" rel= =3D"noopener">https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc= 48327b3124549543b45d933d16f622d2/autogpt_platform/autogpt_libs/autogpt_libs= /logging/config.py#L83-L102</a><br><a href=3D"https://github.com/Significan= t-Gravitas/AutoGPT/blob/62361ccc48327b3124549543b45d933d16f622d2/autogpt_pl= atform/docker-compose.platform.yml#L102-L142" target=3D"_blank" rel=3D"noop= ener">https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b31= 24549543b45d933d16f622d2/autogpt_platform/docker-compose.platform.yml#L102-= L142</a><br>=C2=A0</td>
    </tr>

    <td class=3D"vendor-product">Intel[.]com--Intel(R) Server Firmware Update U= tility Software</td>
    <td>Uncontrolled search path for some Intel(R) Server Firmware Update Utili=
    ty Software before version 16.0.12. within Ring 3: User Applications may al= low an escalation of privilege. System software adversary with an authentic= ated user combined with a high complexity attack may enable escalation of p= rivilege. This result may potentially occur via local access when attack re= quirements are present without special internal knowledge and requires acti=
    ve user interaction. The potential vulnerability may impact the confidentia= lity (high), integrity (high) and availability (high) of the vulnerable sys= tem, resulting in subsequent system confidentiality (none), integrity (none=
    ) and availability (none) impacts.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-35969" target=3D= "_blank" rel=3D"noopener">CVE-2025-35969</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01410.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01410.html</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Intel[.]com--Intel(R) Processors</td>
    <td>Exposure of sensitive information caused by shared microarchitectural p= redictor state that influences transient execution for some Intel(R) Proces= sors within VMX non-root (guest) operation may allow an information disclos= ure. Unprivileged software adversary with an authenticated user combined wi=
    th a high complexity attack may enable data exposure. This result may poten= tially occur via local access when attack requirements are present without = special internal knowledge and requires no user interaction. The potential = vulnerability may impact the confidentiality (high), integrity (none) and a= vailability (none) of the vulnerable system, resulting in subsequent system=
    confidentiality (high), integrity (none) and availability (none) impacts.<=

    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-35979" target=3D= "_blank" rel=3D"noopener">CVE-2025-35979</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01420.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01420.html</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Intel[.]com--Intel Endpoint Management Assista=
    nt (EMA) software</td>
    <td>Improper input validation for some Intel Endpoint Management Assistant = (EMA) software before version 1.14.5 within Ring 3: User Applications may a= llow an escalation of privilege. Unprivileged software adversary with an un= authenticated user combined with a low complexity attack may enable escalat= ion of privilege. This result may potentially occur via adjacent access whe=
    n attack requirements are not present without special internal knowledge an=
    d requires no user interaction. The potential vulnerability may impact the = confidentiality (high), integrity (high) and availability (high) of the vul= nerable system, resulting in subsequent system confidentiality (none), inte= grity (none) and availability (none) impacts.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-35990" target=3D= "_blank" rel=3D"noopener">CVE-2025-35990</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01434.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01434.html</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Intel[.]com--Intel platforms</td>
    <td>Improper initialization in the UEFI firmware for some Intel platforms w= ithin Ring 0: Bare Metal OS may allow an information disclosure. System sof= tware adversary with a privileged user combined with a high complexity atta=
    ck may enable data exposure. This result may potentially occur via local ac= cess when attack requirements are present without special internal knowledg=
    e and requires no user interaction. The potential vulnerability may impact = the confidentiality (high), integrity (none) and availability (none) of the=
    vulnerable system, resulting in subsequent system confidentiality (none), = integrity (none) and availability (none) impacts.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-35991" target=3D= "_blank" rel=3D"noopener">CVE-2025-35991</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01413.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01413.html</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Intel[.]com--Display Virtualization for Window=
    s OS driver software</td>
    <td>Improper buffer restrictions for some Display Virtualization for Window=
    s OS driver software within Ring 2: Device Drivers may allow a denial of se= rvice. Unprivileged software adversary with an authenticated user combined = with a low complexity attack may enable denial of service. This result may = potentially occur via local access when attack requirements are not present=
    without special internal knowledge and requires no user interaction. The p= otential vulnerability may impact the confidentiality (none), integrity (no= ne) and availability (high) of the vulnerable system, resulting in subseque=
    nt system confidentiality (none), integrity (none) and availability (none) = impacts.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-36510" target=3D= "_blank" rel=3D"noopener">CVE-2025-36510</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01430.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01430.html</a><br>=C2=A0</t=

    </tr>

    <td class=3D"vendor-product">Intel[.]com--AI Playground software</td> <td>Uncontrolled search path for some AI Playground software before version=
    3.0.0 alpha within Ring 3: User Applications may allow an escalation of pr= ivilege. Unprivileged software adversary with an authenticated user combine=
    d with a high complexity attack may enable escalation of privilege. This re= sult may potentially occur via local access when attack requirements are pr= esent without special internal knowledge and requires active user interacti= on. The potential vulnerability may impact the confidentiality (high), inte= grity (high) and availability (high) of the vulnerable system, resulting in=
    subsequent system confidentiality (none), integrity (none) and availabilit=
    y (none) impacts.</td>
    <td>2026-05-12</td>
    <td>not yet calculated</td>
    <td><a href=3D"https://www.cve.org/CVERecord?id=3DCVE-2025-36515" target=3D= "_blank" rel=3D"noopener">CVE-2025-36515</a></td>

    <a href=3D"https://intel.com/content/www/us/en/security-center/advisory/int= el-sa-01438.html" target=3D"_blank" rel=3D"noopener">https://intel.com/cont= ent/www/us/en/security-center/advisory/intel-sa-01438.html</a><br>=C2=A0</t=

    </tr>
    </tbody>
    </table>
    <p><a href=3D"#top">Back to top</a></p>
    </div>
    </div>
    </div>
    <style>body {
    font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
    l; font-style: normal; color: #333333;
    }
    </style>
    =20


    <div id=3D"mail_footer">
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
    r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/417e991" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"https://www.cisa.gov/privacy-policy=
    " target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
    r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
    : #757575;">=C2=A0 |=C2=A0 </span><a href=3D"https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
    an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>

    </div>
    <div id=3D"tagline">
    <hr>
    <table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=

    <tbody>

    <td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to cisa@toolazy.synchro.net using GovDelivery Com= munications Cloud, on behalf of: Cybersecurity and Infrastructure Security = Agency =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
    <td align=3D"right" width=3D"11%"><a href=3D"https://subscriberhelp.granicu= s.com/" target=3D"_blank" rel=3D"noopener"><img src=3D"https://content.govd= elivery.com/images/govd-logo-dark.png" border=3D"0" alt=3D"GovDelivery logo=
    " width=3D"115"></a></td>
    </tr>
    </tbody>
    </table>
    <style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
    img {margin-left:0px; margin-right:0px;}</style>

    </div>
    </td>
    </tr>
    </table>

    <img alt=3D"" src=3D"https://links-2.govdelivery.com/CI0/0101019e3ce7a975-0= 4279e1d-c4a4-4390-ae74-eaa897475d71-000000/tlm_SNsaQSB3na98HZNrFGM9LSmUCmnc= knzIX0Njzlg=3D452" style=3D"display: none; width: 1px; height: 1px;">
    </body>
    </html>

    --===============7146585765089518506==--

    --===============8728627738968554007==--